Qualys

Lead Security Research Engineer

Qualys pune, Maharashtra, India

Computer and Network Security · 1,001-5,000 employees

14 h ago
Senior (5-10 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Lead Security Research Engineer will set the technical direction and roadmap for vulnerability detection libraries while mentoring engineering staff. They will also drive the adoption of AI/ML techniques to automate research and enhance the quality of detection content.

What they look for

Vulnerability research Technical leadership Python Bash Docker Kubernetes TCP/IP HTTP SSH SSL/TLS Network security System administration Automation AI/ML Mentorship Packet capture analysis

Requirements

Candidates must have 7+ years of experience in network and systems security with strong technical leadership skills. Proficiency in Python, Bash, container orchestration, and deep knowledge of network protocols are required.

Benefits

Professional development Certifications Continuous learning Inclusive culture

Full description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description 

We are seeking an experienced and technically exceptional Lead Security Research Engineer to drive our Vulnerability Detection Signature Research team. In this role, you will set the technical direction for how we research, develop, and deliver advanced vulnerability detection libraries for our scanning product suite, while mentoring engineers and raising the bar for detection quality across the team. 

Beyond hands-on research, you will own the roadmap for detection coverage, champion automation to scale our research capabilities, and partner with leadership and cross-functional teams to solve the hardest problems in vulnerability detection. Exposure to AI/ML is a strong plus. If you combine deep vulnerability research expertise with the ability to lead people and technical strategy, this role is for you. 

Responsibilities 

  • Set technical direction and own the roadmap for vulnerability detection libraries (signatures) across Qualys Scanner product suite. 
  • Lead the research, design, and development of new detection logic and the enhancement of existing content for databases, applications, operating systems, TCP/IP protocols, and network devices. 
  • Mentor and technically guide Senior and mid-level Research Engineers, conducting design and code reviews and establishing best practices and standards for high-quality detection content. 
  • Explore and, where valuable, drive the adoption of AI/ML techniques to accelerate research, development, and validation such as automated signature generation, false positive/negative reduction, anomaly detection, and intelligent triage of emerging vulnerabilities. 
  • Design and scale automation frameworks for recurring research, development, and validation tasks. 
  • Continuously evaluate emerging technologies and threat trends, and collaborate with customers, vendors, and internal stakeholders to expand detection coverage. 
  • Partner with Customer Support and Research teams to lead the resolution of complex customer issues, such as false positives/negatives, and drive systemic fixes. 
  • Represent the team in cross-functional planning, providing technical estimates, risk assessments, and delivery commitments. 
  • Champion strong documentation, knowledge sharing, and a culture of engineering excellence. 

Qualifications 

  • 7+ years of experience in network and systems security, including demonstrated technical leadership or team mentorship. 
  • Deep understanding of common protocols: TCP/IP, HTTP, FTP, SSH, SSL/TLS. 
  • Strong knowledge of common security vulnerabilities and mitigation techniques. 
  • Hands-on experience with Python and Bash scripting. 
  • Hands-on working experience with containers and orchestration tools (Docker, Kubernetes). 
  • Familiarity with network analysis tools and packet capture analysis. 
  • Strong ability to prioritize, plan, and manage multiple workstreams and people in a fast-paced environment. 
  • System administration experience on Windows or Unix/Linux platforms. 
  • Strong understanding of VPNs, Firewalls, and IDS/IPS technologies. 
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts to both engineers and non-technical stakeholders. 

Additional Plus Competencies 

  • Exposure to applying AI/ML to security problems - e.g., using machine learning for detection, classification, anomaly detection, or pattern recognition, or leveraging LLMs to automate research, code, or content-generation workflows. 
  • Knowledge of Lua (preferred) or Java. 
  • Experience with virtualization platforms such as VMWare, VirtualBox, XEN, etc. 
  • Understanding of cloud platforms (e.g., AWS, Azure, Oracle Cloud), including their AI/ML services. 
  • Experience using or developing vulnerability scanners, IDS/IPS, and other security tools. 
  • Prior experience building security-related tools or automation at scale. 
  • Industry certifications such as OSCP, CISSP, and GIAC. 
  • Track record of leading projects and small teams independently with minimal supervision. 

Why Join Us? 

  • Lead cutting-edge security research and shape how AI/ML transforms vulnerability detection alongside a talented, collaborative engineering team. 
  • Directly influence the security posture of thousands of customers. 
  • Opportunities for professional development, certifications, and continuous learning. 
  • Inclusive culture that values innovation, ownership, and customer impact.