An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Qualys is seeking an experienced security leader to drive product security and secure engineering across globally distributed teams. You will influence roadmaps, translate complex risk to executive stakeholders, and manage large security budgets for a SaaS/cloud-native portfolio.
The ideal candidate has senior leadership experience in secure software, cloud security, and regulatory programs such as FedRAMP/DoD, with a proven track record of collaboration across engineering, product, and legal
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Deep expertise in product security, application security, cloud security, DevSecOps , software supply chain security, and secure software development lifecycle (SSDLC) practices.
Extensive knowledge of modern authentication and identity architectures including:
Deep understanding of modern security frameworks including:
10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.
Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.
Extensive experience working directly with:
Deep knowledge of:
Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.
Hands-on experience implementing and managing environments aligned to:
Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.
Demonstrated knowledge and practical experience supporting:
Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.
Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.
Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.
Strong understanding of:
Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications.
15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale.
Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including: