Penetration Tester, Security Testing
Qualys
- Remote job
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Job Description:
We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.
This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.
Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.
The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.
Key Responsibilities:
Cross-Platform Agent Testing:
Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
Test agent privilege management and evaluate risks of escalation or exploitation.
Data Collection and Handling:
Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
Validate proper implementation of sensitive data redaction and secure storage practices.
Communication Security:
Test the agent’s secure communication mechanisms with the cloud server, focusing on:
Encryption (TLS/SSL, public key cryptography).
Authentication and session management.
Mitigation of threats like MITM, replay attacks, and DNS spoofing.
Reverse Engineering and Exploitation:
Perform binary analysis to identify vulnerabilities in the agent's implementation.
Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
Simulate advanced threat scenarios, including code injection and runtime manipulation.
System Security Evaluations:
Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.
Reporting and Remediation:
Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
Collaborate with development team to address vulnerabilities and validate fixes
Contribute to improving secure development practices and robust agent design.
Required Qualifications:
Technical Expertise:
In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
Proficiency in network security and cryptographic protocol testing.
Strong background in reverse engineering tools and techniques
Tools & Scripting:
Scripting skills in Python, Bash, PowerShell, for creating custom tests.
Hands on experience with proxy solutions ex Burp or Fiddler
Experience:
Proven track record of assessing software agents or similar system monitoring tools.
Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
Experience working with security tools or platforms similar to Qualys Agent.
Certifications (Preferred):
OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.
Preferred Qualifications:
Hands-on experience with agent technologies similar to Qualys Cloud Agent.
Familiarity with cloud architecture, APIs, and integration points.
Knowledge of secure coding practices and defensive programming.
Experience with CI/CD pipeline security.
- ...Skills (Foundational Exposure/Knowledge) Basic understanding of endpoint protection concepts (antivirus, EDR, device compliance).... ...Understanding of SIEM concepts or log analysis. Broader knowledge of security frameworks (CIS, NIST) is beneficial but not required....Suggested
- ...Excellence, Balewadi, Pune, Maharashtra 411045 Job Title: Security Engineer (Penetration Tester) Job Type: Full-time Reports To: Security Architect... ...ideal candidate will be responsible for firewall and endpoint security, WAF implementation, VAPT, fraud investigation,...SuggestedFull timeHybrid workWork at office
- ...Lead Engineer / Endpoint Security Engineering, VP Position Overview Job Title: Lead Engineer / Endpoint Security Engineering, VP Location: Pune, India Role Description As a Lead Engineer, you will be responsible for driving endpoint security engineering...SuggestedFlexible hours
- ...vulnerability assessment and penetration testing tools such as Nessus,... ...understanding of networking concepts and security engineering principles... ...) or GPEN (GIAC Penetration Tester) Strong technical writing... ...identify security weaknesses in client systems and infrastructure...Suggested
- ...solution! Join us to make your contribution. AGCO is looking to hire candidates for the position of Sr. Penetration Tester. At AGCO, the Product Security team is at the forefront of securing our next-generation agricultural machinery. Our core mission is to...SuggestedWorldwideFlexible hours
- ...Fortinet is a worldwide provider of network security appliances and the market leader in... ...software, intrusion prevention systems and endpoint security components. Fortinet is headquartered... ...to communicate effectively with various clients with the ability to explain and elaborate...Hybrid work
Rs 1 - 3 lakhs p.a.
...Provide expert technical support for a wide range of security products and solutions to internal teams and/or clients. Firewall Management: Install, configure,... ...hands-on experience in F5 and Citrix Netscaler. Endpoint Security: Diagnose and resolve issues related to endpoint...- ...consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We... ...life-changing impact to ZS. Associate Consultant - Security Architecture & Engineering (Endpoint Security) The Security Architecture & Engineering Associate...Full timeNo agencyHybrid workLocal areaWork from homeWorldwideFlexible hoursAfternoon shift
- ...in IBM Consulting is built on long-term client relationships and close collaboration worldwide... ...Integrate threat intelligence into security monitoring systems to enhance proactive threat... ..., zoning, integration aspects, API, endpoint security, data security, compliance, and...Long term contractHybrid workWorldwide
- ...Join us as a Penetration Tester in Barclays, responsible for supporting the successful delivery of... ...Infrastructure. APIs. Mobile Apps. Thick clients. MCPs/AI Agents/LLMs. Cloud environments. Understanding of the security mechanisms associated with Applications,...Permanent employment
- ...Job Title : Email Security Administrator - Level 2 Designation: Infrastructure Security... ...Diagnose and resolve email delivery issues, client connectivity problems, and other email-... ...years of experience in email operations, endpoint security, and device management. ~...Full timeWork at officeShift work
- ...Summary of This Role Install, configure, maintain, support, and secure the organization's network communications, including LANs and/or... ...in advanced Network project tasks with internal and external clients Provides mentorship to entry/lower level team members Assists...Full timeLocal areaWorldwide
- ...75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation... ..., with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our...Hybrid workWork at officeRemote jobFlexible hours
- ...management trading system, which allows clients to completely control and customize their... ...Vulnerability Management Engineer to strengthen our Security Operations function. You will own the end... ...remediation coordination—across servers, endpoints, cloud workloads, and network...Permanent employmentFull time
- ...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize... ...of the future. We are looking forward to hireSAP Security Professionals in the following areas : Job description...Flexible hours
Rs 7.87 - 13 lakhs p.a.
