Corporate · onsite · online training worldwide
contact@DevOpsSchool.com· +91 99057 40781·
> Cloud Security Platform · DevOpsSchool Trainer

Qualys Trainer

Private corporate batches, live online cohorts and 1-on-1 mentoring in asset inventory, vulnerability management, policy compliance and web application scanning on one platform — taught by a practitioner who runs it in production.

20 years across DevOps, SRE and Security · 10,000+ engineers trained · Trained teams at JPMorgan Chase, Verizon, Nokia and the World Bank

DeliveryOnline · Onsite · Hybrid
FormatsCorporate · 1-on-1 · Cohort
AgendaCustomisable
Batch size8–30 engineers
Engineers we've trained work at
JPMorgan ChaseBank of AmericaWells FargoVerizonNokiaWorld BankGE HealthcareVMwareOracleQualcommMercedes-BenzAirbusDatadogSplunkDeloitteInfosysWiproCapgemini
# who teaches it

Your Qualys trainer

Rajesh Kumar

Principal DevOps Engineer & Architect

Cloud architectureMulti-cloud estatesInfrastructure at scale20 years in productionPrincipal / architect roles10,000+ engineers trainedM.Tech BITS Pilani25+ certifications

Rajesh teaches Qualys around the asset model first, because tagging is what determines whether reports, remediation rules and access control work at all — and it is the decision most deployments get wrong early and pay for later. Sessions cover sensor selection across scanner appliances, Cloud Agents, container and cloud connectors, authentication records for credentialed scanning, option profile tuning against scan windows, VMDR prioritisation and remediation rules, policy compliance against configuration benchmarks, web application scanning with authenticated crawls, and API-driven automation — all worked through against real subscription data rather than screenshots.

Twenty years across DevOps, SRE and Security, in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe and others. He has trained engineers at JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus — more than 10,000 people personally. He teaches what he runs, not what he reads.

One practitioner, not a bench

You are booked with a named engineer, and that is who turns up. Marketplaces and larger providers rotate whoever is free, so the person who sold you the agenda is rarely the person teaching it.

The same trainer is available for the next engagement, which matters when a team builds on what it learned last time.

18,000+certified learners
500+corporate batches delivered
50+countries served
100+certification programmes
# faculty

Who delivers Qualys engagements

Your batch is assigned a named trainer before it starts, and that is who teaches it. See the full faculty.

How your Qualys trainer is chosen

Engagements are matched on the tool, not the calendar. For Qualys that means a trainer who has run it in production — asset inventory, vulnerability management, policy compliance and web application scanning on one platform — rather than whoever is free that week. You are told who is teaching before you commit, and that person is on the discovery call that shapes the agenda.

Where a batch is large enough to need a second trainer, the pairing is declared up front. The lead trainer stays accountable for the syllabus and the assessment either way.

Rajesh Kumar

Principal DevOps Engineer & Architect

India20 yrsLead trainer

Twenty years across DevOps, SRE and Security in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe, IBM/Emptoris, Ness, MindTree and Accenture. He has trained more than 10,000 engineers personally, at organisations including JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus. He teaches what he runs, not what he reads.

Kapil Gupta

IndiaInstructorCoach

Kunal Jain

IndiaInstructorCoach

Nikhil Gupta

IndiaInstructorCoach

Pranab Kumar

IndiaInstructorCoach

Rohit Ghatol

IndiaInstructorCoach

Amit Agarwal

IndiaInstructorCoach

Anil Kumar

IndiaInstructorCoach

Balachandran Anbalagan

IndiaInstructorCoach

Durga Prasad

IndiaInstructorCoach

Gaurav Aggarwal

IndiaInstructorCoach

Harsh Mehta

IndiaInstructorCoach

# how to engage

Four ways to work with this trainer

Private corporate batch

Teams of 8–30

Custom agenda, your timezone, onsite or online, NDA-friendly.

Request a quote

1-on-1 mentoring

Individual engineers

A private instructor and a curriculum built around your goal.

₹99,999

Live & Interactive cohort

Individuals who want peers

Scheduled batch, max 8 to 10 hours of live instruction.

₹34,999

Self-paced video

Self-starters

Full LMS access — 20+ courses and 50+ tools included.

₹833/mo
# private batches

Private Qualys training for your team

A private batch starts with a discovery call. We look at the stack you actually run — the CI system, the cloud, the constraints — and map the agenda onto it, so examples use your topology rather than a generic one.

Delivery is onsite at your premises, live online, or hybrid, scheduled around your release calendar rather than ours. Batches run 8 to 30 engineers.

