Penetration Tester, Security Testing
Qualys
- Remote job
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Job Description:
We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.
This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.
Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.
The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.
Key Responsibilities:
Cross-Platform Agent Testing:
Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
Test agent privilege management and evaluate risks of escalation or exploitation.
Data Collection and Handling:
Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
Validate proper implementation of sensitive data redaction and secure storage practices.
Communication Security:
Test the agent’s secure communication mechanisms with the cloud server, focusing on:
Encryption (TLS/SSL, public key cryptography).
Authentication and session management.
Mitigation of threats like MITM, replay attacks, and DNS spoofing.
Reverse Engineering and Exploitation:
Perform binary analysis to identify vulnerabilities in the agent's implementation.
Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
Simulate advanced threat scenarios, including code injection and runtime manipulation.
System Security Evaluations:
Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.
Reporting and Remediation:
Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
Collaborate with development team to address vulnerabilities and validate fixes
Contribute to improving secure development practices and robust agent design.
Required Qualifications:
Technical Expertise:
In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
Proficiency in network security and cryptographic protocol testing.
Strong background in reverse engineering tools and techniques
Tools & Scripting:
Scripting skills in Python, Bash, PowerShell, for creating custom tests.
Hands on experience with proxy solutions ex Burp or Fiddler
Experience:
Proven track record of assessing software agents or similar system monitoring tools.
Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
Experience working with security tools or platforms similar to Qualys Agent.
Certifications (Preferred):
OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.
Preferred Qualifications:
Hands-on experience with agent technologies similar to Qualys Cloud Agent.
Familiarity with cloud architecture, APIs, and integration points.
Knowledge of secure coding practices and defensive programming.
Experience with CI/CD pipeline security.
- ...Skills (Foundational Exposure/Knowledge) Basic understanding of endpoint protection concepts (antivirus, EDR, device compliance).... ...Understanding of SIEM concepts or log analysis. Broader knowledge of security frameworks (CIS, NIST) is beneficial but not required....Suggested
- ...worldwide. ZSers drive impact by bringing a client-first mentality to each and every... ...to ZS. What you'll do: Associate Security Architect in the Enterprise will be part... ...Consultant, you will be responsible for endpoint security, hardening, and automation. The...SuggestedFull timeNo agencyHybrid workLocal areaWork from homeWorldwideFlexible hoursAfternoon shift
- ...Lead Engineer / Endpoint Security Engineering, VP Position Overview Job Title: Lead Engineer / Endpoint Security Engineering, VP Location: Pune, India Role Description As a Lead Engineer, you will be responsible for driving endpoint security engineering...SuggestedFlexible hours
- ...Job Description Job Title: Endpoint Security Engineer (Intune & Defender) Location: Pune Department: Infra Security Experience: 5 to 7 years Reporting To: Technical Lead Manager Joining: Within a week or two Job Summary We are seeking a skilled and proactive...Suggested
- ...payments into a strategic advantage, helping clients optimize their payment experience to... ...our team extraordinary. Join us as a Security Engineer on our mission to turn payments... ...CrowdStrike and Twingate across all relevant endpoints and cloud workloads. DRP Readiness:...SuggestedRemote jobWorldwideShift work
- ...consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We... ...life-changing impact to ZS. Associate Consultant - Security Architecture & Engineering (Endpoint Security) The Security Architecture & Engineering Associate...Full timeNo agencyHybrid workLocal areaWork from homeWorldwideFlexible hoursAfternoon shift
- ...28 years helping organisations thrive through world‑class Cyber Security, IT & Cloud, and Automation solutions. With over 200 passionate... ...a 24x7 managed service providing round‑the‑clock protection to clients across a diverse range of industries. This is a hands-on...Remote jobShift workRotating shiftDay shift
- ...Job Title : Email Security Administrator - Level 2 Designation: Infrastructure Security... ...Diagnose and resolve email delivery issues, client connectivity problems, and other email-... ...years of experience in email operations, endpoint security, and device management. ~...Full timeWork at officeShift work
- ...global reach, and depth. How You'll Help Us: Our clients need digital solutions that will transform their business so they... ...years of experience in creating test plan for accessibility and security testing. ~2+ years of hands-on experience on cloud platforms...Contract workHybrid workWork at officeRemote jobFlexible hoursShift work
- ...Summary of This Role Install, configure, maintain, support, and secure the organization's network communications, including LANs and/or... ...in advanced Network project tasks with internal and external clients Provides mentorship to entry/lower level team members Assists...Full timeLocal areaWorldwide
- ...Delivery department, you will play a pivotal role in enhancing our SAP security posture. Your expertise will be instrumental in implementing... ...process. Provide expert guidance and support to clients, helping them navigate complex SAP security challenges and compliance...
