Penetration Tester, Security Testing
Qualys
- Remote job
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Job Description:
We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.
This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.
Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.
The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.
Key Responsibilities:
Cross-Platform Agent Testing:
Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
Identify and exploit vulnerabilities in the agent’s runtime behavior, system interactions, and interprocess communications.
Test agent privilege management and evaluate risks of escalation or exploitation.
Data Collection and Handling:
Analyze the agent’s data collection mechanisms to ensure data privacy and integrity.
Validate proper implementation of sensitive data redaction and secure storage practices.
Communication Security:
Test the agent’s secure communication mechanisms with the cloud server, focusing on:
Encryption (TLS/SSL, public key cryptography).
Authentication and session management.
Mitigation of threats like MITM, replay attacks, and DNS spoofing.
Reverse Engineering and Exploitation:
Perform binary analysis to identify vulnerabilities in the agent's implementation.
Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
Simulate advanced threat scenarios, including code injection and runtime manipulation.
System Security Evaluations:
Assess the agent’s impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.
Reporting and Remediation:
Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
Collaborate with development team to address vulnerabilities and validate fixes
Contribute to improving secure development practices and robust agent design.
Required Qualifications:
Technical Expertise:
In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
Proficiency in network security and cryptographic protocol testing.
Strong background in reverse engineering tools and techniques
Tools & Scripting:
Scripting skills in Python, Bash, PowerShell, for creating custom tests.
Hands on experience with proxy solutions ex Burp or Fiddler
Experience:
Proven track record of assessing software agents or similar system monitoring tools.
Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
Experience working with security tools or platforms similar to Qualys Agent.
Certifications (Preferred):
OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.
Preferred Qualifications:
Hands-on experience with agent technologies similar to Qualys Cloud Agent.
Familiarity with cloud architecture, APIs, and integration points.
Knowledge of secure coding practices and defensive programming.
Experience with CI/CD pipeline security.
- Role : Senior Security Penetration Tester Location : Hyderabad / Pune (Hybrid) Shift : 4:30 PM IST - 1:30 AM IST (Supporting US & LatAm Stakeholders... ...services (S3, EC2, Lambda, API Gateway, SNS, etc.) - Thick Client/Desktop applications using reverse engineering techniques and...SuggestedHybrid workShift work
- ...Join us as a Penetration Tester in Barclays, responsible for supporting the successful delivery of... ...Infrastructure. APIs. Mobile Apps. Thick clients. MCPs/AI Agents/LLMs. Cloud environments. Understanding of the security mechanisms associated with Applications,...SuggestedPermanent employment
- ...is on a mission to stop breaches simplify security and shape the future of cyber defense. We... ...collaboration with U.S.-based teams and clients you will be expected to work during overlapping... ...solutions into enterprise SIEM SOAR and endpoint security ecosystems. Strong...SuggestedFull timeHybrid workWork at officeLocal areaRemote jobWorldwideHome office
- ...Join us as a “Senior Penetration Tester" at Barclays, where you'll spearhead the evolution of our... ...Web applications, APIs, mobile & Thick Clients Infrastructure and networks Virtualization... ...and Kubernetes) Understanding of the security mechanisms associated with Applications...SuggestedLong term contractPermanent employmentTemporary work
- ...our team and start your journey today! Security Engineer Job Description The... ...Protocol reverse engineering Conduct manual penetration testing including but not limited to:... ...secure and that we are protecting our clients from relevant cyber threats by proactively...SuggestedFull timeStart todayFlexible hours
- Description :The Security Engineer is the day-to-day execution arm of our security function... ..., and M365 : SIEM, EDR (Defender for Endpoint), CSPM, and cloud-native logging (CloudTrail... ...assessments and coordinate external penetration tests; manage findings to closure.- Support...Hybrid workWork at office
- ...30 years of financial experience and over 22000 partners we serve the worlds most sophisticated clients using leading technology and exceptional service. The APAC Security Operations/Engineering organization is seeking a junior to mid-level associate developer to join...Full timeWork at officeFlexible hours
- ...: Experienced (relevant combo of work and education) Product Security Engineer -/Pune - 7- to 10yrs Are you curious, motivated, and... ...information that we process in order to provide services to our clients. For specific information on how FIS protects personal...Full time
- ...implementing improvements Resource & Budget Management: Forecast and secure necessary technical resources (engineers, architects, QA, DevOps)... ...75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible...Full timeHybrid workWork at officeRemote jobFlexible hoursShift work
- ...Sr. Security Compliance Engineer Responsibilities Engineering & Implementation: Designing and implementing secure compliant... ...procedures relevant security standards best practices regulations and client requirements to identify gaps and provide remediation solutions....Full time
- ...Job Title: Cybersecurity Analyst / Security Operations Analyst Who are we Fulcrum Digital is an agile and next-generation... ...Microsoft Sentinel, Nessus, Sophos, and Microsoft Defender for Endpoint. Adept at investigating phishing threats, building insightful Power...Full time
- ...technologies that drive modern organizations. Since 2011 our mission hasnt changed were here to stop breaches and weve redefined modern security with the worlds most advanced AI-native platform. We work on large scale distributed systems processing almost 3 trillion events per...Full timeWork at officeLocal area
- ...respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: People Leader All Job Posting Locations: Pune...Full timeLocal area
- ...filings event transcripts expert calls news trade journals and clients own research content. The acquisition of Tegus by AlphaSense... ...We are seeking an experienced Senior Business Applications Security Engineer to join our growing Corporate Technology team. This is...Full timeRemote jobFlexible hoursShift work
- ...the world! Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! As Security Signature Engineer, you will be part of a motivated engineering team that is responsible for the research, development, and delivery...
