Q

Lead Security Research Engineer

Qualys

Pune District, Maharashtra, India · Full Time

Be the first to apply

Experience
8+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor's degree or equivalent
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

We are seeking a Lead Security Research Engineer to spearhead vulnerability research, exploit examination, impact verification, and vulnerability signature creation throughout our security platform. This role centers on leading efforts to uncover, authenticate, and prioritize security risks based on real-world exploitability, helping differentiate genuine threats from potential theoretical vulnerabilities.

Key Responsibilities

  • Drive vulnerability research across a broad spectrum including operating systems, databases, enterprise software, cloud services, container platforms, and network hardware.
  • Investigate newly disclosed vulnerabilities, including N-day and actively exploited threats.
  • Develop techniques to validate exploits, confirming practical exploitability of weaknesses.
  • Ensure quality and consistency by reviewing system designs, research methods, and code submissions.
  • Collaborate closely with Engineering and Product teams to guide product roadmaps and security content strategy.
  • Design controlled, safe validation processes that simulate attacker behavior without affecting live systems.
  • Analyze root causes of vulnerabilities, vectors of attack, conditions for exploitation, and assess business impact.
  • Mentor and provide technical guidance to Security Research Engineers on detailed vulnerability and exploit analysis and signature development.
  • Create validation logic to check if current security components such as WAFs, firewalls, EDRs, and IPS adequately block exploits.
  • Lead automation for vulnerability research workflows including exploit validation, content creation, testing, and releases.
  • Establish and enforce coding standards, best practices, and quality controls for signature development.

Qualifications

  • Bachelor’s degree in a relevant field or equivalent work experience.
  • More than 8 years of hands-on experience in vulnerability research, penetration testing, detection engineering, or related security research roles.
  • In-depth knowledge of network protocols including TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and advanced web protocols.
  • Expertise in vulnerability assessment, exploit development, and attack methodologies.
  • Significant working experience with operating systems, databases, web technologies, cloud infrastructures, and enterprise environments.
  • Strong programming skills and experience with packet analysis, network diagnostics, and protocol reverse engineering.
  • Familiarity with OWASP Top 10, prevalent attack strategies, and contemporary threat actor techniques.
  • Excellent communication skills, both written and verbal, as well as demonstrated leadership in guiding technical projects and teams.

Preferred Skills and Certifications

  • Experience with Lua scripting (preferred), Bash, or Python programming languages.
  • Understanding of cloud platforms like AWS, Azure, and Oracle Cloud.
  • Proficiency with regular expressions.
  • Familiarity with container ecosystems such as Docker and Kubernetes.
  • Practical use of vulnerability scanning, intrusion detection systems, and other security utilities.
  • Certifications like OSCP, CISSP, or SANS GIAC are advantageous.

Minimum education

Bachelor's Degree

Industry

Cybersecurity

How they work

Teamwork & Collaboration Problem Solving Leadership
🤖
Online · instant AI help
Broxer