Every attendee leaves with recordings, slides, lab repositories and a completion certificate. You receive an attendance and assessment report. Invoicing supports PO and GST.

Talk to us about a private Qualys batch

What you provide vs what we bring

  • You: the room or the call, and the engineers
  • Us: trainer, agenda, labs, assessment, certificates
  • Labs: we guide your team through provisioning their own free-tier cloud environment — the skill goes with them
# the technology

What is Qualys?

Qualys is a cloud-delivered security and compliance platform. Rather than a single scanner, it is a set of applications sharing one asset inventory and one data model: asset management, vulnerability management and remediation, policy compliance against configuration benchmarks, web application scanning, container and cloud posture assessment, and patch deployment. Because they share the platform, an asset discovered once carries its tags, its owner and its findings across every application that touches it — which is the main reason organisations consolidate onto it.

Data reaches the platform through several sensor types, and choosing among them is the first real design decision. Scanner appliances, virtual or physical, sweep networks the way a traditional scanner does and are the only option for devices you cannot install software on. The Cloud Agent installs on a host, collects continuously and reports without needing a scan window or inbound network access, which suits laptops, cloud instances and anything behind NAT. Passive sensors identify assets from network traffic, and container and cloud connectors pull inventory and configuration directly from registries and cloud provider APIs.

What makes the platform work or fail in practice is the asset model. Every asset carries tags, and tags — especially dynamic tags built from queries — drive scan targeting, report scope, dashboard filters, remediation rules and access control. A Qualys deployment with a coherent tagging scheme produces reports that route to the right team automatically. One without it produces accurate data that nobody can slice into a work queue, which is the single most common way an otherwise healthy deployment fails to deliver value.

Why this skill matters now

Security operations consolidated. Running one tool for network scanning, another for configuration compliance, another for web application testing and a spreadsheet to reconcile them stopped being viable once estates spanned data centres, several cloud providers, container platforms and a remote workforce. Platforms that unify inventory and findings across all of that became the default enterprise answer, and Qualys is one of the small number that show up repeatedly in that role.

The pressure is regulatory as much as technical. Frameworks and customer questionnaires ask for continuous asset inventory, evidence of periodic vulnerability assessment, configuration compliance against a named benchmark and demonstrable remediation timelines. Producing that from separate tools is an exercise in reconciliation; producing it from one platform with a shared asset model is a reporting exercise, provided the deployment was designed for it.

The skill organisations look for is platform engineering rather than button-clicking. Choosing sensors per asset class, building an asset tagging scheme that survives reorganisation, writing authentication records so scans are credentialed, tuning option profiles so scans complete, defining remediation rules and ownership, extending compliance policies, and driving the platform through its API so scanning becomes part of automated workflows. That is what separates a licensed platform from a working programme.

Qualys training
# outcomes

What your team can do afterwards

Choose the right sensor per asset class — scanner appliance, Cloud Agent, passive sensor, container or cloud connector — and justify the choice
Build an asset tagging scheme, including dynamic tags from queries, that drives targeting, reporting, remediation and access control
Configure authentication records so scans are credentialed across Linux, Windows, databases and cloud instances
Tune option profiles so scans complete inside a maintenance window without dropping the detections that matter
Prioritise findings using detection data, asset context and threat indicators rather than raw severity counts
Run policy compliance scans against configuration benchmarks and manage exceptions with evidence and expiry
Scan web applications with authenticated crawls and API definition import, and keep scope under control
Automate the platform through its API and build dashboards and reports that different audiences will actually use
# curriculum

7 modules. Live demos in a real lab, not slides.

01The platform, its applications and its sensorsLive & Interactive5 hrs · 2 assignments · 1 capstone

How the platform is put together before touching any individual application. Subscriptions, modules and user roles; the shared asset inventory that everything else depends on; then the sensor types, what each can and cannot see, and how to decide which asset gets which.

Topics: Platform architecture and the shared asset data model · Subscriptions, activated modules and licensing units · Scanner appliances: physical, virtual and cloud-hosted · Cloud Agent: continuous collection without scan windows · Passive sensors and network-derived asset discovery · Container sensors and cloud connectors · Users, roles, business units and scoped access · Choosing a sensor strategy per asset class

  • Assignments: (1) Map an estate to sensor types with a justification for each class; (2) Configure roles so a regional team sees only its own assets
  • Capstone: Produce a sensor and access design for a multi-region, multi-cloud estate
02Asset inventory and taggingLive & Interactive5 hrs · 2 assignments · 1 capstone

The module that determines whether everything else works. Building and maintaining inventory across scanned, agent-reported and cloud-discovered assets, then the tagging model — static and dynamic tags, tag hierarchies, and the query language that turns 'internet-facing production database servers' into something you can target.

