🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! Senior Security Research Engineer, Vulnerability Research & Exploit Validation About the Team Qualys is a recognized leader in cloud security and vulnerability management, trusted by thousands of organizations worldwide. Our Threat Research team is known for its work on vulnerability research, exploit analysis, and detection content that protects customers against real-world attacks. About the Role We are hiring a Senior Security Research Engineer to work on vulnerability research and exploit validation across a wide range of technologies, including operating systems, databases, enterprise applications, cloud services, container platforms, and network devices. You will research vulnerabilities, confirm whether they can be exploited in the real world, and turn that work into detection and protection content. This is a hands-on, senior individual-contributor role. You will own complex research projects, mentor other engineers, work closely with Engineering and Product, and help improve automation across the team. The role comes with real freedom to choose the research topics and areas you go deep on, along with clear opportunities to grow your career at Qualys. Responsibilities Research: Lead vulnerability research across operating systems, databases, enterprise applications, cloud services, container platforms, and network devices. Research newly disclosed, zero-day, and actively exploited vulnerabilities, and prioritize work based on real-world risk. Analyze root causes, attack vectors, exploitability conditions, and potential business impact. Review technical designs, research methods, and code contributions for quality and consistency. Exploit Validation & Detection Build exploit-based validation techniques that confirm whether vulnerabilities are exploitable in practice. Design safe, controlled validation methods that emulate attacker behavior without affecting production systems. Write validation logic that determines whether existing security controls such as WAFs, firewalls, EDRs, IPS, and compensating controls actually block exploitation. Set coding standards and quality guidelines for signature and detection content. Automation & Tooling Improve automation across vulnerability research, exploit validation, content generation, testing, and release. Find and apply ways to use AI and LLM to speed up research work. Improve tooling and workflows to raise research quality and output. Required Qualifications 6+ years of hands-on experience in vulnerability research, penetration testing, detection engineering, or security research. Strong background in vulnerability analysis, exploit development, and modern attack techniques. Solid understanding of core protocols, including TCP/IP, HTTP/HTTPS, FTP, SSH, SMTP, DNS, SSL/TLS, and modern web protocols. Broad knowledge of operating systems, databases, web technologies, cloud environments, and enterprise infrastructure. Proficiency with Python and Bash scripting. Experience with packet analysis, network troubleshooting, and protocol reverse engineering. Working knowledge of the OWASP Top 10, common attack techniques, and current threat actor tactics. Track record of leading projects and mentoring technical teammates. Strong written, verbal, and technical communication skills. Preferred Qualifications Experience applying AI or LLM to security research or detection engineering. Contributions to CVEs, security advisories, open-source security tooling, or published research. Relevant certifications such as OSCP, OSCE, OSED, or GXPN (nice to have, not required). Experience building detection content or signatures for IPS, WAF, or EDR platforms. Join our talent community and receive the latest Qualys news, content, and be first in line for new job opportunities. Join our Talent Community! Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. .
Here's how to pick the right one and stand out in your application.
144.883Jobs
31.687IN
81%EN
That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.
Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.
Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.
When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.