research
Posted Dec 16, 2025Principal Security Research Engineer
at Qualys
Pune, IndiaOn-site
Responsibilities
- Rapidly architect and build prototypes, PoCs, and detection tools.
- Design and validate algorithms based on network and application telemetry to detect complex exploit primitives (RCE, SQLi, Memory Corruption) at the execution boundary.
- A track record of taking a vulnerability or theoretical attack method and converting it into a concrete detection rule or defensive tool.
Requirements
- You bring a rare blend of deep security expertise (Zero-days, CVEs, Exploits) and software engineering rigor to drive operational excellence at scale.
- You won’t just theorize; you will write code (Python/Go/C) to test security hypotheses and demonstrate feasibility.
- experience in security research or low-level software engineering, with a focus on advanced threat detection and deep attack analysis.
- Proven ability to develop robust PoCs and tools.
- You are comfortable reading and writing code in modern frameworks (Python, Go, or similar).
- Strong understanding of the Linux ecosystem, OS internals, and cloud-native environments.
- Experience applying advanced AI/ML and LLMs to solve complex security challenges, automating expert tradecraft such as code analysis or adversarial simulation, to transform manual research workflows into autonomous, scalable defense engines.
- Experience with eBPF, syscall tracing, or memory management.
- Experience in architecting secure systems and deploying detection mechanisms to mitigate risk.
- Demonstrated ability to work independently in a fast-paced, unstructured environment where you wear multiple hats.
Experience
- The DNA We Need We are looking for a technologist with a hacker mindset—someone who loves to explore how things work under the hood and prefers architecting solutions over maintaining legacy views. 5+ years of