Topics: Asset discovery across sensors and deduplication · Host assets, cloud assets and unmanaged assets · Static tags versus dynamic tags built from queries · Tag hierarchies and inheritance · Asset search queries and building tags from them · Asset groups and business units, and when each still matters · Using tags to scope scans, reports, dashboards and permissions · Keeping tagging current as the estate changes

  • Assignments: (1) Build a dynamic tag hierarchy covering environment, criticality and owning team; (2) Prove a scan, a report and a permission set can all be driven by the same tags
  • Capstone: Deliver a tagging scheme that survives a team reorganisation without manual re-tagging
03Vulnerability management, detection and responseLive & Interactive5 hrs · 2 assignments · 1 capstone

The core workflow. Option profiles and what each setting costs in scan time, authentication records for credentialed scanning, launching and scheduling scans, then reading detections — the vulnerability knowledge base, detection status, confirmed versus potential findings, and prioritisation that reflects real exposure.

Topics: Option profiles: port lists, detection settings and performance · Authentication records for Linux, Windows, databases and cloud instances · Verifying that a scan authenticated rather than assuming it did · Launching, scheduling and scoping scans by tag · The vulnerability knowledge base and detection identifiers · Confirmed, potential and information-gathered detections · Detection status: new, active, fixed and reopened · Prioritisation using asset context and threat indicators · Remediation rules, ticketing and SLA tracking

  • Assignments: (1) Configure credentialed scanning for Linux and Windows and evidence successful authentication; (2) Build a prioritised remediation queue for one asset tag with owners and target dates
  • Capstone: Deliver a scanning and remediation cycle for one business unit with scheduling, ownership and SLA reporting
04Cloud Agent at scaleLive & Interactive5 hrs · 2 assignments · 1 capstone

Continuous assessment without scan windows. Agent deployment and activation keys, configuration profiles that control how much the agent collects and how often, the practical differences between agent and scanner data, and operating a large agent fleet including the assets that stop reporting.

Topics: Agent installation across Linux, Windows and macOS · Activation keys, modules and deployment at scale · Configuration profiles: intervals, performance and data collection · Agent versus scanner data, and reconciling the two · Continuous assessment and near-real-time detection · Agents behind NAT, on laptops and in ephemeral cloud instances · Handling stale, duplicated and non-reporting agents · Agent upgrades and rollout control

  • Assignments: (1) Deploy agents with configuration management and verify check-in across the fleet; (2) Reconcile agent and scanner findings on the same host and explain the differences
  • Capstone: Deliver an agent rollout plan with configuration profiles, health monitoring and a stale-asset process
05Policy compliance and configuration hardeningLive & Interactive5 hrs · 2 assignments · 1 capstone

The compliance half of the platform, which is a different discipline from vulnerability scanning. Importing and adapting benchmark policies, understanding controls and their expected values, running compliance scans, and managing exceptions with evidence rather than by lowering the standard.

Topics: Policy compliance versus vulnerability management · Technologies, controls and expected values · Importing benchmark policies and adapting them to reality · Creating and editing controls, including custom checks · Compliance scanning requirements and why credentials are mandatory · Posture assessment and reading pass, fail and error states · Exceptions: justification, approval and expiry · Mandate and framework mapping for audit reporting · Tracking compliance drift over time

  • Assignments: (1) Run a benchmark policy against a host, fix three failing controls and re-scan to prove the change; (2) Raise an exception with evidence and an expiry, and report on outstanding exceptions
  • Capstone: Deliver a compliance baseline for one server class with an exception register and drift reporting
06Web application scanningLive & Interactive5 hrs · 2 assignments · 1 capstone

Dynamic testing of web applications and APIs inside the same platform. Defining web applications and scope, authentication records for crawls that need to log in, importing API definitions, choosing scan profiles, and handling the findings and false positives that dynamic scanning produces.

Topics: Defining a web application, its scope and exclusions · Crawl settings, depth limits and links to follow or avoid · Authentication records for form and token-based logins · Verifying the crawl stayed authenticated · Selecting scan profiles and balancing depth against time · Importing API definitions for endpoint coverage · Reading findings, evidence and reproduction detail · Marking false positives and managing them across scans · Coordinating scanning with WAF and rate limiting

  • Assignments: (1) Configure an authenticated web application scan and prove the crawl reached protected pages; (2) Triage a findings set and record justified false positives
  • Capstone: Deliver a repeatable authenticated scan configuration for one application with scoped, triaged reporting
07Reporting, dashboards, integrations and API automationLive & Interactive5 hrs · 2 assignments · 1 capstone

Making the platform produce outcomes rather than data. Report templates and scorecards, dashboards built on saved queries, integrations with ticketing and cloud providers, container image scanning in a pipeline, and driving the whole platform through its API so the routine work stops being manual.

