Senior Web Application Security Engineer

Posted Yesterday
Be an Early Applicant
Pune, Mahārāshtra, IND
In-Office
Senior level
Information Technology • Security • Cybersecurity
The Role
Research, implement, and fine-tune detections for web app vulnerabilities and CVEs with zero false positives for a web application security product. Create exploits and proofs-of-concept, use DAST and scanning tools, analyze network captures, develop security tools, and collaborate to troubleshoot, tune payloads, and improve detections.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Responsibilities 
In this position, you will primarily be researching and implementing detections for vulnerabilities on all the latest web application technologies. You will also be expected to fine-tune existing logic and payloads to detect vulnerabilities and CVEs with zero false positives for the Qualys Web Application Security product. Efficient problem-solving and troubleshooting skills are necessary, as well as using the latest tools in the industry.

 

Required Skills: 
 

* 4-8 years of industry experience in web application security 

* Create exploits, proof-of-concept for web application vulnerabilities 

* Strong JavaScript programming skills 

 * Knowledge of HTTP protocol (Requests, responses, Cookies, etc.)  

* Understanding of web application vulnerabilities, OWASP Top 10 in Web Applications, API, and LLMs 

* Exposure to DAST/BlackBox tools 

* Web application security scanning tools like BURP/ZAP, SQLMap, CURL 

* Experience with network analysis tools and analysis of packet captures. 

* Proficient with regular expressions. 

* System administrator experience on Windows or Unix platforms.   

* Strong analytical and problem-solving skills 

* Passion for web security and attention to detail

* Experience with scripting languages, including Python and Bash   

* Exposure to JAVA programming   

* Experience with Selenium, Postman scripting 

* Experience with Metasploit/Nessus exploits (especially HTTP-related ) 

* Experience with web application firewalls (WAF) rules, ModSecurity 

* Exposure to WEB 2.0, XML/XPath, JSON, Swagger  

* Database/SQL knowledge 

* Experienced in the use of various scanners and open-source security tools. 

* Experience in developing security-related tools/programs. 

* Ability to work independently 

* Published research  

* Security certifications 

Education
Bachelor’s / Master’s degree in Computer Science, Engineering, or equivalent practical experience

Skills Required

  • 4-8 years of industry experience in web application security
  • Create exploits and proof-of-concept for web application vulnerabilities
  • Strong JavaScript programming skills
  • Knowledge of HTTP protocol (requests, responses, cookies)
  • Understanding of web application vulnerabilities and OWASP Top 10, API security, and LLM-related issues
  • Exposure to DAST / black-box testing tools
  • Experience with Burp Suite, ZAP, SQLMap, and curl
  • Experience with network analysis tools and packet capture analysis
  • Proficient with regular expressions
  • System administration experience on Windows or Unix platforms
  • Experience with scripting languages including Python and Bash
  • Exposure to Java programming
  • Experience with Selenium and Postman scripting
  • Experience with Metasploit and Nessus exploits (especially HTTP-related)
  • Experience with web application firewalls (WAF) and ModSecurity rules
  • Familiarity with Web 2.0 technologies, XML/XPath, JSON, and Swagger
  • Database and SQL knowledge
  • Experience using various scanners and open-source security tools
  • Experience developing security-related tools or programs
  • Strong analytical and problem-solving skills, attention to detail
  • Ability to work independently
  • Published research in web security
  • Security certifications
  • Bachelor's or Master's degree in Computer Science, Engineering, or equivalent practical experience

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Foster City, CA
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Capco Logo Capco

RWA

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Capco Logo Capco

Test Automation Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Capco Logo Capco

Machine Learning Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

JPMorganChase Logo JPMorganChase

Client Data

Financial Services
Remote or Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account