Lead Security Engineer

Open 36d posting dated 7 days ago

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

As a Lead Engineer, Security Signatures you will be part of a Qualys Threat Research Unit that is responsible for the research, development, and delivery of emergent vulnerability signatures. This opening is your opportunity to work on a unique security solution in the rapidly expanding fields of penetration testing, vulnerability assessments and cyber security.

Responsibilities

  • Research and create signatures for the Qualys product to detect vulnerabilities in Industrial Control Systems.

  • Research new and emerging technologies to identify vulnerabilities and exploits.

  • Research zero-day and actively attack vulnerabilities to create signatures to identify vulnerable assets.

  • Build automation for day-to-day tasks.

Qualifications

  • Experience and strong knowledge in penetration testing and vulnerability management.

  • Knowledge and hands on experience with several types of security vulnerabilities and attacks such as cross-site scripting, privilege escalation, remote code execution.

  • Proficient with regular expressions.

  • Bachelor's in computer science with 5+ years of experience in Information Security domain or Masters in Computer Science or Cyber Security.

  • In-depth knowledge of TCP/IP, HTTP, DNS, FTP, SSH, TLS/SSL, and SMTP protocols.

  • Experience with scripting languages, including Python and Bash.

  • Experience with network analysis tools, analysis of packet captures.

  • System administrator experience on Windows or Unix platforms.

  • Excellent written and verbal communication skills.

Additional Plus Competencies

  • Understanding of Lua (preferred), or Python

  • Knowledge of Virtualization software (VMWare, Virtual PC/Virtual Box, XEN, etc.).

  • Knowledge of container technologies such as Docker and Kubernetes.

  • Able to handle projects independently.

  • Experienced in the use of vulnerability scanners, IDS, and multiple security tools.

  • Experience in developing security-related tools/programs.

  • OSCP and similar certifications.