Lead Security Research Engineer

qualysยท QLYS_IN Qualys Security TechServices Private Ltd.
Apply Now โ†—
๐Ÿ“ PuneFull time
Full timeQLYS_IN Qualys Security TechServices Private Ltd.

About this role

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

As a Lead Security Research Engineer, you will provide technical leadership for vulnerability research, exploit analysis, exposure validation, and vulnerability signature development across the Qualys security platform. You will lead initiatives to identify, validate, and prioritise security risks based on real-world exploitability, helping customers distinguish theoretical exposures from confirmed attack paths.
ย 

Responsibilities:

- Lead vulnerability research initiatives across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.
- Research newly disclosed, N-day, and actively exploited vulnerabilities.
- Lead the development of exploit-based exposure validation techniques to confirm real-world exploitability of vulnerabilities.
- Review technical designs, research methodologies, and code contributions to ensure quality and consistency.
- Partner with Engineering and Product teams to influence roadmap decisions and security content strategy.
- Design safe and controlled validation mechanisms that emulate attacker behavior without affecting production systems.
- Analyze vulnerability root causes, attack vectors, exploitability conditions, and potential business impact.
- Mentor and guide Security Research Engineers on vulnerability analysis, exploit analysis, and signature creation.
- Build validation logic capable of determining whether existing security controls such as WAFs, firewalls, EDRs, IPS, and compensating controls effectively prevent exploitation.
- Drive automation initiatives for vulnerability research, exploit validation, content generation, testing, and release processes.
- Establish best practices, coding standards, and quality guidelines for signature development.


Qualifications:
- Bachelor's degree in a relevant field (or equivalent experience).

- 8+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.
- Deep understanding of TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.
- Strong expertise in vulnerability analysis, exploit development, and attack techniques.
- Extensive knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure.
- Strong coding background.
- Experience with packet analysis, network troubleshooting, and protocol reverse engineering.
- Knowledge of OWASP Top 10, common attack techniques, and modern threat actor tactics.
- Excellent written, verbal, and technical communication skills.
- Demonstrated experience leading projects and mentoring technical teams.


Additional Plus Competencies:
Understanding of Lua (preferred), Bash, or Python.
Knowledge of Cloud Platforms (AWS, Azure, Oracle, etc.).
Proficient with regular expressions.
Knowledge of container technologies such as Docker and Kubernetes.
Experienced in the use of vulnerability scanners, IDS, and security tools.
OSCP, CISSP, or SANS GIAC certifications.

Frequently Asked Questions

Is the salary disclosed for the Lead Security Research Engineer position at qualys?
The salary for this Lead Security Research Engineer role at qualys is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Lead Security Research Engineer position at qualys located?
This Lead Security Research Engineer role at qualys is based in Pune. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Lead Security Research Engineer role at qualys full-time or part-time?
This is listed as a Full time position. It is posted as a Lead Security Research Engineer role in the QLYS_IN Qualys Security TechServices Private Ltd. department at qualys.
Which team or department does the Lead Security Research Engineer at qualys belong to?
This Lead Security Research Engineer position is part of the QLYS_IN Qualys Security TechServices Private Ltd. department at qualys. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Lead Security Research Engineer position at qualys?
Click the "Apply Now" button on this page. You will be redirected to qualys's official application portal hosted on workday where you can submit your application directly.
When was the Lead Security Research Engineer job at qualys posted?
This Lead Security Research Engineer position at qualys was posted on Jul 28, 2026. Apply as soon as possible โ€” early applications are often reviewed first.
Lead Security Research Engineer
qualys
Apply for this role โ†—

You'll be redirected to qualys's official application page on Workday.