Jobs Companies Qualys Senior Security Research Engineer

Sobre este puesto de Senior Security Research Engineer en Qualys

Qualys · Presencial · Pune

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description:

We're hiring a vulnerability researcher for the Threat Research Unit at Qualys. You'll take vulnerabilities apart to understand exactly how they work, prove out what an attacker could do with them, and turn that into detections and mitigations that hold up on real customer systems. The work sits between offense and defense: writing proof-of-concept exploits to ground your analysis in fact, then using what you learn to build safe, reliable checks and design defenses that make whole classes of bugs harder to exploit.


 Responsibilities:

  • Analyze vulnerabilities down to the affected code path, trigger conditions, the primitive they yield, and what a patch actually changes.
  • Develop proof-of-concept exploits in the lab to establish reachability, reliability, and real-world impact, giving detection and mitigation work a concrete basis in what an attacker can achieve.
  • Build non-harmful checks that confirm whether a vulnerability is present on customer hosts. Use a distinguishing signal instead of a harmful payload, and deliver a clear verdict, a response taxonomy, a safety statement, and a false-positive analysis.
  • Assess mitigation bypasses. Given a vulnerability and a target's defenses (ASLR, DEP/NX, stack canaries, CFI, RELRO, sandboxing, and modern hardware mitigations), determine whether exploitation remains feasible and how.
  • Design and write stronger mitigations at two levels: killing bug classes and patching individual instances. This includes compiler and platform hardening, defense-in-depth, and design changes that make exploitation economically infeasible even when a bug survives.
  • Read and adapt public offensive and detection tooling, with a clear grasp of which parts are detection, which are payload, and which are load-bearing for a bypass.
  • Stand up matched vulnerable and patched lab environments for reproducible exploitation, regression testing, and mitigation validation.

     Required Qualifications:

  • Minimum 3 year of experience in Vulnerability research.
  • BE/B.Tech/MCA, preferably in Computer Science, Information Technology, or a related field.
  • Native and binary exploitation. Practical command of memory-corruption classes: stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string bugs. Comfortable with a debugger and disassembler/decompiler workflow (gdb with pwndbg or GEF, WinDbg, IDA, Ghidra, or Binary Ninja) and with pwntools or an equivalent.
  • Vulnerability-class fluency. Able to reason in terms of root-cause classes and run variant analysis.
  • Scripting and delivery. Proficient in at least one of Python, C/C++, Go, or Rust.
  • Clear technical writing. Able to document exploitation reasoning, verdict logic, residual risk, and known gaps, including an honest record of what you tried, where a constraint blocked the ideal approach, and what you shipped instead.
  • Working fluency with AI and LLM tools (such as Claude Code) as part of your day-to-day workflow.

Preferred Qualifications:

  • Published CVE research, exploit development, or coordinated disclosure.
  • Fuzzing experience.
  • Program analysis experience.
  • Reverse engineering or source-code review to pinpoint a patch's distinguishing change.
  • Authoring experience for a detection or scanning platform.
  • CTF background or an equivalent hands-on track record.
  • Reproducible lab orchestration (containers or VMs) for exploitation and mitigation fixtures.

¿Listo para postularte en Qualys?
Postúlate en Qualys

Sobre Qualys

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

Ver todos los empleos en Qualys →

Empleos similares

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Qualys

Ver todos los empleos en Qualys →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis