Qualys, Inc.

Senior Security Research Engineer

Qualys, Inc.
Apply
2 hours ago
Pune, IndiaSenior

Responsibilities

  • Analyze vulnerabilities down to affected code paths, trigger conditions, exploitation primitives, and patch changes.
  • Develop proof-of-concept exploits in controlled lab environments to establish reachability, reliability, and impact.
  • Build safe, non-harmful vulnerability checks for customer hosts with clear verdicts, response taxonomies, safety statements, and false-positive analyses.
  • Assess whether vulnerabilities remain exploitable against ASLR, DEP/NX, stack canaries, CFI, RELRO, sandboxing, and modern hardware mitigations.
  • Design compiler, platform, defense-in-depth, and architectural mitigations that address individual vulnerabilities and broader bug classes.
  • Adapt public offensive and detection tooling while distinguishing detection logic, payloads, and bypass-critical components.
  • Create matched vulnerable and patched lab environments for reproducible exploitation, regression testing, and mitigation validation.
  • Document exploitation reasoning, verdict logic, residual risk, known gaps, constraints, and shipped outcomes.

Requirements

  • At least 3 years of vulnerability research experience.
  • BE/B.Tech or MCA, preferably in Computer Science, Information Technology, or a related field.
  • Native and binary exploitation experience with practical knowledge of stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string vulnerabilities.
  • Experience with debuggers and disassembler/decompiler workflows such as gdb with pwndbg or GEF, WinDbg, IDA, Ghidra, or Binary Ninja, and with pwntools or an equivalent.
  • Fluency in vulnerability classes and variant analysis, including root-cause reasoning.
  • Proficiency in at least one of Python, C, C++, Go, or Rust.
  • Strong technical writing skills for documenting exploitation reasoning, detection verdicts, residual risk, and known gaps.
  • Working fluency with AI and LLM tools such as Claude Code in day-to-day work.
  • Preferred: published CVE research, exploit development, coordinated disclosure, fuzzing, program analysis, reverse engineering, source-code review, detection or scanning platform authoring, CTF experience, and container- or VM-based lab orchestration.

Tech Stack

Categories

Qualys, Inc.

About Qualys, Inc.

1,001-5,000 employees
Contact me