
Senior Security Research Engineer
Qualys, Inc.2 hours ago
Pune, IndiaSenior
Responsibilities
- Analyze vulnerabilities down to affected code paths, trigger conditions, exploitation primitives, and patch changes.
- Develop proof-of-concept exploits in controlled lab environments to establish reachability, reliability, and impact.
- Build safe, non-harmful vulnerability checks for customer hosts with clear verdicts, response taxonomies, safety statements, and false-positive analyses.
- Assess whether vulnerabilities remain exploitable against ASLR, DEP/NX, stack canaries, CFI, RELRO, sandboxing, and modern hardware mitigations.
- Design compiler, platform, defense-in-depth, and architectural mitigations that address individual vulnerabilities and broader bug classes.
- Adapt public offensive and detection tooling while distinguishing detection logic, payloads, and bypass-critical components.
- Create matched vulnerable and patched lab environments for reproducible exploitation, regression testing, and mitigation validation.
- Document exploitation reasoning, verdict logic, residual risk, known gaps, constraints, and shipped outcomes.
Requirements
- At least 3 years of vulnerability research experience.
- BE/B.Tech or MCA, preferably in Computer Science, Information Technology, or a related field.
- Native and binary exploitation experience with practical knowledge of stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string vulnerabilities.
- Experience with debuggers and disassembler/decompiler workflows such as gdb with pwndbg or GEF, WinDbg, IDA, Ghidra, or Binary Ninja, and with pwntools or an equivalent.
- Fluency in vulnerability classes and variant analysis, including root-cause reasoning.
- Proficiency in at least one of Python, C, C++, Go, or Rust.
- Strong technical writing skills for documenting exploitation reasoning, detection verdicts, residual risk, and known gaps.
- Working fluency with AI and LLM tools such as Claude Code in day-to-day work.
- Preferred: published CVE research, exploit development, coordinated disclosure, fuzzing, program analysis, reverse engineering, source-code review, detection or scanning platform authoring, CTF experience, and container- or VM-based lab orchestration.