368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$27k – $62k per year (Estimated)
Location
In office (Pune)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Qualys, Inc. is a publicly traded enterprise cybersecurity, compliance, and IT solutions provider headquartered in Foster City, California. Founded in 1999 as a pioneer in SaaS-delivered vulnerability management, the company provides the Qualys Enterprise TruRisk Platform. Its single-agent cloud architecture unifies cybersecurity asset management, vulnerability management detection and response (VMDR), patch management, web application security, policy compliance, and cloud security across hybrid IT environments, public clouds, and containers.

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

About the Role

Qualys is seeking aSeniorVulnerabilityAnalystto join the Product Security Incident Response Team (PSIRT) as a hands-on technical practitioner. Reporting to the LeadVulnerabilityAnalyst, you will execute the day-to-day work ofvulnerabilitydiscovery, triage, analysis, and remediation tracking across a product portfolio of more than 35 products. Where the Lead owns program-level strategy, cross-functional accountability, and executive communications, this role is responsible for the depth and rigor of the technical analysis that underpins every PSIRT decision.

This is an individual contributor role for a mid-career security professional who thrives in the details: reviewing source code to assess exploitability, writing precise advisories, building detection logic, and driving engineering teams toward timely remediation. You will work across the fullvulnerabilitylifecycle, from initial intake through coordinated disclosure, and contribute directly to the tools, automation, and processes that make the PSIRT function scale.

Key Responsibilities

Vulnerability Analysis & Triage

  • Perform deep technical analysis of reported vulnerabilities, including root-cause investigation, exploitability assessment, CVSS and SSVC scoring, and impact determination across affected products.
  • Triage incomingvulnerabilityreports from internal scanners, SCA tooling, external researchers, and coordinated disclosure channels, ensuring accurate classification and priority assignment.
  • Analyze source code in C/C++, Java, and web application frameworks to validatevulnerabilityfindings and assess the effectiveness of proposed fixes.
  • Support major incident response efforts led by the LeadVulnerabilityAnalyst, providing technical depth during war-room triage of high-severity and zero-day vulnerabilities.

Detection, Monitoring & Threat Hunting

  • Build and maintain alerting rules and detection automation to identify known and emerging vulnerabilities in production products and services.
  • Continuously hunt for CVEs and CWEs affecting Qualys components, third-party dependencies, and container base images; document findings with reproducible analysis.
  • Monitor publicvulnerabilitydatabases, threat intelligence feeds, and researcher disclosures to proactively identify exposure across the product portfolio.
  • Investigatevulnerabilitytrends and systemic weakness patterns; surface findings to the LeadVulnerabilityAnalystto inform program-level priorities.
  • Coordinate with counterparts in Security Operations, including CERT

Remediation Tracking & SLA Compliance

  • Track engineering remediation efforts against defined patching SLAs, maintaining accurate status records for every openvulnerabilityacross product teams.
  • Coordinate the determination of Affected Status for vulnerabilities and their corresponding fix timelines, working directly with product engineering owners.
  • Review security exception requests, documenting technical justifications, compensating controls, and residual risk for Lead review and approval.
  • Prepare SLA conformance reports and delinquency summaries for leadership review.

Advisory Authoring & Coordinated Disclosure

  • Draft customer-facing Product Security Advisories (PSAs), ensuring technical accuracy, completeness, and consistency with PSIRT editorial standards.
  • Coordinate with security testing teams to validate compensating controls, verify fix effectiveness, and confirm exploitability status prior to advisory publication.
  • Support the CoordinatedVulnerabilityDisclosure (CVD) process by managing researcher communications, tracking disclosure timelines, and preparing disclosure packages under the direction of the Lead.

Toolchain & Process Improvement

  • Develop and enhance PSIRT tooling, including SCA and SAST integration workflows, SBOM analysis pipelines, container security, andvulnerabilitydata lake ingestion.
  • Maintain and improve PSIRT runbooks, triage playbooks, and standard operating procedures based on lessons learned and evolving threat landscape.
  • Build and refine dashboards and reporting artifacts that surfacevulnerabilityposture, remediation velocity, and trend data for leadership and audit consumption.

Required Qualifications

  • 5+ years of experience invulnerabilityanalysis, product security, application security, or security engineering.
  • 2+ years of experience operating within a PSIRT, CERT, or comparablevulnerabilitycoordination function.
  • Strong written and verbale communication skills and attention to detail in technical documentation.
  • Strong technical skills invulnerabilityanalysis, including root-cause investigation, exploitability assessment, and CVSS/SSVC scoring.
  • Demonstrated proficiency in operating system security (Linux), container security, and web application security.
  • Working knowledge of C/C++, Java, and SaaS platform architectures sufficient to perform code-levelvulnerabilityassessment.
  • Hands-on experience with CVE/CWE analysis workflows,vulnerabilitydatabases, and threat intelligence sources.
  • Experience drafting security advisories or technicalvulnerabilitywrite-ups for external audiences.