- ...Information Risk Management LLP (PIRM) is a global player in Information Security, Cybersecurity, Compliance, and Risk Management solutions with a... ..., the USA, Asia, Europe, and the Middle East. Serving over 150 clients worldwide, PIRM operates a dedicated managed security testing...Full timeWorldwide
- ...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize... ...of the future. We are looking forward to hireSAP Security Professionals in the following areas : Job description...Flexible hours
- ...Job Title: Cybersecurity Analyst / Security Operations Analyst Experience: 4-8 years Summary: Detail-oriented and proactive Cybersecurity... ...Sentinel , Nessus , Sophos , and Microsoft Defender for Endpoint . Adept at investigating phishing threats, building insightful...
Rs 3.5 - 7 lakhs p.a.
...advisory solutions. The company's Offensive Security professionals focus on discovering and mitigating unique security risks for clients worldwide, using cutting-edge tools and... ...including web, mobile, API, and network penetration tests . You'll be the technical authority...Worldwide- ...JOB RESPONSIBILITIES: • Deliver offensive security services in at least two of the following... ...application, web application and wireless penetration testing and related technical security assessments. • Collaborate with clients, project management, and engagement...
- Join us as a 'Senior Penetration Tester' at Barclays, where you'll spearhead the evolution of our... ...Web applications, APIs, mobile & Thick Clients Infrastructure and networks Virtualization... ...and Kubernetes) Understanding of the security mechanisms associated with Applications...Long term contractTemporary work
- ...Introduction In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep... ...Expertise Senior SOC Analyst must have skills in email security, system event, network event, log analysis. Knowledge of common...
- ...Job Summary: We are looking for an experienced Security Specialist with deep expertise in Identity and Access Management (IAM) and... ...~ Broad exposure across cyber security domains such as network, endpoint, cloud, and identity security ~ Strong understanding of security...Hybrid work
- ...Continuous Learning: Access to training, certifications, and global security conferences. Cutting-Edge Tools: Work with advanced platforms... ...cross-border exposure. Mission & Impact: Protect sensitive client data and ensure the resilience of a leading law firm....Full timeFlexible hours
Rs 3 - 6 lakhs p.a.
...Must have 6+ years of SAP Security and/or GRC support and implementation experience Hands-on experience on SAP Security and Authorizations... ...on building a custom ruleset based on the requirement from the client. Should have experience in managing complex workflows and...Rs 7 - 12 lakhs p.a.
...We are actively seeking a highly experienced and technically proficient Security L3 Engineer to join our client's team through Acme Services . This pivotal role requires strong expertise in a diverse range of security technologies, including Palo Alto, Juniper SRX, Fortigate...- ...We are seeking a highly skilled and motivated Senior Hybrid Security Engineer to own the architecture and operations of Prisma Access while... ...policies to reduce noise and improve response fidelity. Endpoint/XDR Integration Partner with endpoint owners to deploy and...Hybrid workRemote job
- ...About the role: We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives... ...(e.g., VRA, security checklists) required by new BFSI clients. Analyse and complete detailed cloud infrastructure security...
Rs 12 - 28 lakhs p.a.
...Define and maintain enterprise security architecture standards and reference architectures across on-premises, cloud infrastructure, SaaS... ...custom applications. Design secure solutions covering network, endpoint, cloud security, identity and access management, privileged access...Contract work- ...Pune, Maharashtra 411045 Job Title: Security Engineer Job Type: Full-time Reports... ...will be responsible for firewall and endpoint security, WAF implementation, VAPT, fraud... ...Perform Vulnerability Assessments & Penetration Testing (VAPT) on infrastructure, applications...Full timeHybrid workWork at office
- ...markets, investment banking, and institutional securities. We're scaling toward an elite team of 50... ...to protect enterprise platforms using endpoint security technologies, with a primary... ...workstations, laptops, virtual machines, and thin clients running Windows, Linux, and UNIX. You...Full timeLocal area
Rs 3 - 5 lakhs p.a.
...Job Summary We are seeking a Product Security Engineer who will work in the Product Security... ...for highly Vulnerability Analysis and Penetration testing. This role requires an understanding... ...and Penetration testing of Web / Thick client / Mobile applications used in critical infrastructure...Hybrid workWork at officeLocal areaRemote jobWork from homeRs 3 - 8 lakhs p.a.
...Key Responsibilities: Lead Architect to provide the solutions to clients. Requirement gathering and designing. Experience in deployment Implementation of IIQ based on Customer needs. Liaison with teams on delivery, helping them on issue technical issue, bugs fixing...Full time- Job Title: Security Engineer / Cybersecurity Specialist Role Overview We are seeking an experienced and proactive Security Engineer... .... The ideal candidate will have strong hands-on experience with endpoint security, threat detection, vulnerability management, and SOC coordination...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester, Security Testing. Be the first to apply!

