Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Senior Penetration Tester, Endpoint Client Security @ Qualys

Home > Other

 Senior Penetration Tester, Endpoint Client Security

Job Description


Job Description:


We are seeking a skilled Penetration Tester to assess and enhance the security of our cross-platform executable Qualys Cloud Agent.

This agent is responsible for system monitoring, data collection, and secure communication with a cloud platform.

Operating across Unix, Windows, and macOS environments, the agent plays a critical role in our security and compliance solutions.

The ideal candidate will uncover vulnerabilities, simulate attack scenarios, and work with our teams to fortify the system against threats.


Key Responsibilities:


Cross-Platform Agent Testing:

  • Conduct comprehensive security testing of the executable agent, ensuring robust functionality across Unix/Linux, Windows, and macOS platforms.
  • Identify and exploit vulnerabilities in the agents runtime behavior, system interactions, and interprocess communications.
  • Test agent privilege management and evaluate risks of escalation or exploitation.

Data Collection and Handling:

  • Analyze the agents data collection mechanisms to ensure data privacy and integrity.
  • Validate proper implementation of sensitive data redaction and secure storage practices.

Communication Security:

  • Test the agents secure communication mechanisms with the cloud server, focusing on:
    • Encryption (TLS/SSL, public key cryptography).
    • Authentication and session management.
    • Mitigation of threats like MITM, replay attacks, and DNS spoofing.

Reverse Engineering and Exploitation:

  • Perform binary analysis to identify vulnerabilities in the agent's implementation.
  • Reverse engineer agent components to assess the effectiveness of tamper-proofing mechanisms and embedded security features.
  • Simulate advanced threat scenarios, including code injection and runtime manipulation.

System Security Evaluations:

  • Assess the agents impact on host system security, ensuring it does not inadvertently introduce risks (e.g., open ports, exploitable configurations).
  • Evaluate installation, update, and self-defense mechanisms for tamper resistance and exploitation risks.

Reporting and Remediation:

  • Provide detailed vulnerability reports with proof of concept (PoC), risk impact assessments, and actionable remediation steps.
  • Collaborate with development team to address vulnerabilities and validate fixes
  • Contribute to improving secure development practices and robust agent design.

Required Qualifications:


Technical Expertise:

  • In-depth knowledge of penetration testing methodologies for executable agents, system processes, and OS-specific security models (Windows, Unix/Linux, macOS).
  • Proficiency in network security and cryptographic protocol testing.
  • Strong background in reverse engineering tools and techniques

Tools & Scripting:

  • Scripting skills in Python, Bash, PowerShell, for creating custom tests.
  • Hands on experience with proxy solutions ex Burp or Fiddler

Experience:

  • Proven track record of assessing software agents or similar system monitoring tools.
  • Familiarity with common vulnerabilities, including CVEs related to agent-based applications.
  • Experience working with security tools or platforms similar to Qualys Agent.

Certifications (Preferred):

  • OSCP, OSWE, CEH, GPEN, or equivalent cybersecurity certifications.
  • Relevant cloud certifications such as AWS Security Specialty, Azure Security Engineer Associate.

Preferred Qualifications:

  • Hands-on experience with agent technologies similar to Qualys Cloud Agent.
  • Familiarity with cloud architecture, APIs, and integration points.
  • Knowledge of secure coding practices and defensive programming.
  • Experience with CI/CD pipeline security.

Job Classification

Industry: Hardware & Networking
Functional Area / Department: Other
Role Category: Other
Role: Other
Employement Type: Full time

Contact Details:

Company: Qualys
Location(s): Pune

+ View Contactajax loader


Keyskills:   Penetration Testing Penetration tester Endpoint Security web application security

 Fraud Alert to job seekers!

₹ Not Disclosed

Similar positions

Sap Security Consultant

  • Tata Consultancy
  • 5 - 10 years
  • Kolkata
  • 4 days ago
₹ Not Disclosed

Senior Programme Leader Animal Health & Welfare (Splahw)

  • Brooke
  • 5 - 10 years
  • Noida, Gurugram
  • 7 days ago
₹ Not Disclosed

Senior DevOps Engineer

  • SAP Servers Tech
  • 4 - 8 years
  • Bengaluru
  • 8 days ago
₹ Not Disclosed

Senior Business Development Executive

  • Cognizant
  • 3 - 8 years
  • Hyderabad
  • 17 days ago
₹ 4-9 Lacs P.A.

Qualys

Qualys, Inc., the leading provider of cutting edge cloud-based security provider is looking for highly skilled Signature Engineer for Cloud Security Compliance engineering team. Qualys was born in the cloud with a completely fresh approach to security. Qualys provides a hackers-eye view of the ...