Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
As a Senior Engineer, Security Research you will be part of a Qualys Threat Research Unit that is responsible for the research, development, and delivery of emergent vulnerability mitigation techniques. This opening is your opportunity to work on a unique security solution in the rapidly expanding fields of penetration testing, vulnerability assessments, and cyber security.
- Research, analyze, and assess attack surface and vulnerability data.
- Develop tailored and actionable mitigation strategies and plans to address vulnerability risk.
- Work with new and emerging vulnerability data to identify potential attack paths in critical systems.
- Document, develop and present mitigation strategies in web applications, databases, standalone applications, etc.
- Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigation.
- Elevate AI strategies to provide mitigation strategies that prioritize risk against level of effort for multiple systems or organizations.
- Patch diffing and reverse engineering with tools such as Ghidra, IDA, etc. \
- Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologies.
- Work in a fast-paced startup-like environment with shifting priorities to handle and maintain balance with multiple stakeholders.
- Conduct research to assess and create software patches and configuration changes to be applied to varied software, middleware, and hardware.
- Provide assessments including security, system, and business impact of vulnerabilities.
- Must be able to think ahead to avoid business outages based on the lab results.
- Analyze vulnerability data and support management of identified vulnerabilities, including tracking, remediation, and reporting.
- Graduate with a preferable 4-year degree or at least 3-year degree with computer science and information technology background.
- Vulnerability research and exploit analysis.
- Programming in any one of the following languages: PowerShell, Python, Shell.
- Excellent understanding of network, system, and application security.
- Excellent written and verbal communication and articulation skills.
- Secure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate risk.
- Have working knowledge of basic operation systems commands and tooling - Windows, Linux, Mac OS.
- Solid understanding of the security implications of a patch on web applications, Windows, Linux, Mac OS operating systems.
- Experience with IDA Pro, Ghidra, or similar binary analysis tools.
- Knowledge of various vulnerability scanning solutions is a plus.
- Specific demonstrated experience mapping business processes and comparing those processes to industry best practices.
- Thorough testing of patches in a non-production environment.
- Ability and ready to learn new technology and should be a good team player.
Skills Required
- Four-year degree preferred, or at least a three-year degree with a computer science or information technology background
- Experience with vulnerability research and exploit analysis
- Programming experience in PowerShell, Python, or Shell
- Strong understanding of network, system, and application security
- Excellent written and verbal communication skills
- Knowledge of secure architecture designs and detection or protection mechanisms, including firewalls, IDS/IPS, and full-packet capture technologies
- Working knowledge of operating-system commands and tooling for Windows, Linux, and Mac OS
- Understanding of security implications of patches for web applications and Windows, Linux, and Mac OS operating systems
- Experience with IDA Pro, Ghidra, or similar binary analysis tools
- Knowledge of vulnerability scanning solutions
- Experience mapping business processes against industry best practices
- Experience thoroughly testing patches in non-production environments
- Ability and willingness to learn new technologies and work effectively in a team
Qualys Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.
-
Affordable Benefits — Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
-
Healthcare Strength — Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
-
Equity Value & Accessibility — Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.
Qualys Insights
What We Do
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com





