Full-Time
Updated on 9/3/2026
Cloud-based vulnerability management and compliance platform
No salary listed
Pune, Maharashtra, India
In Person
Bachelor's, Master's
See people who can refer or advise you
Qualys provides cloud-based cybersecurity and compliance solutions to secure IT infrastructure for enterprises, SMBs, and government. Its main products include vulnerability management, policy compliance, web application security, and IT asset management, delivered via the Qualys Cloud Platform that continuously monitors environments. The platform collects data from agents and sensors, runs automated checks, enforces policies, and generates real-time compliance reports. It differentiates with real-time analytics, automated workflows, and scalable cloud architecture, offering a unified security and compliance ecosystem to manage risk across on-premises, cloud, and hybrid environments.
Company Size
1,001-5,000
Company Stage
IPO
Headquarters
Redwood City, California
Founded
1999
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Remote Work Options
Prevalent AI appoints Nitin Maini as CTO to accelerate the evolution of its ai-powered Data Fabric. New CTO will lead technology strategy as Prevalent AI aims to meet demand of use cases focused on context and scalability. LONDON, Sept. 02, 2026 (GLOBE NEWSWIRE) - Prevalent AI, an accelerating leader in AI-powered enterprise context, has appointed Nitin Maini as Chief Technology Officer (CTO) as the company broadens the application of its AI-powered Data Fabric and Knowledge Graph across different enterprise data and AI use cases. "Every enterprise I speak to wants to move AI into production, but confidence drops quickly once agents are expected to act inside live systems. They need..." "Prevalent AI has spent nearly a decade building a connected data foundation for complex cybersecurity environments, and Nitin joins us at a point when that..." "His experience scaling global engineering organisations and leading AI transformation will be important as we extend the Knowledge Graph into new enterprise..." "Across my career, I have seen what happens when complex platforms are built on fragmented data. AI is making that weakness much harder to ignore," Maini, who has more than 20 years of experience across cybersecurity and enterprise software, will shape Prevalent AI's technology roadmap as the company builds on its established cybersecurity business and extends its approach to unifying and delivering critical context from fragmented customer data into broader enterprise use cases. He brings significant experience in scaling engineering organisations and building enterprise technology platforms. Most recently, as Senior Vice President of Engineering at Qualys, Maini led a 1,000-plus-person engineering organisation in India and helped drive an AI-first engineering transformation. Before Qualys, he spent almost six years as Chief Technology Officer at Sapience Analytics, following earlier senior engineering roles at Vuclip and BMC Software. The appointment follows Prevalent AI's $22 million growth investment from Integrity Growth Partners last month. The investment was the first primary capital raised in the company's nine-year history and is being used to support global expansion and further development of its offerings for customers across financial services, telecommunications, and critical national infrastructure. "Prevalent AI has spent nearly a decade building a connected data foundation for complex cybersecurity environments, and Nitin joins us at a point when that foundation has a much broader role to play," said Paul Stokes, CEO and co-founder of Prevalent AI. "His experience scaling global engineering organisations and leading AI transformation will be important as we extend the Knowledge Graph into new enterprise use cases, such as financial crime analysis and operational intelligence, while continuing to serve our security customers." "Across my career, I have seen what happens when complex platforms are built on fragmented data. AI is making that weakness much harder to ignore," said Maini. "What drew me to Prevalent was the maturity and extensibility of the Knowledge Graph. It gives enterprises a connected foundation that can support security today and broader AI use cases tomorrow as those systems move into production." Prevalent AI's platform connects and resolves data across enterprise systems to build a continuously updated view of assets, identities, controls and their relationships. As AI agents gain greater access to internal systems and workflows, Maini believes that trusted enterprise context is critical if enterprises are to use them reliably in production. "Every enterprise I speak to wants to move AI into production, but confidence drops quickly once agents are expected to act inside live systems. They need current context about the organisation they operate in and how its systems are connected. My ambition is for Prevalent AI to become the trusted data and context layer for enterprise AI, with the Knowledge Graph extending from cybersecurity into areas such as governance, risk and compliance," said Maini. About Prevalent AI Prevalent AI is an AI-powered data fabric company that provides the organizational context enterprises need to securely operate, reliably deploy AI, and make decisions with confidence. Founded by alumni of GCHQ, Prevalent AI continuously cleans, connects, and contextualizes fragmented enterprise data into a sovereign knowledge graph, giving teams and AI systems the trusted context they need to operate reliably at scale. Proven first in cybersecurity, where fragmented data creates immediate operational risk, the platform now supports financial crime analysis, operational intelligence, compliance, and enterprise AI initiatives from the same underlying foundation. Prevalent works with global banks, telcos, and critical national infrastructure operators. Headquartered in London, the company supports customers across some of the world's most complex and highly regulated industries. For more information, visit www.prevalent.ai/
