Lead Security Engineer
QLYS_IN Qualys Security TechServices Private Ltd. · Pune, India
About The Role
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
We are seeking a passionate and detail-oriented Lead Security Engineer to join our Vulnerability Research Development team. As a Lead Security Engineer, you will join a motivated engineering research team responsible for researching, developing, and delivering detection signatures for our vulnerability scanning products. This opening is your opportunity to work in the rapidly expanding field of computer security with a company with excellent customer ratings and outstanding growth rates.
Responsibilities:
- Research vulnerabilities in the areas of applications, operating systems, databases, TCP/IP protocols, network devices, and various services.
- Develop, test, and maintain high-quality detections to detect known vulnerabilities and 0-day threats.
- Research new and emerging technologies to identify vulnerabilities and exploits.
- Drive technical direction, prioritization, and execution of detection development initiatives.
- Collaborate with security researchers, product teams, and QA engineers to ensure the timely delivery of detection content.
- Research Zero-day vulnerabilities and actively attack vulnerabilities to deliver fast detection content within hours of vulnerability disclosure.
- Act as a technical escalation point for complex vulnerability research and detection challenges.
- Stay up to date with the latest CVEs, advisories, and security intelligence feeds.
- Work with our Customer Support and Research teams to troubleshoot and triage customer issues such as false positives and false negatives.
Qualifications:
- 7+ years of industry experience in network and systems security.
- In-depth knowledge of TCP/IP, SSL, HTTP, FTP, SSH, DNS and others.
- Knowledge of OWASP top 10 and familiarity with other web-based attacks.
- Proficiency in at least one scripting language (Python, Bash, Go).
- Ability to quickly analyse proofs-of-concept or exploits and translate them into accurate signatures.
- Experience with network analysis tools, and analysis of packet captures.
- Knowledge of different Databases (Oracle, DB2, etc.) and system Administration.
- Strong understanding of VPN, Firewalls, Intrusion detection systems (IDS), and security tools.
- Excellent written and verbal communication skills.
Educational Qualification: BE/B.Tech/MCA, preferably in Computer Science, Information Technology, or a related field
Additional Plus Competencies:
- Experience with large-scale vulnerability management programs.
- Proficient with regular expressions and system administration.
- Demonstrated ability to drive strategic initiatives and independently own technical roadmaps.
- Knowledge of Cloud Platforms (AWS, Azure, Oracle, etc.).
- Knowledge of container technologies such as Docker and Kubernetes.
- OSCP, CISSP, or SANS GIAC certifications.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing