
Senior Security Research Engineer
Qualys, Inc.2 hours ago
Pune, IndiaSenior
Responsibilities
- Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
- Research newly disclosed, zero-day, and actively exploited vulnerabilities and prioritize work based on real-world risk.
- Analyze vulnerability root causes, attack vectors, exploitability conditions, and business impact.
- Build safe, controlled exploit-validation techniques that emulate attacker behavior without affecting production systems.
- Write validation logic to determine whether WAFs, firewalls, EDRs, IPS, and compensating controls block exploitation.
- Set coding standards and quality guidelines for signatures and detection content.
- Improve automation across vulnerability research, exploit validation, content generation, testing, and release.
- Apply AI and LLM technologies to accelerate security research and improve tooling and workflows.
- Review technical designs, research methods, and code contributions for quality and consistency.
- Lead complex research projects, mentor technical teammates, and collaborate with Engineering and Product.
Requirements
- 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
- Strong background in vulnerability analysis, exploit development, and modern attack techniques.
- Solid understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
- Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
- Proficiency with Python and Bash scripting.
- Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
- Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
- Track record of leading projects and mentoring technical teammates.
- Strong written, verbal, and technical communication skills.
- Preferred experience applying AI or LLM to security research or detection engineering.
- Contributions to CVEs, security advisories, open-source security tooling, or published research are preferred.
- Relevant certifications such as OSCP, OSCE, OSED, or GXPN are preferred but not required.
- Experience building detection content or signatures for IPS, WAF, or EDR platforms is preferred.
Benefits
- The role offers freedom to choose research topics and areas of specialization.
- The position includes opportunities for career growth at Qualys.