Compliance Research Analyst
Qualys
- Location
- Pune
- Work model
- On-Site
- Level
- Mid
- Posted
- Aug 20, 2026
Skills
About this role
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! We are looking for a motivated and detail-oriented Compliance Research Analyst to join our team. This role is ideal for candidates with 0–3 years of experience who have a strong foundation in Linux administration and an interest in cybersecurity, compliance, and security best practices. The primary responsibility of this role is to research security hardening standards, understand technical configurations, define security controls, and contribute to developing compliance content across operating systems and other technologies.
Key Responsibilities
1. Technical Research & Compliance Content Research and analyze security configuration requirements for Linux, Windows, macOS, databases, applications, and network devices. Study industry security benchmarks such as CIS Benchmarks and DISA STIG to understand secure configuration requirements. Help create and maintain technical compliance controls based on security best practices. Assist in mapping security controls to frameworks such as NIST , MITRE ATT&CK , PCI-DSS , ISO 27001 , and other compliance standards. Document control descriptions, rationale, risk, and remediation guidance. 2. Security Research Research emerging technologies and understand their security architecture. Identify important security configuration settings and recommend secure configurations. Continuously learn new technologies and industry security standards. 3. Content Maintenance Review and update compliance content as security benchmarks and frameworks evolve. Understand existing Bash/Shell scripts used for compliance checks and perform basic modifications when required. Assist in validating compliance controls through testing and technical analysis. 4. Collaboration Work closely with Product, Development, QA, and Infrastructure teams. Participate in technical discussions and contribute to improving compliance content quality. Support internal teams by analyzing compliance gaps and researching technical solutions. Required Technical Skills Linux (Primary Requirement) Strong understanding of Linux operating systems. Hands-on experience with at least one RHEL-based distribution (RHEL, CentOS, Rocky Linux, AlmaLinux). Familiarity with at least one Debian-based distribution (Ubuntu or Debian). Good understanding of: Linux filesystem hierarchy Users, groups, permissions, and ownership SSH configuration Sudo configuration PAM basics Cron jobs Syslog and logging Disk partitions, filesystems, and mount management Kernel parameters (sysctl) Basic understanding of SELinux concepts is desirable. Familiarity with Linux auditing ( auditd , audit rules, ausearch, aureport) is a plus. Security & Compliance Basic understanding of operating system security concepts. Familiarity with security hardening standards such as CIS Benchmarks and DISA STIG . Awareness of security frameworks including: NIST ISO 27001 PCI-DSS MITRE ATT&CK Basic understanding of networking concepts. Scripting Ability to read, understand, and troubleshoot basic Bash/Shell scripts . Basic scripting knowledge to make small modifications to existing scripts. Familiarity with Regular Expressions (Regex) is desirable. Additional Knowledge Exposure to any of the following is a plus: Windows administration macOS Databases APIs or Postman Microsoft Security Compliance Toolkit (SCT) Required Soft Skills Strong analytical and problem-solving skills. Excellent written and verbal communication. Curiosity and willingness to learn new technologies. Strong attention to detail. Ability to research technical topics independently. Good collaboration and teamwork skills. Positive attitude and ownership of assigned tasks.
Preferred Qualifications
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. 0–3 years of experience in Linux Administration, Cybersecurity, Technical Support, System Administration, or