Senior Security Research Engineer

Qualys

Maharashtra

On-site

INR 2,500,000 - 4,200,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Qualys is a recognized leader in cloud security and vulnerability management. We are hiring a Senior Security Research Engineer to drive vulnerability research, exploit validation, and detection content across operating systems, databases, enterprise apps, cloud services, containers, and network devices.

This is a hands-on, senior individual-contributor role. You will own complex research projects, mentor other engineers, and help improve automation across the team with a clear path for career

Qualifications

  • Minimum 6+ years in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong background in vulnerability analysis and exploit development.
  • Solid understanding of core protocols (TCP/IP, HTTP/S, DNS, TLS) and modern web tech.
  • Broad knowledge of OS, databases, cloud, and enterprise infra.
  • Experience with packet analysis and protocol reverse engineering.
  • Working knowledge of OWASP Top 10 and threat actor tactics.
  • Track record of leading projects and mentoring teammates.
  • Strong written and verbal communication skills.

Responsibilities

  • Lead vulnerability research across OSes, databases, apps, cloud services, containers, and network devices.
  • Research disclosed, zero-day, and exploited vulns; prioritize by real-world risk.
  • Analyze root causes, attack vectors, exploitability, and business impact.
  • Review designs, methods, and code for quality and consistency.
  • Build exploit-based validation techniques to confirm exploitability.
  • Design safe validation methods that emulate attackers without affecting production.
  • Write validation logic to test whether security controls block exploitation.
  • Set coding standards and guidelines for signatures and detection content.
  • Improve automation across research, validation, content generation, testing, and release.
  • Explore AI/LLM for speeding up research work.
  • Enhance tooling and workflows to raise research quality and output.

Skills

Vulnerability research
Exploit development
Threat analysis
Mentoring
Project leadership
Communication

Tools

Python
Bash

Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Senior Security Research Engineer, Vulnerability Research & Exploit Validation
About The Team

Qualys is a recognized leader in cloud security and vulnerability management, trusted by thousands of organizations worldwide. Our Threat Research team is known for its work on vulnerability research, exploit analysis, and detection content that protects customers against real-world attacks.

About The Role

We are hiring a Senior Security Research Engineer to work on vulnerability research and exploit validation across a wide range of technologies, including operating systems, databases, enterprise applications, cloud services, container platforms, and network devices. You will research vulnerabilities, confirm whether they can be exploited in the real world, and turn that work into detection and protection content.

This is a hands-on, senior individual-contributor role. You will own complex research projects, mentor other engineers, work closely with Engineering and Product, and help improve automation across the team. The role comes with real freedom to choose the research topics and areas you go deep on, along with clear opportunities to grow your career at Qualys.

Responsibilities
Research
  • Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
  • Research newly disclosed, zero-day, and actively exploited vulnerabilities, and prioritize work based on real-world risk.
  • Analyze root causes, attack vectors, exploitability conditions, and potential business impact.
  • Review technical designs, research methods, and code contributions for quality and consistency.
Exploit Validation & Detection
  • Build exploit-based validation techniques that confirm whether vulnerabilities are exploitable in practice.
  • Design safe, controlled validation methods that emulate attacker behavior without affecting production systems.
  • Write validation logic that determines whether existing security controls such as WAFs, firewalls, EDRs, IPS, and compensating controls actually block exploitation.
  • Set coding standards and quality guidelines for signature and detection content.
Automation & Tooling
  • Improve automation across vulnerability research, exploit validation, content generation, testing, and release.
  • Find and apply ways to use AI and LLM to speed up research work.
  • Improve tooling and workflows to raise research quality and output.
Required Qualifications
  • 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
  • Strong background in vulnerability analysis, exploit development, and modern attack techniques.
  • Solid understanding of core protocols, including TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
  • Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
  • Proficiency with Python and Bash scripting.
  • Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
  • Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics.
  • Track record of leading projects and mentoring technical teammates.
  • Strong written, verbal, and technical communication skills.
Preferred Qualifications
  • Experience applying AI or LLM to security research or detection engineering.
  • Contributions to CVEs, security advisories, open-source security tooling, or published research.
  • Relevant certifications such as OSCP, OSCE, OSED, or GXPN (nice to have, not required).
  • Experience building detection content or signatures for IPS, WAF, or EDR platforms.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Research Engineer
Senior Security Research Engineer

Qualys • Pune District

On-site
INR 4,000,000 - 7,000,000
Senior Security Research Engineer
Senior Security Research Engineer

Segment (Twilio) • Pune District

On-site
INR 1,200,000 - 1,600,000
Opportunities for professional development
Inclusive culture
Cutting-edge security research
Security Research Engineer
Security Research Engineer

Qualys • Pune District

On-site
INR 1,500,000 - 3,000,000
Lead Security Research Engineer
Lead Security Research Engineer

Qualys • Pune District

On-site
INR 1,800,000 - 2,400,000
Lead Security Research Engineer
Lead Security Research Engineer

Qualys • Maharashtra

On-site
INR 4,000,000 - 7,000,000
Threat Research Engineer
Threat Research Engineer

Qualys • Maharashtra

On-site
INR 1,500,000 - 2,100,000
Lead Security Research Engineer
Lead Security Research Engineer

Qualys, Inc. • Pune District

On-site
INR 2,800,000 - 3,600,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

Qualys • Maharashtra

On-site
INR 1,500,000 - 2,500,000
Senior Application Security Analyst
Senior Application Security Analyst

Qualys • Maharashtra

On-site
INR 1,800,000 - 3,200,000
Senior Web Application Security Engineer
Senior Web Application Security Engineer

Qualys • Maharashtra

On-site
INR 1,200,000 - 1,800,000