- Location
- Pune, India
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Bachelor
- Source
- Workday
Description
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
As a Senior Engineer, Security Research you will be part of a Qualys Threat Research Unit that is responsible for the research, development, and delivery of emergent vulnerability mitigation techniques. This opening is your opportunity to work on a unique security solution in the rapidly expanding fields of penetration testing, vulnerability assessments, and cyber security.
Responsibilities:
- Research, analyze, and assess attack surface and vulnerability data.
- Develop tailored and actionable mitigation strategies and plans to address vulnerability risk.
- Work with new and emerging vulnerability data to identify potential attack paths in critical systems.
- Document, develop and present mitigation strategies in web applications, databases, standalone applications, etc.
- Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigation.
- Elevate AI strategies to provide mitigation strategies that prioritize risk against level of effort for multiple systems or organizations.
- Patch diffing and reverse engineering with tools such as Ghidra, IDA, etc. \
- Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologies.
- Work in a fast-paced startup-like environment with shifting priorities to handle and maintain balance with multiple stakeholders.
- Conduct research to assess and create software patches and configuration changes to be applied to varied software, middleware, and hardware.
- Provide assessments including security, system, and business impact of vulnerabilities.
- Must be able to think ahead to avoid business outages based on the lab results.
- Analyze vulnerability data and support management of identified vulnerabilities, including tracking, remediation, and reporting.
Required Qualifications:
- Graduate with a preferable 4-year degree or at least 3-year degree with computer science and information technology background.
- Vulnerability research and exploit analysis.
- Programming in any one of the following languages: PowerShell, Python, Shell.
- Excellent understanding of network, system, and application security.
- Excellent written and verbal communication and articulation skills.
- Secure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate risk.
- Have working knowledge of basic operation systems commands and tooling - Windows, Linux, Mac OS.
- Solid understanding of the security implications of a patch on web applications, Windows, Linux, Mac OS operating systems.
Preferred Skills:
- Experience with IDA Pro, Ghidra, or similar binary analysis tools.
- Knowledge of various vulnerability scanning solutions is a plus.
- Specific demonstrated experience mapping business processes and comparing those processes to industry best practices.
- Thorough testing of patches in a non-production environment.
- Ability and ready to learn new technology and should be a good team player.