Preferred Qualifications

  • Experience with offensive security techniques, penetration testing, or red team operations.
  • Familiarity withvulnerabilityhanding standards and best practices.
  • Hands-on experience with SCA tools (e.g., Black Duck, Snyk, Trivy), SAST platforms, and SBOM tooling (SPDX, CycloneDX).
  • Familiarity with NIST SSDF, CoordinatedVulnerabilityDisclosure frameworks, and product security lifecycle models.
  • Experience building detection rules, alerting logic, or security automation in scripting languages such as Python or Go.
  • Exposure to data lake architectures, security telemetry pipelines, orvulnerabilityanalytics platforms.
  • Active participation in the security community through CTFs, research publications, conference presentations, or open-source contributions.
  • Relevant certifications such as OSCP, GPEN, GWAPT, CSSLP, or equivalent.

How This Role Relates to the Lead

The LeadVulnerabilityAnalystowns PSIRT program strategy, cross-functional escalation authority, executive reporting, and external disclosure relationships. TheSeniorVulnerabilityAnalystprovides the technical execution layer: performing the detailed analysis, writing the initial advisory drafts, building the detection and tracking infrastructure, and ensuring everyvulnerabilityhas a complete, auditable record from intake through closure. Together, the two roles form the analytical core of the PSIRT function.

Why Qualys

  • Join a PSIRT function that is purpose-built to operate at the intersection of engineering accountability and security excellence.
  • Work with a product portfolio that protects critical infrastructure across enterprise and government environments worldwide.
  • Shape thevulnerabilitymanagement practices of a company whose core mission is security.
  • Collaborate with a leadership team that values operational rigor, transparency, and continuous improvement.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Pune
$27k – $58k per year (Estimated) • In office • 3+ years exp • Saratov
C++
Java
C++
Qt
Java
Gradle
Maven
DevOps
CI/CD
Apply
Data Scientist 1 day ago
$25k – $56k per year (Estimated) • Remote • Bachelor's Degree • Moscow
C++
Python
SQL
AI/ML
Computer Vision
CUDA
CUDA Toolkit
TensorRT
DevOps
Docker
Git
Kubernetes
Apply
Web Developer 6 hours ago
$25k – $67k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
JavaScript
SQL
Java
Java
Spring Boot
Apply
$19k – $49k per year (Estimated) • In office • Full-Time • Moscow
C++
DevOps
Git
Management
Jira
Apply
$15k – $37k per year (Estimated) • In office • Full-Time • Moscow
C++
Lua
Python
DevOps
VirtualBox
Cybersecurity
Wireshark
Apply
$23k – $58k per year (Estimated) • In office • Full-Time • 6+ years exp • Pune
Java
Python
Databases
Apache Kafka
ClickHouse
DevOps
Alertmanager
Ansible
AWS
Azure
CI/CD
Configuration Management
Consul
Filebeat
Fluent Bit
GCP
Grafana
gRPC
Jenkins
Kubernetes
OpenTelemetry
Platform Engineering
Prometheus
Terraform
Cybersecurity
HashiCorp Vault
Cryptography
Vault
Apply
Lead SFDC Developer 5 days ago
$155k – $175k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Foster City
Apex
Apex
Lightning Web Components
Visualforce
DevOps
Bitbucket
CI/CD
Git
Cybersecurity
Okta
Qualys Cloud Platform
Marketing
Salesforce
Apply
$215k – $255k per year • Equity • In office • Full-Time • 16+ years exp • Bachelor's Degree • Foster City
DevOps
AWS
Azure
GCP
Platform Engineering
Cybersecurity
ISO 27001
Qualys Cloud Platform
Apply
$31k – $68k per year (Estimated) • In office • Full-Time • 10+ years exp • Pune
AI/ML
AI Agents
Cybersecurity
Qualys Cloud Platform
Design
Figma
Management
Jira
ServiceNow
Apply
$136k – $212k per year (Estimated) • In office • Full-Time • 5+ years exp • Georgia
Cybersecurity
HIPAA
ISO 27001
Qualys Cloud Platform
Apply
$12k – $27k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Pune
SQL
Analytics
Power BI
Tableau
Apply
$13k – $29k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Pune
JavaScript
Apex
Apex
MuleSoft
AI/ML
AI Agents
Edge AI
DevOps
AWS
Azure
Management
Draw.io
Marketing
Salesforce
Apply
$11k – $42k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Pune
ABAP
Apply
Data Architect 6 hours ago
$38k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Node JS
Python
SQL
JavaScript
Databases
Databricks
MongoDB
Redis
Apply
$23k – $62k per year (Estimated) • In office • Full-Time • 3+ years exp • Navi Mumbai • Pune
Python
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.