Senior Security Engineer — Deployment & Administration
VaporVM · Riyadh, Saudi Arabia
Apply & track with Apply EdgeSenior Security Engineer — Deployment & AdministrationExperience: 5+ YearsWe are seeking a Senior Security Engineer with strong hands-on expertise in Qualys platform deployment, administration, vulnerability management, and security integrations. The role will focus on designing, implementing, and optimizing Qualys solutions across on-premises, cloud, and hybrid environments, while supporting clients in strengthening their overall security posture.Key ResponsibilitiesLead Qualys deployment, onboarding, architecture, and rollout planning for enterprise clients.Deploy and manage Qualys Cloud Agents, Scanner Appliances, Passive Sensors, and Cloud Connectors.Configure and administer Qualys VMDR, Policy Compliance (PC), Patch Management (PM), WAS, and CSAM.Design and optimize authenticated/unauthenticated scans, credentials, schedules, scan performance, and asset coverage.Manage asset tags, dynamic asset groups, dashboards, reports, business-unit structures, RBAC, users, subscriptions, and licensing.Integrate Qualys with SIEM, ITSM, CMDB, ServiceNow, Jira, and other enterprise platforms using APIs and connectors.Support vulnerability remediation through validation, false-positive analysis, exception management, and re-scan verification.Develop risk-based vulnerability reports and scorecards aligned with remediation SLAs and business requirements.Ensure vulnerability and compliance assessments align with ISO 27001, NCA ECC, SAMA CSF, PCI DSS, and CIS Benchmarks.Provide technical troubleshooting, documentation, client support, and technical guidance throughout the deployment lifecycle.Required Qualifications & Skills5+ years of experience in Vulnerability Management, with 3+ years of hands-on Qualys experience.Strong expertise in Qualys VMDR and at least two of PC, PM, WAS, or CSAM.Hands-on experience with Qualys Cloud Agents, Scanner Appliances, Passive Sensors, and platform architecture.Experience with Qualys REST/XML APIs and integrations with SIEM, ITSM, and CMDB platforms.Strong understanding of TCP/IP, firewalls, network segmentation, Windows, Linux, AWS, and Azure.Good knowledge of CVE, CVSS, vulnerability prioritization, risk assessment, and remediation.Familiarity with ISO 27001, PCI DSS, CIS Benchmarks, NCA ECC, and/or SAMA CSF.Strong troubleshooting, documentation, stakeholder management, and client-facing communication skills.