Principal Vulnerability Management Engineer

Zscaler

United States

Hybrid

USD 150.000 - 190.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Eine Bewerbung wie gemacht für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Zscaler seeks a Principal Engineer, Vulnerability & Exposure Management to join our Hybrid team. You will shape the operating model, build scalable workflows, and partner with DevOps, IT, and engineering to reduce security exposure across infrastructure, cloud, APIs, and endpoints.

You’ll influence leadership with metrics, while delivering practical guidance and durable improvements. You’ll operate strategically and technically in a role that demands ownership, collaboration, and a builder

Qualifikationen

  • Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain.
  • 12+ years of experience in security engineering or product security, including 7+ years of hands-on experience driving and scaling vulnerability and exposure management programs within complex environments.
  • Deep understanding of scanner mechanics (including authenticated/unauthenticated)

Aufgaben

  • Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability
  • Define advanced, risk-based prioritization models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams
  • Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation
  • Drive external attack surface management (EASM) to map internet-facing assets while aggressively identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions
  • Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics

Kenntnisse

AI/ML understanding
Security engineering experience
Scanner mechanics

Jobbeschreibung

About Zscaler

Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise , we are constantly pushing the envelope, leveraging the world's largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate -we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession , collaboration, ownership, and accountability.

We value high-impact, high-accountability with a sense of urgency where you're enabled to do your best work and embrace your potential. If you're driven by purpose, thrive on solving complex challenges, and want to be part of the team that's helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

Role

We are looking for a Principal Engineer, Vulnerability & Exposure Management to join our team. This is a hybrid role, reporting to the Senior Manager, Information Security Engineering in the Product Security department. This critical role helps modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets. As an individual contributor, you will operate both strategically and technically to define the operating model, build scalable workflows, influence engineering teams, and dive deep into findings, coverage gaps, scanner limitations, and remediation paths with a strong builder mindset.

What you’ll do (Role Expectations)
  • Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability
  • Define advanced, risk-based prioritization models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams
  • Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation
  • Drive external attack surface management (EASM) to map internet-facing assets while aggressively identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions
  • Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics
Who You Are (Success Profile)
  • You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
  • You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
  • You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
  • You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback -knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
  • You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We’re Looking for (Minimum Qualifications)
  • Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
  • 12+ years of experience in security engineering or product security, including 7+ years of hands-on experience driving and scaling vulnerability and exposure management programs within complex environments
  • Deep understanding of scanner mechanics (including authenticated/unauthenticated
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Lead Vulnerability & Exposure Engineer
Lead Vulnerability & Exposure Engineer

Zscaler • USA

Hybrid
USD 150.000 - 190.000
Senior Manager Software Engineering
Senior Manager Software Engineering

Zscaler, Inc. • San Jose (CA)

Hybrid
USD 180.000 - 225.000
Principal Product Manager
Principal Product Manager

Zscaler, Inc. • San Jose (CA), Northern (KY)

Hybrid
USD 172.000 - 245.000
Hybrid work model
Senior Information Security Engineer
Senior Information Security Engineer

Zscaler, Inc. • Northern (KY)

Hybrid
USD 134.000 - 168.000
Time off plans
Parental leave
Retirement options
+1
Insider Risk Security Engineer
Insider Risk Security Engineer

Zscaler, Inc. • Northern (KY)

Hybrid
USD 134.000 - 168.000
Senior Director, Product Management
Senior Director, Product Management

Zscaler • San Jose (CA)

Hybrid
USD 231.000 - 330.000
Various health plans
Time off plans for vacation and sick
Parental leave options
+3
Insider Risk Security Engineer
Insider Risk Security Engineer

Zscaler • USA

Remote
USD 134.000 - 168.000
Remote work (US)
Competitive salary
Senior Security Engineer
Senior Security Engineer

Kontoor Brands, Inc. • Northern (KY)

Remote
USD 140.000 - 190.000
Manager, MDR & Threat Hunting
Manager, MDR & Threat Hunting

Candidate • Northern (KY)

Hybrid
USD 144.000 - 205.000
Health plans
Time off plans for vacation and sick
Parental leave options
+2
Staff Technical Program Manager - Compliance Architecture
Staff Technical Program Manager - Compliance Architecture

Zscaler • USA

Vor Ort
USD 119.000 - 170.000
Various health plans
Time off for vacation and sick leave
Parental leave options
+2