research
Posted 14 hours agoLead Security Research Engineer
at Qualys
Pune, IndiaOn-site
Responsibilities
- - Lead the development of exploit-based exposure validation techniques to confirm real-world exploitability of vulnerabilities.
- - Review technical designs, research methodologies, and code contributions to ensure quality and consistency.
- - Design safe and controlled validation mechanisms that emulate attacker behavior without affecting production systems.
- - Build validation logic capable of determining whether existing security controls such as WAFs, firewalls, EDRs, IPS, and compensating controls effectively prevent exploitation.
- - Drive automation initiatives for vulnerability research, exploit validation, content generation, testing, and release processes.
- - Establish best practices, coding standards, and quality guidelines for signature development.
- - Lead vulnerability research initiatives across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
Requirements
- Qualifications: - Bachelor's degree in a relevant field (or equivalent experience). - 8+ years of hands-on
- experience in vulnerability research, penetration testing, detection engineering, or security research. - Deep understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols. - Strong expertise in vulnerability analysis, exploit development, and attack techniques. - Extensive knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure. - Strong coding background. -
- Experience with packet analysis, network troubleshooting, and protocol reverse engineering. - Knowledge of OWASP Top 10, common attack techniques, and modern threat actor tactics. - Excellent written, verbal, and technical communication skills. - Demonstrated
- experience leading projects and mentoring technical teams.
- Additional Plus Competencies: Understanding of Lua (preferred), Bash, or Python.
- Knowledge of Cloud Platforms (AWS, Azure, Oracle, etc.).
- Knowledge of container technologies such as Docker and Kubernetes.
- OSCP, CISSP, or SANS GIAC certifications.
Additional details
- Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! As a Lead Security Research Engineer, you will provide technical leadership for vulnerability research, exploit analysis, exposure validation, and vulnerability signature development across the Qualys security platform.
- You will lead initiatives to identify, validate, and prioritise security risks based on real-world exploitability, helping customers distinguish theoretical exposures from confirmed attack paths.
- - Research newly disclosed, N-day, and actively exploited vulnerabilities.
- - Partner with Engineering and Product teams to influence roadmap decisions and security content strategy.
- - Analyze vulnerability root causes, attack vectors, exploitability conditions, and potential business impact.
- Experienced in the use of vulnerability scanners, IDS, and security tools.