Qualys

Security Research Engineer

Qualys pune, Maharashtra, India

Computer and Network Security · 1,001-5,000 employees

14 h ago
Mid (2-5 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will research, design, and develop advanced vulnerability detection libraries and signatures for the Qualys Scanner product suite. Additionally, you will collaborate with cross-functional teams to automate research tasks and resolve customer issues related to detection accuracy.

What they look for

Vulnerability research Security engineering Python Bash scripting Docker Kubernetes TCP/IP HTTP SSH SSL/TLS Network analysis System administration Linux Unix Firewalls IDS/IPS

Requirements

Candidates must have at least 4 years of experience in network and systems security with strong proficiency in Python, Bash, and common network protocols. A deep understanding of security vulnerabilities, container orchestration, and system administration is essential for this role.

Benefits

Professional development Certifications Continuous learning Inclusive culture

Full description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

We are seeking a highly skilled and motivated Security Research Engineer to join our Vulnerability Detection Signature Research team. In this role, you will research, develop, and deliver advanced vulnerability detection libraries for VMDR scanning products. You will partner closely with cross-functional teams to solve complex challenges and ensure our customers receive accurate, high-quality vulnerability coverage. 

If you have a strong foundation in vulnerability research, hands-on security engineering, and solid coding experience and you enjoy diving deep into technologies, this role is for you. Exposure to AI/ML, or an interest in exploring how it can accelerate security research, is a strong plus. 

Responsibilities 

  • Research, design, and develop new vulnerability detection libraries (signatures), or enhance existing ones, for Qualys Scanner product suite. 
  • Build detection logic for a wide range of technologies including databases, applications, operating systems, TCP/IP protocols, and network devices. 
  • Continuously research emerging technologies and collaborate with customers, vendors, and internal stakeholders to extend detection coverage. 
  • Automate recurring research, development, and validation of tasks. 
  • Explore, where valuable, how AI/ML techniques can accelerate research, development, and validation such as automated signature generation, false positive/negative reduction, anomaly detection, and triage of emerging vulnerabilities. 
  • Work closely with Customer Support and Research teams to troubleshoot and resolve customer issues such as false positives/negatives. 
  • Contribute to high-quality detection content through strong documentation and collaboration. 

Qualifications 

  • 4+ years of experience in network and systems security. 
  • Deep understanding of common protocols: TCP/IP, HTTP, FTP, SSH, SSL/TLS. 
  • Strong knowledge of common security vulnerabilities and mitigation techniques. 
  • Hands-on experience with Python and Bash scripting. 
  • Hands-on working experience with containers and orchestration tools (Docker, Kubernetes). 
  • Familiarity with network analysis tools and packet capture analysis. 
  • Ability to prioritize and manage multiple tasks in a fast-paced environment. 
  • System administration experience on Windows or Unix/Linux platforms. 
  • Strong understanding of VPNs, Firewalls, and IDS/IPS technologies. 
  • Excellent written and verbal communication skills. 

Additional Plus Competencies 

  • Exposure to applying AI/ML to security problems - e.g., using machine learning for detection, classification, anomaly detection, or pattern recognition, or leveraging LLMs to automate research, code, or content-generation workflows. 
  • Knowledge of Lua (preferred) or Java. 
  • Experience with virtualization platforms such as VMWare, VirtualBox, XEN, etc. 
  • Understanding of cloud platforms (e.g., AWS, Azure, Oracle Cloud). 
  • Experience using or developing vulnerability scanners, IDS/IPS, and other security tools. 
  • Prior experience building security-related tools or automation. 
  • Industry certifications such as OSCP, CISSP, and GIAC. 
  • Ability to lead projects independently and work with minimal supervision. 

Why Join Us? 

  • Work on cutting-edge security research with a talented, collaborative engineering team. 
  • Directly influence the security posture of thousands of customers. 
  • Opportunities for professional development, certifications, and continuous learning. 
  • Inclusive culture that values innovation, ownership, and customer impact.