Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
https://bayt.page.link/N4P6p28c4fj9AdU58
Back to the job results

Lead Vulnerability Analyst

3 days ago 2026/09/10
Other Business Support Services
Create a job alert for similar positions
Job alert turned off. You won’t receive updates for this search anymore.

Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!


About the Role



Qualys is seeking a LeadVulnerabilityAnalystto serve as aseniortechnical leader within the Product Security Incident Response Team (PSIRT). This individual will own the end-to-end lifecycle ofvulnerabilityidentification, triage, coordination, and disclosure across the Qualys product portfolio. You will operate at the intersection of security engineering, incident response, and cross-functional program management, ensuring that Qualys products maintain the highest security posture for our global customer base.


This is a high-visibility role requiring deep technical expertise, collaboration, executive communication skills, and the judgment to navigate complexvulnerabilityscenarios under pressure. You will work closely with Engineering, Product Management, and Security leadership to drive accountability, accelerate remediation, and continuously mature the PSIRT function. This is a role for a mid-career professional that operates like an owner.


Key Responsibilities



Vulnerability Assessment & Incident Coordination


  • Assess and triage vulnerabilities reported through internal discovery, external researchers, and automated tooling across the Qualys product portfolio of more than 35 products.
  • Coordinate software incident handling across Engineering, Product, and Security teams in alignment with ISO/IEC 30111 and ISO/IEC 29147 standards.
  • Lead major incident response for high-severity and zero-day vulnerabilities, managing cross-functional war rooms through resolution.

Detection, Alerting & Trend Analysis


  • Instrument and operate alerting systems to detect production vulnerabilities in shipped products and services.
  • Hunt for CVEs and CWEs affecting Qualys components, dependencies, and third-party integrations; identify recurringvulnerabilitytrends and systemic weaknesses.
  • Enable and manage escalation workflows, ensuring critical findings reach decision-makers with appropriate context and urgency.

Policy, Compliance & SLA Enforcement


  • Review and enforce security policies governing test automation, build configurations, and production incident handling.
  • Coordinate the determination of Affected Status for vulnerabilities and their corresponding fix timelines
  • Assess engineering requests for security exceptions, documenting risk acceptance decisions and compensating controls.
  • Hold Product and Engineering teams accountable for patching within defined SLAs, tracking remediation velocity and reporting delinquencies to leadership.

Advisories & CoordinatedVulnerabilityDisclosure


  • Author, review, and publish Product Security Advisories (PSAs) in compliance with CSAF VEX format requirements.
  • Run the CoordinatedVulnerabilityDisclosure (CVD) process end-to-end, managing relationships with external researchers, CERTs, and industry partners.
  • Coordinate security testing and validation of compensating controls, fixes, and exploitability status prior to advisory publication.

Toolchain, Process & Continuous Improvement


  • Support the development and maturation of a best-in-class PSIRT toolchain, including SBOM analysis, SCA, SAST integration, container security, andvulnerabilitydata lake infrastructure.
  • Continuously improve PSIRT runbooks, standard operating procedures, and playbooks to increase response speed, consistency, customer communications, stakeholder management, and audit-readiness.
  • Contribute to the design and operationalization of metrics and dashboards that provide leadership visibility intovulnerabilityposture and remediation trends.

Required Qualifications



  • 7+ years of experience invulnerabilitymanagement, product security, application security, or security engineering.
  • 3+ years of experience leading or operating within a PSIRT, CERT, or comparable incident response function.
  • Demonstrated leadership in major incident handling, escalation management, and cross-functional coordination under time pressure.
  • Deep technical expertise in operating system security (Linux), container security, client-side product security, and web application security.
  • Strong domain knowledge of C/C++, Java, and SaaS platform architectures, with the ability to assessvulnerabilityimpact at the code level.
  • Hands-on experience with CVE/CWE analysis, CVSS scoring, SSVC scoring
  • Expertise managing, leading, or materially supporting CoordinatedVulnerabilityDisclosure Programs
  • Strong written and verbal communications skills, experience authoring customer-facing security advisories and communicating technical risk to executive and non-technical audiences.

Preferred Qualifications



  • Previous experience leading or contributing to offensive security, red teaming, or penetration testing operations.
  • Familiarity with NIST SSDF, CoordinatedVulnerabilityDisclosure, and product security framewroks
  • Experience with SCA tools (e.g., Black Duck, Snyk, Trivy), SAST platforms, and SBOM generation tooling (SPDX, CycloneDX).
  • Hands-on expertise in C/C++, Java, and SaaS platform architectures
  • Proficiency with data lake architectures, security telemetry pipelines, andvulnerabilityanalytics platforms.
  • Active participation in the broader security community through research publications, conference presentations, or open-source contributions.
  • Relevant certifications such as OSCP, OSCE, GPEN, GXPN, CSSLP, or equivalent.

Why Qualys



  • Join a PSIRT function that is purpose-built to operate at the intersection of engineering accountability and security excellence.
  • Work with a product portfolio that protects critical infrastructure across enterprise and government environments worldwide.
  • Shape thevulnerabilitymanagement practices of a company whose core mission is security.
  • Collaborate with a leadership team that values operational rigor, transparency, and continuous improvement.
This job post has been translated by AI and may contain minor differences or errors.

You’ve reached the maximum limit of 15 job alerts. To create a new alert, please delete an existing one first.
Job alert created for this search. You’ll receive updates when new jobs match.
Are you sure you want to unapply?

You'll no longer be considered for this role and your application will be removed from the employer's inbox.