Qualys, Inc.

Lead Security Research Engineer

Qualys, Inc.
Apply
1 hour ago
Pune, IndiaStaff+

Responsibilities

  • Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
  • Research newly disclosed, N-day, and actively exploited vulnerabilities and analyze their root causes, attack vectors, exploitability, and business impact.
  • Develop exploit-based exposure validation techniques and safe mechanisms that emulate attacker behavior without affecting production systems.
  • Review technical designs, research methodologies, and code contributions for quality and consistency.
  • Partner with Engineering and Product teams on roadmap decisions and security content strategy.
  • Build validation logic to assess whether WAFs, firewalls, EDRs, IPS, and compensating controls prevent exploitation.
  • Drive automation for vulnerability research, exploit validation, content generation, testing, and release processes.
  • Establish signature-development best practices, coding standards, and quality guidelines.
  • Mentor and guide Security Research Engineers on vulnerability analysis, exploit analysis, and signature creation.

Requirements

  • Bachelor’s degree in a relevant field or equivalent experience.
  • 8+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Deep understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Strong expertise in vulnerability analysis, exploit development, and attack techniques.
  • Extensive knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Strong coding background with experience in packet analysis, network troubleshooting, and protocol reverse engineering.
  • Knowledge of OWASP Top 10, common attack techniques, and modern threat actor tactics.
  • Excellent written, verbal, and technical communication skills.
  • Demonstrated experience leading projects and mentoring technical teams.
  • Preferred knowledge of Lua, Bash, Python, cloud platforms, regular expressions, Docker, Kubernetes, vulnerability scanners, IDS, and security tools.
  • OSCP, CISSP, or SANS GIAC certifications are additional preferred qualifications.

Categories

Qualys, Inc.

About Qualys, Inc.

1,001-5,000 employees
Contact me