- ...Are you ready to take the lead in cutting-edge security engineering projects? We are looking for a seasoned professional with deep Saviynt experience, a strong background in cyber security, and a genuine passion for driving innovation in our growing security practice....Full timeHybrid work
- ...Pentester Security Engineer Context: The position is within the Michelin CERT team (Computer Emergency Response Team) the cyber defense team of the Michelin Group. Its three missions are: - Prevent and anticipate threats prepare for cyber crises - Detect threats vulnerabilities...Full time
- ...software patches and configuration changes to be applied to varied software, middleware and hardware Provide assessment including security, system, and business impact of vulnerabilities Must be able to think ahead to avoid business outages based on the lab results...Remote jobFull timeShift work
- ...Description Network Security II Engineer II (Enterprise IT Manufacturing/OT) Platforms: Palo Alto NGFW (Strata) Zscaler (ZIA/ZPA) F5 BIG-IP WAF (ASM/AWAF) ServiceNow Shift: Flexible AMER EMEA or APAC time zones Role Summary Support day-to-day network security...Full timeInternshipFlexible hours
- ...Description Job Title: Network Security Engineer II Location: Onsite Role Summary Were seeking a Senior Network Security Engineer to enhance our global security posture focusing mainly on Palo Alto Zscaler WAF IoT/OT security and zero-trust architecture. You will...Full timeHybrid workRemote job
- ...you join us! Job Description Job Description Senior PAM Security Engineer Job Location – Pune / Bangalore Job Summary:... ...lifecycle and CI/CD pipelines. Conduct security assessments, penetration testing, and remediation planning for identity and access management...Hybrid workWork at officeLocal areaMonday to Thursday
- ...come together to support the most exciting missions in the world! Overview: We are seeking a highly skilled and experienced Senior Security Engineer to join our team. As a Senior Security Engineer, you will be responsible for designing, implementing, and maintaining security...Remote jobFor contractors
- ...Role Summary The Security Engineer will design support and enhance identity and access services across Active Directory Microsoft Entra and enterprise applications. This role requires strong technical depth advanced troubleshooting ability automation expertise and the capability...Full time
- Job Description :We're on the hunt for a talented Senior Product Security Cybersecurity Engineer to elevate our Product Security team. In... ...-depth security testing, including vulnerability assessments, penetration testing, and evaluations mandated by OEMs like Airbus and...Shift work
- ...Public Cloud Security Engineer Vulnerability & Exposure Management (MultiCloud) This is a senior technical leadership role at the intersection... ...management tools SIEM and centralised logging platforms Endpoint and workload protection technologies (EDR/XDR) Packet capture...Full timeShift work
- ..., testing, deployment and delivery. Conducts performance, load, security and service virtualization testing. What Part Will You Play?... ...Acts as a single point of contact for assigned moderately complex client projects with regard to test engineering activities. Coordinates...Full timeWorldwide
- ...Senior Engineer Cyber Product Security NielsenIQ is maturing its Application Security programs and is recruiting an Application Security Engineer who will be responsible for supporting the rollout of DevSecOps capabilities and practises across all geographies and business...Full timeLocal areaFlexible hours
- Role : Network Engineer L3 Palo Alto Security SpecialistSenior Level8+ Years ExperienceCCNP CertifiedDepartment : Information Technology / Network OperationsRole Level : L3 Senior Network EngineerExperience : 8+ Years (Networking), 4+ Years (Palo Alto NGFW)Certification : CCNP...Full timeHybrid workRemote jobFlexible hours
- ...integration testing deployment and delivery. Conducts performance load security and service virtualization testing. What Part Will You Play... ...as a single point of contact for assigned moderately complex client projects with regard to test engineering activities. Coordinates...Full timeWorldwide
- ...affordable data connectivity in over 190 countries. Nomad is available as an iOS or Android app or via getnomad.app. Overview: As Security Engineer on the Infrastructure Team at LotusFlare you will be responsible to drive the overall IT security standards across our cloud...Work at officeWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester, Security Testing. Be the first to apply!

