Senior Security Research Engineer

Summary

Senior engineer in Qualys's Threat Research Unit doing vulnerability research, exploit analysis, and mitigation development, including patch diffing and reverse engineering with Ghidra/IDA across Windows, Linux, and macOS systems.

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

As a Senior Engineer, Security Research you will be part of a Qualys Threat Research Unit that is responsible for the research, development, and delivery of emergent vulnerability mitigation techniques. This opening is your opportunity to work on a unique security solution in the rapidly expanding fields of penetration testing, vulnerability assessments, and cyber security.

Responsibilities:

  • Research, analyze, and assess attack surface and vulnerability data.
  • Develop tailored and actionable mitigation strategies and plans to address vulnerability risk.
  • Work with new and emerging vulnerability data to identify potential attack paths in critical systems.
  • Document, develop and present mitigation strategies in web applications, databases, standalone applications, etc.
  • Analyze the root cause of vulnerabilities and support the prioritization of mitigations based on risk and return on mitigation.
  • Elevate AI strategies to provide mitigation strategies that prioritize risk against level of effort for multiple systems or organizations.
  • Patch diffing and reverse engineering with tools such as Ghidra, IDA, etc. \
  • Provide subject matter expertise on tailored mitigations to resolve and remediate vulnerabilities on targeted technologies.
  • Work in a fast-paced startup-like environment with shifting priorities to handle and maintain balance with multiple stakeholders.
  • Conduct research to assess and create software patches and configuration changes to be applied to varied software, middleware, and hardware.
  • Provide assessments including security, system, and business impact of vulnerabilities.
  • Must be able to think ahead to avoid business outages based on the lab results.
  • Analyze vulnerability data and support management of identified vulnerabilities, including tracking, remediation, and reporting.

Required Qualifications:

  • Graduate with a preferable 4-year degree or at least 3-year degree with computer science and information technology background.
  • Vulnerability research and exploit analysis.
  • Programming in any one of the following languages: PowerShell, Python, Shell.
  • Excellent understanding of network, system, and application security.
  • Excellent written and verbal communication and articulation skills.
  • Secure architecture designs and use of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) to mitigate risk.
  • Have working knowledge of basic operation systems commands and tooling - Windows, Linux, Mac OS.
  • Solid understanding of the security implications of a patch on web applications, Windows, Linux, Mac OS operating systems.

Preferred Skills:

  • Experience with IDA Pro, Ghidra, or similar binary analysis tools.
  • Knowledge of various vulnerability scanning solutions is a plus.
  • Specific demonstrated experience mapping business processes and comparing those processes to industry best practices.
  • Thorough testing of patches in a non-production environment.
  • Ability and ready to learn new technology and should be a good team player.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available