Role: Qualys Engineer
Location: Malvern, PA/Dallas, TX (Need to be local for F2F interview)
Duration: 6+ months contract
ROLE_DESCRIPTION
Bachelor's degree in computer science, Information Security, or related field.
3-5 years of experience in Vulnerability Management and Security Operations.
Hands-on experience with Qualys VMDR (Vulnerability Management, Detection and Response).
Strong understanding of:
o Vulnerability assessment methodologies
o CVSS scoring
o Security frameworks (NIST, CIS, ISO 27001)
o Patch management processes
o Network and system security concepts
Experience with Windows, Linux, and Cloud platforms (AWS, Azure, Google Cloud Platform).
Knowledge of TCP/IP, DNS, HTTP/HTTPS, Active Directory, and network protocols.
Experience with scripting languages such as Python, PowerShell, or Bash.
Ability to analyze and communicate technical security risks effectively.
Roles & Responsibilities
Administer and maintain the Qualys platform, including VMDR, Policy Compliance, Patch Management, and Asset Inventory modules.
Configure and manage Qualys scanners, scanner appliances, agents, and scan schedules.
Perform vulnerability assessments and analyze scan results across servers, endpoints, network devices, cloud environments, and applications.
Prioritize vulnerabilities based on risk, CVSS scores, threat intelligence, and business impact.
Coordinate with infrastructure, application, and cloud teams to drive remediation efforts.
Develop dashboards, reports, and metrics for security leadership and stakeholders.
Monitor compliance against security policies and regulatory requirements.
Conduct asset discovery and maintain accurate asset inventories.
Support security audits, risk assessments, and compliance initiatives.
Automate vulnerability management processes using APIs, scripting, and integrations.
Troubleshoot scan-related issues and optimize scanning performance.
Stay current with emerging vulnerabilities, threat landscapes, and Qualys feature enhancements.