Qualys logo

Security Research Engineer

Qualys

On-site
Pune
Full-time
Senior
3+ yrs
Salary not listedPosted 5d ago

Real job — pulled straight from Qualys’s careers page · Verified August 29, 2026 · No reposts.

Job description

Qualys is hiring a Security Research Engineer — a full-time, based in Pune role. Apply directly on Qualys's careers page below.

Senior Security Research Engineer

Location: Pune

Time Type: Full time

Job Description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description:

We're hiring a vulnerability researcher for the Threat Research Unit at Qualys. You'll take vulnerabilities apart to understand exactly how they work, prove out what an attacker could do with them, and turn that into detections and mitigations that hold up on real customer systems. The work sits between offense and defense: writing proof-of-concept exploits to ground your analysis in fact, then using what you learn to build safe, reliable checks and design defenses that make whole classes of bugs harder to exploit.


 Responsibilities:

  • Analyze vulnerabilities down to the affected code path, trigger conditions, the primitive they yield, and what a patch actually changes.
  • Develop proof-of-concept exploits in the lab to establish reachability, reliability, and real-world impact, giving detection and mitigation work a concrete basis in what an attacker can achieve.
  • Build non-harmful checks that confirm whether a vulnerability is present on customer hosts. Use a distinguishing signal instead of a harmful payload, and deliver a clear verdict, a response taxonomy, a safety statement, and a false-positive analysis.
  • Assess mitigation bypasses. Given a vulnerability and a target's defenses (ASLR, DEP/NX, stack canaries, CFI, RELRO, sandboxing, and modern hardware mitigations), determine whether exploitation remains feasible and how.
  • Design and write stronger mitigations at two levels: killing bug classes and patching individual instances. This includes compiler and platform hardening, defense-in-depth, and design changes that make exploitation economically infeasible even when a bug survives.
  • Read and adapt public offensive and detection tooling, with a clear grasp of which parts are detection, which are payload, and which are load-bearing for a bypass.
  • Stand up matched vulnerable and patched lab environments for reproducible exploitation, regression testing, and mitigation validation.

Required Qualifications:

  • Minimum 3 year of experience in Vulnerability research.
  • BE/B.Tech/MCA, preferably in Computer Science, Information Technology, or a related field.
  • Native and binary exploitation. Practical command of memory-corruption classes: stack and heap overflows, use-after-free, double-free, type confusion, integer overflows, off-by-one, and format-string bugs. Comfortable with a debugger and disassembler/decompiler workflow (gdb with pwndbg or GEF, WinDbg, IDA, Ghidra, or Binary Ninja) and with pwntools or an equivalent.
  • Vulnerability-class fluency. Able to reason in terms of root-cause classes and run variant analysis.
  • Scripting and delivery. Proficient in at least one of Python, C/C++, Go, or Rust.
  • Clear technical writing. Able to document exploitation reasoning, verdict logic, residual risk, and known gaps, including an honest record of what you tried, where a constraint blocked the ideal approach, and what you shipped instead.
  • Working fluency with AI and LLM tools (such as Claude Code) as part of your day-to-day workflow.

Preferred Qualifications:

  • Published CVE research, exploit development, or coordinated disclosure.
  • Fuzzing experience.
  • Program analysis experience.
  • Reverse engineering or source-code review to pinpoint a patch's distinguishing change.
  • Authoring experience for a detection or scanning platform.
  • CTF background or an equivalent hands-on track record.
  • Reproducible lab orchestration (containers or VMs) for exploitation and mitigation fixtures.

Get Security Research Engineer jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
GE Appliances (Haier) logo

Senior AI Enablement Partner

Remote · US-eligible
✓ From careers page· 12m ago
GE Appliances (Haier) logo

Principal Applied AI Solutions Engineer

Louisville, KY
✓ From careers page· 12m ago
DigitalOcean logo

Senior Solutions Architect, AI/ML (Remote)

$150k–$186kRemote · US-eligible
✓ From careers page· 16m ago
Formlabs logo

Hardware Systems Integration Intern

$82k–$101kSomerville, MA
✓ From careers page· 21m ago

Frequently asked questions

What skills are required for Security Research Engineer at Qualys?

The required skills for Security Research Engineer at Qualys include: Python, C++, Go, Rust, AI, LLM.

What is the seniority level for Security Research Engineer at Qualys?

Security Research Engineer at Qualys is a Senior level position.

How do I apply for Security Research Engineer at Qualys?

You can view the full description and apply for Security Research Engineer at Qualys on EchoJobs: https://echojobs.io/job/qualys-senior-security-research-engineer-9orza.