Senior Security Research Engineer

QualysApplyPublished 2 days agoFirst seen 2 days ago
Apply

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

As a Senior Engineer, Security Research you will be part of a Qualys Threat Research Unit that is responsible for the research, development, and delivery of emergent vulnerability mitigation techniques. This opening is your opportunity to work on a unique security solution in the rapidly expanding fields of penetration testing, vulnerability assessments, and cyber security.  

Responsibilities:  

  • Research, analyze, and assess attack surface and vulnerability data.  
  • Develop tailored and actionable mitigation strategies and plans to address vulnerability risk. 
  • Work with new and emerging vulnerability data to identify potential attack paths in critical systems.  
  • Document, develop and present mitigation strategies in web applications, databases, standalone applications, etc.  
  • Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigation.  
  • Elevate AI strategies to provide mitigation strategies that prioritize risk against level of effort for multiple systems or organizations.  
  • Patch diffing and reverse engineering with tools such as Ghidra, IDA, etc. \
  • Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologies.  
  • Work in a fast-paced startup-like environment with shifting priorities to handle and maintain balance with multiple stakeholders.  
  • Conduct research to assess and create software patches and configuration changes to be applied to varied software, middleware, and hardware.  
  • Provide assessments including security, system, and business impact of vulnerabilities.  
  • Must be able to think ahead to avoid business outages based on the lab results.  
  • Analyze vulnerability data and support management of identified vulnerabilities, including tracking, remediation, and reporting.  

Required Qualifications:  

  • Graduate with a preferable 4-year degree or at least 3-year degree with computer science and information technology background.  
  • Vulnerability research and exploit analysis. 
  • Programming in any one of the following languages: PowerShell, Python, Shell. 
  • Excellent understanding of network, system, and application security. 
  • Excellent written and verbal communication and articulation skills. 
  • Secure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate risk. 
  • Have working knowledge of basic operation systems commands and tooling - Windows, Linux, Mac OS.  
  • Solid understanding of the security implications of a patch on web applications, Windows, Linux, Mac OS operating systems.  

Preferred Skills:

  • Experience with IDA Pro, Ghidra, or similar binary analysis tools. 
  • Knowledge of various vulnerability scanning solutions is a plus.  
  • Specific demonstrated experience mapping business processes and comparing those processes to industry best practices.  
  • Thorough testing of patches in a non-production environment.   
  • Ability and ready to learn new technology and should be a good team player.