Web Application Security Signature Engineer

Pune · On-site

About this role

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Responsibilities 
In this position, you will primarily be researching and implementing detections for vulnerabilities on all the latest web application technologies. You will also be expected to fine-tune existing logic and payloads to detect vulnerabilities and CVEs with zero false positives for the Qualys Web Application Security product. Efficient problem-solving and troubleshooting skills are necessary, as well as using the latest tools in the industry.

 

Required Skills: 

3-5 years of industry experience in web application security 

Create exploits, proof-of-concept for web application vulnerabilities 

Strong JavaScript programming skills 

  Knowledge of HTTP protocol (Requests, responses, Cookies, etc.)  

Understanding of web application vulnerabilities, OWASP top 10 in Web Applications, API, and LLMs 

Exposure to DAST/BlackBox tools 

Web application security scanning tools like BURP/ZAP, SQLMap, CURL 

Experience with network analysis tools and analysis of packet captures. 

Proficient with regular expressions. 

System administrator experience on Windows or Unix platforms.   

Strong analytical and problem-solving skills 

Passion for web security and attention to detail

Experience with scripting languages, including Python and Bash   

Exposure to JAVA programming   

Experience with selenium, postman scripting 

Experience with Metasploit/Nessus exploits (especially HTTP-related ) 

Experience with web application firewalls (WAF) rules, ModSecurity 

Exposure to WEB 2.0, XML/XPath, JSON, Swagger  

Database/SQL knowledge 

Experienced in the use of various scanners and open-source security tools. 

Experience in developing security-related tools/programs. 

Ability to work independently 

Published research  

Security certifications 

Company at a glance

Qualys, Inc. (NASDAQ: QLYS) is a leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.

The Qualys Enterprise TruRisk Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices.

Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com.

Founded1999
Team Size1,001-5,000 employees
WorkspaceOn-site
IndustryComputer and Network Security
Location
pune, Maharashtra, India
Websitequalys.com
LinkedInLinkedIn

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?