Senior Security Research Engineer

Posted 2 Days Ago
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Senior level
Information Technology • Security • Cybersecurity
The Role
Research and analyze vulnerabilities, including root causes, exploitability, affected code paths, and patch changes. Develop proof-of-concept exploits, safe vulnerability checks, detections, and mitigations. Assess bypasses against modern defenses, perform variant analysis, adapt offensive tooling, and build reproducible vulnerable and patched lab environments. Document verdict logic, residual risk, false positives, and technical limitations.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description:

We're hiring a vulnerability researcher for the Threat Research Unit at Qualys. You'll take vulnerabilities apart to understand exactly how they work, prove out what an attacker could do with them, and turn that into detections and mitigations that hold up on real customer systems. The work sits between offense and defense: writing proof-of-concept exploits to ground your analysis in fact, then using what you learn to build safe, reliable checks and design defenses that make whole classes of bugs harder to exploit.

 Responsibilities:

  • Analyze vulnerabilities down to the affected code path, trigger conditions, the primitive they yield, and what a patch actually changes.
  • Develop proof-of-concept exploits in the lab to establish reachability, reliability, and real-world impact, giving detection and mitigation work a concrete basis in what an attacker can achieve.
  • Build non-harmful checks that confirm whether a vulnerability is present on customer hosts. Use a distinguishing signal instead of a harmful payload, and deliver a clear verdict, a response taxonomy, a safety statement, and a false-positive analysis.
  • Assess mitigation bypasses. Given a vulnerability and a target's defenses (ASLR, DEP/NX, stack canaries, CFI, RELRO, sandboxing, and modern hardware mitigations), determine whether exploitation remains feasible and how.
  • Design and write stronger mitigations at two levels: killing bug classes and patching individual instances. This includes compiler and platform hardening, defense-in-depth, and design changes that make exploitation economically infeasible even when a bug survives.
  • Read and adapt public offensive and detection tooling, with a clear grasp of which parts are detection, which are payload, and which are load-bearing for a bypass.
  • Stand up matched vulnerable and patched lab environments for reproducible exploitation, regression testing, and mitigation validation.

     Required Qualifications:

  • Minimum 3 year of experience in Vulnerability research.
  • BE/B.Tech/MCA, preferably in Computer Science, Information Technology, or a related field.
  • Native and binary exploitation. Practical command of memory-corruption classes: stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string bugs. Comfortable with a debugger and disassembler/decompiler workflow (gdb with pwndbg or GEF, WinDbg, IDA, Ghidra, or Binary Ninja) and with pwntools or an equivalent.
  • Vulnerability-class fluency. Able to reason in terms of root-cause classes and run variant analysis.
  • Scripting and delivery. Proficient in at least one of Python, C/C++, Go, or Rust.
  • Clear technical writing. Able to document exploitation reasoning, verdict logic, residual risk, and known gaps, including an honest record of what you tried, where a constraint blocked the ideal approach, and what you shipped instead.
  • Working fluency with AI and LLM tools (such as Claude Code) as part of your day-to-day workflow.

Preferred Qualifications:

  • Published CVE research, exploit development, or coordinated disclosure.
  • Fuzzing experience.
  • Program analysis experience.
  • Reverse engineering or source-code review to pinpoint a patch's distinguishing change.
  • Authoring experience for a detection or scanning platform.
  • CTF background or an equivalent hands-on track record.
  • Reproducible lab orchestration (containers or VMs) for exploitation and mitigation fixtures.

Skills Required

  • Minimum 3 years of vulnerability research experience
  • BE, B.Tech, MCA, or related degree, preferably in Computer Science or Information Technology
  • Practical native and binary exploitation experience
  • Experience with memory-corruption vulnerabilities, including stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string bugs
  • Comfort with debugger and disassembler/decompiler workflows using tools such as GDB, WinDbg, IDA, Ghidra, or Binary Ninja
  • Experience with pwntools or an equivalent exploitation framework
  • Vulnerability-class fluency and variant-analysis ability
  • Proficiency in at least one of Python, C, C++, Go, or Rust
  • Clear technical writing and documentation skills
  • Working fluency with AI and LLM tools such as Claude Code
  • Published CVE research, exploit development, or coordinated disclosure
  • Fuzzing experience
  • Program analysis experience
  • Reverse engineering or source-code review experience
  • Experience authoring detections or scanning-platform checks
  • CTF background or equivalent hands-on experience
  • Reproducible lab orchestration using containers or virtual machines

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Foster City, CA
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Qualys Logo Qualys

Senior Security Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Qualys Logo Qualys

Senior Security Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Qualys Logo Qualys

Senior Security Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Qualys Logo Qualys

Senior Security Research Engineer

Information Technology • Security • Cybersecurity
In-Office
Pune, Mahārāshtra, IND
2736 Employees

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account