About this role
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
As a Senior Engineer, Security Research you will be part of a Qualys Threat Research Unit that is responsible for the research, development, and delivery of emergent vulnerability mitigation techniques. This opening is your opportunity to work on a unique security solution in the rapidly expanding fields of penetration testing, vulnerability assessments, and cyber security.
Responsibilities:
• Research, analyze, and assess attack surface and vulnerability data. • Develop tailored and actionable mitigation strategies and plans to address vulnerability risk. • Work with new and emerging vulnerability data to identify potential attack paths in critical systems. • Document, develop and present mitigation strategies in web applications, databases, standalone applications, etc. • Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigation. • Elevate AI strategies to provide mitigation strategies that prioritize risk against level of effort for multiple systems or organizations. • Patch diffing and reverse engineering with tools such as Ghidra, IDA, etc. \ • Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologies. • Work in a fast-paced startup-like environment with shifting priorities to handle and maintain balance with multiple stakeholders. • Conduct research to assess and create software patches and configuration changes to be applied to varied software, middleware, and hardware. • Provide assessments including security, system, and business impact of vulnerabilities. • Must be able to think ahead to avoid business outages based on the lab results. • Analyze vulnerability data and support management of identified vulnerabilities, including tracking, remediation, and reporting.
Required Qualifications:
• Graduate with a preferable 4-year degree or at least 3-year degree with computer science and information technology background. • Vulnerability research and exploit analysis. • Programming in any one of the following languages: PowerShell, Python, Shell. • Excellent understanding of network, system, and application security. • Excellent written and verbal communication and articulation skills. • Secure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate risk. • Have working knowledge of basic operation systems commands and tooling - Windows, Linux, Mac OS. • Solid understanding of the security implications of a patch on web applications, Windows, Linux, Mac OS operating systems.
Preferred Skills:
• Experience with IDA Pro, Ghidra, or similar binary analysis tools. • Knowledge of various vulnerability scanning solutions is a plus. • Specific demonstrated experience mapping business processes and comparing those processes to industry best practices. • Thorough testing of patches in a non-production environment. • Ability and ready to learn new technology and should be a good team player.