Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
We are seeking a passionate and detail-oriented Lead Security Engineer to join our Vulnerability Research Development team. As a Lead Security Engineer, you will join a motivated engineering research team responsible for researching, developing, and delivering detection signatures for our vulnerability scanning products. This opening is your opportunity to work in the rapidly expanding field of computer security with a company with excellent customer ratings and outstanding growth rates.
Responsibilities:
- Research vulnerabilities in the areas of applications, operating systems, databases, TCP/IP protocols, network devices, and various services.
- Develop, test, and maintain high-quality detections to detect known vulnerabilities and 0-day threats.
- Research new and emerging technologies to identify vulnerabilities and exploits.
- Drive technical direction, prioritization, and execution of detection development initiatives.
- Collaborate with security researchers, product teams, and QA engineers to ensure the timely delivery of detection content.
- Research Zero-day vulnerabilities and actively attack vulnerabilities to deliver fast detection content within hours of vulnerability disclosure.
- Act as a technical escalation point for complex vulnerability research and detection challenges.
- Stay up to date with the latest CVEs, advisories, and security intelligence feeds.
- Work with our Customer Support and Research teams to troubleshoot and triage customer issues such as false positives and false negatives.
Qualifications:
- 7+ years of industry experience in network and systems security.
- In-depth knowledge of TCP/IP, SSL, HTTP, FTP, SSH, DNS and others.
- Knowledge of OWASP top 10 and familiarity with other web-based attacks.
- Proficiency in at least one scripting language (Python, Bash, Go).
- Ability to quickly analyse proofs-of-concept or exploits and translate them into accurate signatures.
- Experience with network analysis tools, and analysis of packet captures.
- Knowledge of different Databases (Oracle, DB2, etc.) and system Administration.
- Strong understanding of VPN, Firewalls, Intrusion detection systems (IDS), and security tools.
- Excellent written and verbal communication skills.
Educational Qualification: BE/B.Tech/MCA, preferably in Computer Science, Information Technology, or a related field
Additional Plus Competencies:
- Experience with large-scale vulnerability management programs.
- Proficient with regular expressions and system administration.
- Demonstrated ability to drive strategic initiatives and independently own technical roadmaps.
- Knowledge of Cloud Platforms (AWS, Azure, Oracle, etc.).
- Knowledge of container technologies such as Docker and Kubernetes.
- OSCP, CISSP, or SANS GIAC certifications.
Skills Required
- 7+ years of industry experience in network and systems security
- In-depth knowledge of TCP/IP, SSL, HTTP, FTP, SSH, DNS, and related protocols
- Knowledge of the OWASP Top 10 and familiarity with web-based attacks
- Proficiency in at least one scripting language: Python, Bash, or Go
- Ability to analyze proofs of concept or exploits and translate them into accurate signatures
- Experience with network analysis tools and packet capture analysis
- Knowledge of databases such as Oracle and DB2, plus system administration
- Strong understanding of VPNs, firewalls, intrusion detection systems, and security tools
- Excellent written and verbal communication skills
- BE, B.Tech, MCA, or equivalent degree, preferably in Computer Science, Information Technology, or a related field
- Experience with large-scale vulnerability management programs
- Proficiency with regular expressions and system administration
- Ability to drive strategic initiatives and independently own technical roadmaps
- Knowledge of cloud platforms such as AWS, Azure, or Oracle
- Knowledge of container technologies such as Docker and Kubernetes
- OSCP, CISSP, or SANS GIAC certification
Qualys Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.
-
Affordable Benefits — Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
-
Healthcare Strength — Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
-
Equity Value & Accessibility — Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.
Qualys Insights
What We Do
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com





