Senior Security Research Engineer
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!Senior Security Research Engineer, Vulnerability Research & Exploit ValidationAbout the TeamQualys is a recognized leader in cloud security and vulnerability management, trusted by thousands of organizations worldwide. Our Threat Research team is known for its work on vulnerability research, exploit analysis, and detection content that protects customers against real-world attacks.About the RoleWe are hiring a Senior Security Research Engineer to work on vulnerability research and exploit validation across a wide range of technologies, including operating systems, databases, enterprise applications, cloud services, container platforms, and network devices. You will research vulnerabilities, confirm whether they can be exploited in the real world, and turn that work into detection and protection content.This is a hands-on, senior individual-contributor role. You will own complex research projects, mentor other engineers, work closely with Engineering and Product, and help improve automation across the team. The role comes with real freedom to choose the research topics and areas you go deep on, along with clear opportunities to grow your career at Qualys.ResponsibilitiesResearch:Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices.Research newly disclosed, zero-day, and actively exploited vulnerabilities, and prioritize work based on real-world risk.Analyze root causes, attack vectors, exploitability conditions, and potential business impact.Review technical designs, research methods, and code contributions for quality and consistency.Exploit Validation & DetectionBuild exploit-based validation techniques that confirm whether vulnerabilities are exploitable in practice.Design safe, controlled validation methods that emulate attacker behavior without affecting production systems.Write validation logic that determines whether existing security controls such as WAFs, firewalls, EDRs, IPS, and compensating controls actually block exploitation.Set coding standards and quality guidelines for signature and detection content.Automation & ToolingImprove automation across vulnerability research, exploit validation, content generation, testing, and release.Find and apply ways to use AI and LLM to speed up research work.Improve tooling and workflows to raise research quality and output.Required Qualifications6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research.Strong background in vulnerability analysis, exploit development, and modern attack techniques.Solid understanding of core protocols, including TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols.Broad knowledge of operating systems, databases, web technologies, cloud environments, and ente...