Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Responsibilities
Research and create signatures for the Qualys product to detect vulnerabilities in Industrial Control Systems.
Research new and emerging technologies to identify vulnerabilities and exploits.
Research zero-day and actively attack vulnerabilities to create signatures to identify vulnerable assets.
Build automation for day-to-day tasks.
Qualifications
Experience and strong knowledge in penetration testing and vulnerability management.
Knowledge and hands on experience with several types of security vulnerabilities and attacks such as cross-site scripting, privilege escalation, remote code execution.
Proficient with regular expressions.
Bachelor's in computer science with 5+ years of experience in Information Security domain or Masters in Computer Science or Cyber Security.
In-depth knowledge of TCP/IP, HTTP, DNS, FTP, SSH, TLS/SSL, and SMTP protocols.
Experience with scripting languages, including Python and Bash.
Experience with network analysis tools, analysis of packet captures.
System administrator experience on Windows or Unix platforms.
Excellent written and verbal communication skills.
Additional Plus Competencies
Understanding of Lua (preferred), or Python
Knowledge of Virtualization software (VMWare, Virtual PC/Virtual Box, XEN, etc.).
Knowledge of container technologies such as Docker and Kubernetes.
Able to handle projects independently.
Experienced in the use of vulnerability scanners, IDS, and multiple security tools.
Experience in developing security-related tools/programs.
OSCP and similar certifications.
Skills Required
- Experience and strong knowledge in penetration testing and vulnerability management
- Knowledge and hands on experience with security vulnerabilities and attacks such as cross-site scripting, privilege escalation, remote code execution
- Proficient with regular expressions
- Bachelor's in Computer Science with 5+ years in Information Security OR Master's in Computer Science or Cyber Security
- In-depth knowledge of TCP/IP, HTTP, DNS, FTP, SSH, TLS/SSL, and SMTP protocols
- Experience with scripting languages, including Python and Bash
- Experience with network analysis tools and analysis of packet captures
- System administrator experience on Windows or Unix platforms
- Excellent written and verbal communication skills
- Understanding of Lua (preferred) or Python
- Knowledge of virtualization software (VMWare, VirtualBox, XEN, etc.)
- Knowledge of container technologies such as Docker and Kubernetes
- Able to handle projects independently
- Experienced in the use of vulnerability scanners, IDS, and multiple security tools
- Experience in developing security-related tools/programs
- OSCP and similar certifications
Qualys Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.
-
Affordable Benefits — Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
-
Healthcare Strength — Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
-
Equity Value & Accessibility — Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.
Qualys Insights
What We Do
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com








