Compliance Research Analyst

Qualys

Pune District

On-site

INR 400,000 - 800,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Qualys, Inc. is seeking a motivated Compliance Research Analyst with 0–3 years of experience to join the security-focused team. You will perform technical research on Linux/Windows/macOS configurations and help map controls to NIST, PCI-DSS, ISO 27001, MITRE ATT&CK, and other standards.

The role emphasizes content maintenance, testing, and collaboration with Product, Development, QA, and Infrastructure teams to improve compliance content quality and address gaps.

Qualifications

  • Bachelor's degree in CS/IT/Cybersecurity or related field.
  • 0–3 years of experience in Linux administration, cybersecurity, technical support, system administration, or compliance.
  • Strong foundation in Linux administration and security benchmarks.
  • Linux certifications such as RHCSA, LFCS, or Linux+. Security certifications like Security+ desirable.
  • Excellent analytical, written and verbal communication, and teamwork skills.

Responsibilities

  • Conduct technical and content research for Linux/other systems security configurations.
  • Study CIS Benchmarks, DISA STIG, and map controls to NIST, ISO 27001, PCI-DSS, MITRE ATT&CK.
  • Maintain and update compliance content and validate controls through testing.
  • Collaborate with Product, Development, QA, and Infrastructure teams to close gaps.

Skills

Linux Administration
RHEL/CentOS
Debian Linux
Bash/Shell scripting
Regular Expressions
Security Frameworks
NIST ISO PCI
Networking concepts
Analytical thinking
Communication skills
Collaboration

Education

Bachelor's degree in CS/IT/Cybersecurity

Tools

Postman
Microsoft Security Toolkit

Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! We are looking for a motivated and detail-oriented Compliance Research Analyst to join our team. This role is ideal for candidates with 0-3 years of experience who have a strong foundation in Linux administration and an interest in cybersecurity, compliance, and security best practices.

Key Responsibilities
  • Technical Research & Compliance Content Research - Analyze security configuration requirements for Linux, Windows, macOS, databases, applications, and network devices. Study industry security benchmarks such as CIS Benchmarks and DISA STIG to understand secure configuration requirements. Help create and maintain technical compliance controls based on security best practices. Assist in mapping security controls to frameworks such as NIST, MITRE ATT&CK, PCI-DSS, ISO 27001, and other compliance standards. Document control descriptions, rationale, risk, and remediation guidance.
  • Security Research - Research emerging technologies and understand their security architecture. Identify important security configuration settings and recommend secure configurations. Continuously learn new technologies and industry security standards.
  • Content Maintenance - Review and update compliance content as security benchmarks and frameworks evolve. Understand existing Bash/Shell scripts used for compliance checks and perform basic modifications when required. Assist in validating compliance controls through testing and technical analysis.
  • Collaboration - Work closely with Product, Development, QA, and Infrastructure teams. Participate in technical discussions and contribute to improving compliance content quality. Support internal teams by analyzing compliance gaps and researching technical solutions.
Required Technical Skills
  • Linux (Primary Requirement)
  • Strong understanding of Linux operating systems.
  • Hands-on experience with at least one RHEL-based distribution (RHEL, CentOS, Rocky Linux, AlmaLinux).
  • Familiarity with at least one Debian-based distribution (Ubuntu or Debian).
  • Good understanding of: Linux filesystem hierarchy; users, groups, permissions, and ownership; SSH configuration; sudo configuration; PAM basics; Cron jobs; Syslog and logging; Disk partitions, filesystems, and mount management; Kernel parameters (sysctl); Basic understanding of SELinux concepts is desirable; Familiarity with Linux auditing (auditd, audit rules, ausearch, aureport) is a plus.
  • Security & Compliance
  • Basic understanding of operating system security concepts.
  • Familiarity with security hardening standards such as CIS Benchmarks and DISA STIG.
  • Awareness of security frameworks including: NIST, ISO 27001, PCI-DSS, MITRE ATT&CK.
  • Basic understanding of networking concepts.
  • Scripting
  • Ability to read, understand, and troubleshoot basic Bash/Shell scripts.
  • Basic scripting knowledge to make small modifications to existing scripts.
  • Familiarity with Regular Expressions (Regex) is desirable.
  • Additional Knowledge
  • Exposure to any of the following is a plus: Windows administration; macOS; Databases; APIs or Postman; Microsoft Security Compliance Toolkit (SCT).
  • Required Soft Skills
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication.
  • Curiosity and willingness to learn new technologies.
  • Strong attention to detail.
  • Ability to research technical topics independently.
  • Good collaboration and teamwork skills.
  • Positive attitude and ownership of assigned tasks.
  • Preferred Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 0-3 years of experience in Linux Administration, Cybersecurity, Technical Support, System Administration, or Compliance.
  • Linux certification (RHCSA, LFCS, Linux+).
  • Security certifications such as Security+. These are desirable but not mandatory.

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Research Analyst
Compliance Research Analyst

Qualys • Maharashtra

On-site
INR 600,000 - 900,000
Security Research Engineer
Security Research Engineer

Qualys • Pune District

On-site
INR 1,500,000 - 3,000,000
Senior Compliance & Research Analyst
Senior Compliance & Research Analyst

Qualys • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Lead Security Research Engineer
Lead Security Research Engineer

Qualys • Pune District

On-site
INR 1,800,000 - 2,400,000
Senior Security Research Engineer
Senior Security Research Engineer

Qualys • Maharashtra

On-site
INR 2,500,000 - 4,200,000
Lead Technical Support Engineer
Lead Technical Support Engineer

Qualys • Maharashtra

On-site
INR 900,000 - 1,300,000
Threat Research Engineer
Threat Research Engineer

Qualys • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Senior Product Manager, Security Research
Senior Product Manager, Security Research

Qualys • Pune District

On-site
INR 1,800,000 - 2,400,000
Senior Compliance & Research Analyst
Senior Compliance & Research Analyst

Qualys • Pune District

On-site
INR 1,500,000 - 2,100,000
Security Research Engineer
Security Research Engineer

Qualys • Maharashtra

On-site
INR 1,800,000 - 3,200,000