Topics: Report templates: technical, executive and scorecard reports · Query-driven dashboards and widgets per audience · Scheduled report distribution and access control · Cloud connectors for AWS, Azure and GCP inventory and posture · Container image scanning in a build pipeline · Ticketing integration with Jira and ServiceNow · The platform API: authentication, rate limits and pagination · Scripting scan launch, result export and asset tagging · Designing the operating cycle: discover, assess, prioritise, remediate, verify

  • Assignments: (1) Build three reports for three audiences from the same data set; (2) Script scan launch and result export through the API with no interface interaction
  • Capstone: Deliver an automated operating cycle with API-driven scanning, tag-based routing, ticketing integration and audience-specific reporting

Need this mapped to your stack?

We rebuild the agenda around the tools you actually run.

Request a custom agenda
# hands-on

Labs and capstones your engineers actually build

LAB · TAGGING

Tags that drive everything

Build a dynamic tag hierarchy from asset queries, then prove the same tags scope a scan, a report, a dashboard and a permission set without duplication.

taggingasset queriesscoping
LAB · CREDENTIALS

Prove the scan authenticated

Configure authentication records for Linux, Windows and a database, run a credentialed scan and evidence successful authentication rather than assuming it from the result count.

authentication recordscredentialed scanvmdr
LAB · AGENTS

A fleet that keeps reporting

Deploy Cloud Agents through configuration management with activation keys and configuration profiles, then find and resolve the agents that stopped checking in.

cloud agentactivation keysfleet health
LAB · COMPLIANCE

Benchmark, fix, re-scan

Run a configuration benchmark policy against a server class, remediate failing controls, re-scan to prove the change and raise one exception with evidence and an expiry.

policy compliancebenchmarksexceptions
LAB · WAS

An authenticated crawl that reaches the app

Define a web application with scope and exclusions, configure an authenticated crawl, import an API definition and prove protected endpoints were actually tested.

web application scanningauthenticationapi
CAPSTONE · AUTOMATION

The cycle without the console

Script asset tagging, scan launch, result export and ticket creation through the API, schedule it and produce audience-specific reporting from the same data.

apiautomationreporting
# ecosystem

The tools Qualys sits next to

AWS
Azure
Google Cloud
Jira
ServiceNow
Jenkins
Docker
Kubernetes
Ansible
Splunk
Active Directory
Linux

Who this is for

  • Security engineers operating or rolling out a vulnerability management programme
  • Infrastructure and systems administrators who receive and remediate the findings
  • SOC analysts triaging platform findings and routing them to owners
  • Compliance and audit engineers producing configuration and remediation evidence
  • Cloud and DevOps engineers extending coverage to cloud accounts, containers and ephemeral hosts
  • Security architects consolidating several point tools onto a single platform

Pre-requisites

  • Solid TCP/IP networking: addressing, subnets, ports, firewalls and NAT
  • Working knowledge of Linux and Windows administration, including how software is patched
  • Basic understanding of SSH and Windows authentication for credentialed scanning
  • Familiarity with at least one cloud provider's account and inventory model
  • Access to a Qualys subscription with the relevant modules for the hands-on work
# pricing

Straightforward pricing

Every plan includes 1 year of full LMS access — not just this course, the entire DevOpsSchool LMS: 20+ courses, 50+ tools, videos, quizzes, assignments and projects.

Self-paced video

₹833/mo

Billed yearly at ₹9,996

Enroll now

1-on-1 mentorship

₹99,999

Full program, private instructor

Enroll 1-on-1

Corporate / private batch

8–30 engineers · custom agenda · onsite or online · PO and GST invoicing

Get a custom quote

Refunds. If we cancel or postpone a cohort, you get a full refund within 15 days. There is no money-back guarantee otherwise.

Terms. Course material remains licensed to the attendee. Read the terms.

Your data. We don't share it with third parties. Privacy policy.

Every attendee gets a verifiable certificate

  • Issued per attendee on completion
  • Verifiable at devopsschool.com/certificates
  • Hard copy available on request
  • Corporate batches receive an attendance and assessment report
DevOpsSchool

Qualys Training

Certificate of completion

# feedback

What engineers say

4.4 / 5 from 26 reviews on Trustpilot.

