Senior Web Application Security Signature Engineer
About this role
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
ResponsibilitiesÂ
In this position, you will primarily be researching and implementing detections for vulnerabilities on all the latest web application technologies. You will also be expected to fine-tune existing logic and payloads to detect vulnerabilities and CVEs with zero false positives for the Qualys Web Application Security product. Efficient problem-solving and troubleshooting skills are necessary, as well as using the latest tools in the industry.
Â
Required Skills:Â
* 3-5 years of industry experience in web application securityÂ
* Create exploits, proof-of-concept for web application vulnerabilitiesÂ
* Strong JavaScript programming skillsÂ
 * Knowledge of HTTP protocol (Requests, responses, Cookies, etc.) Â
* Understanding of web application vulnerabilities, OWASP top 10 in Web Applications, API, and LLMsÂ
* Exposure to DAST/BlackBox toolsÂ
* Web application security scanning tools like BURP/ZAP, SQLMap, CURLÂ
* Experience with network analysis tools and analysis of packet captures.Â
* Proficient with regular expressions.Â
* System administrator experience on Windows or Unix platforms.  Â
* Strong analytical and problem-solving skillsÂ
* Passion for web security and attention to detail
* Experience with scripting languages, including Python and Bash  Â
* Exposure to JAVA programming  Â
* Experience with selenium, postman scriptingÂ
* Experience with Metasploit/Nessus exploits (especially HTTP-related )Â
* Experience with web application firewalls (WAF) rules, ModSecurityÂ
* Exposure to WEB 2.0, XML/XPath, JSON, Swagger Â
* Database/SQL knowledgeÂ
* Experienced in the use of various scanners and open-source security tools.Â
* Experience in developing security-related tools/programs.Â
* Ability to work independentlyÂ
* Published research Â
* Security certificationsÂ
Frequently Asked Questions
Is the salary disclosed for the Senior Web Application Security Signature Engineer position at qualys?
Where is the Senior Web Application Security Signature Engineer position at qualys located?
Is the Senior Web Application Security Signature Engineer role at qualys full-time or part-time?
Which team or department does the Senior Web Application Security Signature Engineer at qualys belong to?
How do I apply for the Senior Web Application Security Signature Engineer position at qualys?
You'll be redirected to qualys's official application page on Workday.