...Technologies is a leading technology integrator specializing in helping clients reimagine operating models, enhance competitiveness, optimize... ...of the future. We are looking forward to hire SAP Security Professionals in the following areas : Job Description Experience...Flexible hours- ...Information Risk Management LLP (PIRM) is a global player in Information Security, Cybersecurity, Compliance, and Risk Management solutions with a... ..., the USA, Asia, Europe, and the Middle East. Serving over 150 clients worldwide, PIRM operates a dedicated managed security testing...Full timeWorldwide
- ...Job Title: Cybersecurity Analyst / Security Operations Analyst Experience: 4-8 years Summary: Detail-oriented and proactive Cybersecurity... ...Sentinel , Nessus , Sophos , and Microsoft Defender for Endpoint . Adept at investigating phishing threats, building insightful...
- ...Join us as a “Senior Penetration Tester" at Barclays, where you'll spearhead the evolution of our... ...Web applications, APIs, mobile & Thick Clients Infrastructure and networks Virtualization... ...and Kubernetes) Understanding of the security mechanisms associated with Applications...Long term contractTemporary work
- ...JOB RESPONSIBILITIES: • Deliver offensive security services in at least two of the following... ...application, web application and wireless penetration testing and related technical security assessments. • Collaborate with clients, project management, and engagement...
- ...worldwide. ZSers drive impact by bringing a client-first mentality to each and every... ...to ZS. What you'll do: Perform security assessments (including some ethical hacking... ...in information security, as an analyst, penetration tester or operator of security systems. ~...Full timeNo agencyHybrid workLocal areaRemote jobWork from homeWorldwideFlexible hours2 days week3 days week
- ...background support. That's what we do. And we do it for private clients, institutions, and corporations around the world. We have about... ...is a global organization within the Tech Information Security Office. Our services focus on cybersecurity monitoring, incident...Work at office
- ...About The Role The Senior Security Engineer role is a highly technical position responsible for strengthening the organization's cybersecurity posture through robust infrastructure, endpoint, and cyber security measures. The role requires strong expertise in Zero Trust implementation...Hybrid workWork at officeRemote job
Rs 3 - 6 lakhs p.a.
...Must have 6+ years of SAP Security and/or GRC support and implementation experience Hands-on experience on SAP Security and Authorizations... ...on building a custom ruleset based on the requirement from the client. Should have experience in managing complex workflows and...Rs 12 - 28 lakhs p.a.
...Define and maintain enterprise security architecture standards and reference architectures across on-premises, cloud infrastructure, SaaS... ...custom applications. Design secure solutions covering network, endpoint, cloud security, identity and access management, privileged access...Contract work- ...Job Description The Role: The Senior Security Engineer is a critical role within Security Engineering & Cyber Security, responsible... ...Provide technical oversight of enterprise security toolsets spanning endpoint, server, identity, email, network, cloud, and detection &...Long term contractFull timeHybrid work
- ...About the role: We are seeking a hands-on Security & Compliance Lead to own and execute end-to-end security audits and compliance initiatives... ...(e.g., VRA, security checklists) required by new BFSI clients. Analyse and complete detailed cloud infrastructure security...
Rs 5 - 8 lakhs p.a.
...We are seeking an experienced Microsoft Security Professional to safeguard and optimize the organization's digital environment. This role... ...Deploy and manage security solutions: Microsoft Defender for Cloud, Endpoint, Identity, Office 365, Cloud Apps, and Microsoft Sentinel....Hybrid workWork at office- Obsessed with security Are you looking for a new opportunity to channel your security expertise into building, integrating, and automating... ...build, integrate and automate security controls from cloud to endpoint. Act as a subject matter expert while partnering with Corporate...
- ...to contribute to the development, deployment, and integration of security tooling across our infrastructure. This role is instrumental in... ...Response, secrets management, application security scanning systems, endpoint protection systems and others. Develop and maintain custom...Contract workLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester, Security Testing. Be the first to apply!

