Qualys Security Engineer - 6 months - Inside IR35 - Hybrid in Southampton
Role Overview
A 6-month hybrid contract role based in Southampton (3 days on-site), for an experienced Qualys Security Engineer to refresh and re-baseline cloud vulnerability management capabilities across AWS, Azure, and GCP. The position is responsible for configuring and optimising Qualys VMDR, CSAM, and External Attack Surface Management (EASM) to ensure all in-scope cloud assets are onboarded, scanned, and aligned to remediation workflows. The role also covers BAU support, operational documentation, and stakeholder reporting across cloud, infrastructure, and security teams.
Key Responsibilities
- Refresh and re-baseline Qualys cloud integrations across AWS, Azure, and GCP, including configuration and validation of cloud connectors and asset discovery.
- Configure and optimise Qualys VMDR scanning, reporting, and External Attack Surface Management (EASM) capabilities.
- Support Cybersecurity Asset Management (CSAM) and align vulnerability findings with established remediation workflows.
- Develop dashboards, vulnerability reports, operational runbooks, and support documentation for ongoing BAU operations.
- Collaborate with cloud, infrastructure, and security stakeholders, providing guidance to junior team members on technical best practices.
Top 5 Skills
- Qualys VMDR expertise - 5/7 years of hands-on Qualys VMDR administration and vulnerability management, including scanning configuration, optimisation, and reporting.
- Multi-cloud integration - Proven experience integrating Qualys across AWS, Azure, and GCP environments, including cloud connector configuration and cloud asset discovery.
- CSAM & EASM - Hands-on experience with Cybersecurity Asset Management and External Attack Surface Management capabilities within Qualys.
- Scripting & automation - Proficiency in PowerShell or Python for automation and integration tasks, including ServiceNow or ITSM platform integration.
- Vulnerability remediation & frameworks - Strong understanding of the vulnerability remediation life cycle, with knowledge of security frameworks such as CIS, NIST, or ISO 27001 being a strong advantage.