★★★★★
Rajesh is a very good trainer I have experienced in DevSecOps training. The number of contents in different topics he has posted on the DevOpsSchool public website are amazing and user friendly for beginners and experienced professionals.
Ashutosh Mishra · Trustpilot
★★★★★
The trainer (Rajesh) provided very good sessions on SRE profession. Not only hands-on learning on the tools but also SRE mindset.
Peter Wang · Trustpilot
★★★★★
Very good training session. Well explained from the basics to the complex concepts. Also tried to cover practicals and demos within the 3 hour sessions. The learning content and videos are of a great deal of help.
Sreekanth Kannoth · Trustpilot
★★★★★
Basics explanation was exemplary from Rajesh where he dealt with complicated topics to be simple. Great learning stuff personally for me.
Krishna Mohan Yelleti · Trustpilot
★★★★★
Very detailed explanation and has lots of patience in attending the questionnaire. Thanks again for your wonderful sessions.
Uttam Samudrala · Trustpilot
★★★★★
Good discussion, helped us to understand different tools in SRE.
Prashant Saxena · Trustpilot
# comparison

Why a named practitioner beats a marketplace listing

What mattersYouTube + blogsGeneric online courseFreelance marketplaceDevOpsSchool
Named practitionerNoRarelyVaries per bookingYes — same trainer each time
Production experienceUnknownUnknownUnverified20 years, named employers
Custom agendaNoNoSometimesBuilt from your stack
Onsite deliveryNoNoSometimesYes
Lab environmentNoneSandbox that expiresVariesYour own cloud — skill goes with you
AssessmentNoneQuizRarelyAssignments + capstone per module
Per-attendee certificatesNoSometimesRarelyYes
Corporate invoicingNoLimitedVariesPO and GST
Post-training supportNoneForum, time-limitedNoneLifetime forum access
# questions

Frequently asked

Can the agenda be customised for our stack?
Yes — that is the normal case for a private batch. We start with a discovery call, look at which modules you have licensed, your cloud footprint, operating system mix and compliance obligations, and rebuild the module list around them. Applications you do not own are dropped.
Do you deliver onsite?
Yes. Private batches run onsite at your premises, live online, or hybrid. You provide the room and the engineers; we bring the trainer, agenda, labs, assessment and certificates.
Do we need our own Qualys subscription?
For the full hands-on track, yes — it is a commercial SaaS platform and we cannot provide access to it. Most corporate batches run against the client's existing subscription, which makes the labs directly applicable. Where access is limited we adapt to demonstration plus design work on your real asset model.
Is this an offensive security course?
No. It is defensive operations — inventorying assets you own, finding unpatched and misconfigured systems, evidencing compliance and tracking remediation. All scanning in the labs targets the client's own assets or attendee-provisioned hosts.
What lab environment do we need?
Attendees need access to your Qualys subscription plus a few target hosts they control — free-tier cloud instances or local VMs — which we walk them through provisioning. We deliberately do not hand out temporary sandboxes, because the environment they build is the one they keep.
Should we use scanner appliances or Cloud Agents?
Usually both, and the first module covers the decision explicitly. Agents suit hosts you can install software on, especially laptops and ephemeral cloud instances; appliances remain necessary for network devices, appliances and anything where agent installation is not possible.
Our reports are accurate but nobody acts on them. Is that addressed?
That is almost always a tagging and ownership problem rather than a data problem, and it gets a full module. Dynamic tags built from asset queries let reports, remediation rules and permissions all route to the same owning team automatically.
Does this cover policy compliance as well as vulnerability management?
Yes, as a separate discipline. Compliance scanning requires credentials, works against configuration benchmarks with defined expected values, and needs an exception process with evidence and expiry — all of which is covered hands-on.
How long does a private Qualys batch take?
Typically three to four days. Platform, sensors, tagging and vulnerability management fit in two to three days; adding policy compliance, web application scanning and API automation takes it to four.
What size are batches?
Private corporate batches run 8 to 30 engineers. Public Live & Interactive cohorts are capped at 10 so everyone gets time with the trainer.
Do attendees get a certificate?
Yes — every attendee receives a completion certificate, verifiable at devopsschool.com/certificates. Corporate batches also receive an attendance and assessment report.
What is your refund position?
If we cancel or postpone a cohort, you receive a full refund within 15 days. There is no general money-back guarantee, and GST and gateway fees are not refunded.

Still deciding?

Tell us the team, the stack and the timeline. You'll get a straight answer, not a sales sequence.

Talk to an advisor
# ready when you are

Book a Qualys trainer — or ask a question first.

  • No spam, no drip sequence
  • Syllabus in 60 seconds
  • A human reply within one business day

Prefer to call or email?

More ways to reach us on the contact page.

Talk to an advisorRequest a quote