Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Prevent issues from becoming incidents.
As a Lead Software Security Engineer, focusing on Web development, you will be part of a motivated security engineering team responsible for ensuring that Qualys products are built to the highest levels of security and trust. This is a senior role for developers with a passion for security who can build trustworthy and scalable software.
About Product Security at Qualys
The Product Security team operates differently. Our mission is to enable continuous improvement across the lifecycle of our product portfolio, so that Qualys can ensure the highest standards of verifiable security, trust, and compliance. Our function is to build a secure SDLC, uphold quality management objectives, and ensure predictable outcomes for customers, our company, and attackers. We find and resolve problems early, working in-line with development. This allows us to reduce friction, increase release velocity, all while keeping security front of mind and at your fingertips.
Responsibilities
- Collaborate on the development of Qualys' unparalleled platform by creating secure-by-default middleware, end-point components, and building tools for our team to succeed in helping others.
- Build high quality software adhering to secure architecture and design principles, ensuring that developers across Qualys can easily use your trustworthy and rugged work.
- Engineer trustworthy libraries, APIs, and microservices that deliver security improvements for a platform that processes over a hundred million transactions and terabytes of data daily.
- Aid in incorporating security into software designs as a first-class goal.
Qualifications
- Exceptional Java and frameworks experience like Spring Boot and Struts, Object Relationship Mapping (Hibernate), Object Oriented Programming principles.
- Good understanding of security development lifecycle principles, data structures and algorithms, application design, exposure to thick and thin (web) client development architecture.
- Proficiency in constructing scalable SaaS platforms utilizing microservices and distributed systems architecture.
- Expertise in RDBMS systems (preferably Oracle) and experience with NoSQL databases (preferably Cassandra).
- Skilled in the development and design of RESTful APIs for underlying microservices.
- Expertise in building business process automation, helping our company make informed decisions with security data and guardrails.
- Effective understanding of Hashing, Authentication, Symmetric Encryption, Asymmetric Encryption, Digital Signatures, and PKI.
- Knowledge of static code analysis tools and basic operations.
Bonus Points
- Secret pen tester or bug bounty champ.
- Passion for Test Driven Development, DevSecOps.
- Expertise in Identity Access Management (RBAC, OpenID Connect, OAuth 2.0), Encryption, privilege management.
Top Skills
What We Do
Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.
The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com