Senior Security Research Engineer

Posted 4 Days Ago
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Senior level
Information Technology • Security • Cybersecurity
The Role
Lead vulnerability research and exploit validation across operating systems, databases, enterprise apps, cloud services, containers, and network devices. Analyze root causes, exploitability, and impact; build safe exploit-based validation methods and detection logic for WAF/EDR/IPS; improve automation and tooling, apply AI/LLMs, mentor engineers, and collaborate with engineering/product to produce detection and protection content.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Senior Security Research Engineer, Vulnerability Research & Exploit Validation

About the Team

Qualys is a recognized leader in cloud security and vulnerability management, trusted by thousands of organizations worldwide. Our Threat Research team is known for its work on vulnerability research, exploit analysis, and detection content that protects customers against real-world attacks.

About the Role

We are hiring a Senior Security Research Engineer to work on vulnerability research and exploit validation across a wide range of technologies, including operating systems, databases, enterprise applications, cloud services, container platforms, and network devices. You will research vulnerabilities, confirm whether they can be exploited in the real world, and turn that work into detection and protection content.

This is a hands-on, senior individual-contributor role. You will own complex research projects, mentor other engineers, work closely with Engineering and Product, and help improve automation across the team. The role comes with real freedom to choose the research topics and areas you go deep on, along with clear opportunities to grow your career at Qualys.
Responsibilities
Research:

  • Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
  • Research newly disclosed, zero-day, and actively exploited vulnerabilities, and prioritize work based on real-world risk.
  • Analyze root causes, attack vectors, exploitability conditions, and potential business impact.
  • Review technical designs, research methods, and code contributions for quality and consistency.

Exploit Validation & Detection

  • Build exploit-based validation techniques that confirm whether vulnerabilities are exploitable in practice.
  • Design safe, controlled validation methods that emulate attacker behavior without affecting production systems.
  • Write validation logic that determines whether existing security controls such as WAFs, firewalls, EDRs, IPS, and compensating controls actually block exploitation.
  • Set coding standards and quality guidelines for signature and detection content.

Automation & Tooling

  • Improve automation across vulnerability research, exploit validation, content generation, testing, and release.
  • Find and apply ways to use AI and LLM to speed up research work.
  • Improve tooling and workflows to raise research quality and output.

Required Qualifications

  • 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong background in vulnerability analysis, exploit development, and modern attack techniques.
  • Solid understanding of core protocols, including TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Proficiency with Python and Bash scripting.
  • Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
  • Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
  • Track record of leading projects and mentoring technical teammates.
  • Strong written, verbal, and technical communication skills.

Preferred Qualifications

  • Experience applying AI or LLM to security research or detection engineering.
  • Contributions to CVEs, security advisories, open-source security tooling, or published research.
  • Relevant certifications such as OSCP, OSCE, OSED, or GXPN (nice to have, not required).
  • Experience building detection content or signatures for IPS, WAF, or EDR platforms.

Skills Required

  • 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong background in vulnerability analysis, exploit development, and modern attack techniques.
  • Solid understanding of core protocols including TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Proficiency with Python and Bash scripting.
  • Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
  • Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
  • Track record of leading projects and mentoring technical teammates.
  • Strong written, verbal, and technical communication skills.
  • Experience applying AI or LLM to security research or detection engineering.
  • Contributions to CVEs, security advisories, open-source security tooling, or published research.
  • Relevant certifications such as OSCP, OSCE, OSED, or GXPN.
  • Experience building detection content or signatures for IPS, WAF, or EDR platforms.

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Foster City, CA
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Qualys Logo Qualys

Senior Security Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Qualys Logo Qualys

Senior Security Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Magna International Logo Magna International

Senior Analyst, Finance Solutions

Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
Hybrid
Pune, Mahārāshtra, IND
171000 Employees
Remote or Hybrid
3 Locations
289097 Employees

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account