Equixly and Qualys partner to bring exploit validation into vulnerability management. Mattia Dalla Piazza, Zoran Gorgiev. Exploit-validated findings from Equixly now flow into Qualys VMDR, and Qualys asset inventory flows back to scope tests. Proven application and API risk lands where your security team does its work. The new integration between Equixly and Qualys connects continuous offensive security testing of APIs and web applications with Qualys Vulnerability Management, Detection, and Response (VMDR). Findings arrive with evidence of exploitability, so your organization can add that proof to the risk context already available in Qualys. Security teams typically spend substantial time and resources triaging vulnerabilities before they know which ones are genuinely exploitable. The integration between Equixly and Qualys helps address this problem by enabling asset owners and their teams to concentrate remediation efforts on vulnerabilities with a working attack path. * Equixly pulls relevant assets from Qualys to decide what to probe. * It tests those assets and produces findings backed by evidence of exploitability. * The security testing platform then sends the findings with that evidence into the Qualys workflow teams already use. The result is an efficient remediation process, with validated findings, exploit evidence, and existing workflows brought together in one place. How the Equixly-Qualys integration works. The connection runs on events: * A scan starts from the Equixly UI, on a schedule, or from a pipeline through Equixly's CI/CD hooks or API. * The Equixly engine runs the scan against the project in scope. * At the end of the scan, the engine publishes a completion event to Equixly's message broker. * A dedicated Qualys consumer waits for that event, collects the vulnerabilities, and loads them into Qualys. * Qualys takes in the data and shows the results with the rest of your vulnerability data. Nobody exports a report. Nobody re-keys a finding from one console into another. Every step you must carry out by hand is a step where a proven vulnerability can stall or drop out of sight. Your Qualys asset inventory sets the scope. Findings travel one way. Assets travel the other. Equixly reads the asset inventory your team maintains in Qualys and uses it to scope tests. Offensive testing then follows the estate your asset management records describe, rather than a target list someone maintains by hand. When a result lands back in Qualys, it arrives against an asset your inventory tracks, next to the risk context your team relies on for prioritization. Proof of exploitability next to the rest of your risk data. A severity score describes what a class of vulnerability can do in general. It says less about whether an attacker can reach that flaw in your environment. Equixly's Agentic AI Hacker chains requests the way a real adversary does, so a finding that reaches Qualys VMDR rests on a demonstrated attack rather than on inference. Three things change for a security team: * Triage starts from evidence. Remediation efforts follow vulnerabilities with a demonstrated path, not a ranking alone. * Business logic and authorization flaws reach the same queue as everything else. Static testing tools rarely surface this class of issue, because the flaw lives in how endpoints behave together rather than in the code itself. * Prioritization arguments get shorter. An engineer who receives a reproducible attack path has much firmer ground for a fix than one who receives a score. Evidence for compliance reporting. Regulated organizations report on application and API security testing under PCI DSS, DORA, NIS2, and ISO 27001. Exploit-validated results now sit in Qualys, tied to the assets they affect, between formal assessments as well as during them. Availability. The Qualys integration shipped with Equixly's July 2026 release and is live in the platform now. Teams that run Qualys vulnerability management over fast-changing application and API estates in banking, insurance, payments, SaaS, and energy will feel the difference first. Your Equixly contact can walk your team through setup. Read the July 2026 product update for the full release notes. Book a demo to see exploit-validated findings arrive in your Qualys VMDR console. Mattia Dalla Piazza CEO & FOUNDER Mattia's fascination with cybersecurity began in the early 2000s during his school days when he discovered vulnerabilities in school systems. With over 15 years in the Information Technology domain, he has built a notable career that includes leadership roles, such as heading a System Engineering Centre of Excellence for UniCredit Bank and being an International IT Manager at IBM. Mattia's expertise also extended to a NASDAQ-listed company, where he oversaw the management of its data centers as a System Engineer. Mattia is well-known for his ability in information network design, security, and infrastructure architecture. His robust problem-solving skills and forward-thinking vision underscore his commitment to enhancing service efficiency and fortifying his clients' security posture. Zoran Gorgiev Technical Content Specialist Zoran is a technical content specialist with SEO mastery and practical cybersecurity and web technologies knowledge. He has rich international experience in content and product marketing, helping both small companies and large corporations implement effective content strategies and attain their marketing objectives. He applies his philosophical background to his writing to create intellectually stimulating content. Zoran is an avid learner who believes in continuous learning and never-ending skill polishing. 08/17/26 Press Releases
Qualys introduces Real-Time cloud security posture management (CSPM) for faster risk detection and remediation. Wednesday, August 12, 2026 at 07:34 PM UTC · Source: Qualys Blog Updated: Wednesday, August 12, 2026 at 08:00 PM UTC Executive summary. Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require them. It evaluates each finding in context by correlating posture data with vulnerabilities, asset [ Analysis. Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require them. It evaluates each finding in context by correlating posture data with vulnerabilities, asset […] Source Attribution Originally published by Qualys Blog on Aug 12, 2026.
Qualys raised its full-year 2026 revenue guidance to $732 million–$738 million, citing strong demand for its Enterprise TruRisk Management (ETM) solution. The cybersecurity firm attributes growth to what it calls the "post-Mythos" threat landscape, where AI has compressed exploit timelines to hours, forcing a shift from detection to autonomous remediation. Channel-led revenue grew 22% and now accounts for 54% of total revenue. The company's Risk Operations Center framework is gaining traction as customers replace manual processes with automated detection and patching systems. Qualys repurchased $76.8 million worth of shares during the second quarter, buying back 797,000 shares. The company appointed Shailesh Athalye as Chief Product Solutions Officer and Nathan Smolenski as CISO following recent executive departures. Management expects the federal sector to drive growth, supported by new FedRAMP High status.
Cybersecurity firm Qualys saw its stock surge nearly 14% on Wednesday following strong second-quarter results. The company reported revenue of $182.2 million, up 11% year-over-year, surpassing analyst expectations of under $179 million. Adjusted net income rose 13% to over $69 million, or $1.98 per share, beating the consensus estimate of $1.79. Qualys attributed the growth to sustained demand for risk management solutions and its AI-enhanced offerings. For 2026, the company projects revenue between $732 million and $738 million, representing at least 9% growth and exceeding analyst forecasts of $726 million. Adjusted earnings per share are expected to reach $7.74 to $7.88, compared to the average estimate of $7.86.