Responsibilities
- Lead vulnerability and exposure management across infrastructure, cloud, APIs, containers, and other organizational assets.
- Define risk-based prioritization models that incorporate threat intelligence, business context, exploitability, and asset criticality.
- Design and deploy automated pipelines and workflow orchestration for asset discovery, authenticated scanning, triage, routing, and validation.
- Drive external attack surface management and identify gaps such as unauthenticated scans, stale ownership, and untracked exceptions.
- Partner with DevOps, IT, and engineering teams to translate vulnerability data into remediation guidance, infrastructure improvements, and leadership metrics.
- Build a scalable product security engineering capability rather than operating only as a reporting and ticket-follow-up function.
Requirements
- 12+ years of experience in security engineering or product security, including 7+ years driving and scaling vulnerability and exposure management programs in complex environments.
- Deep understanding of authenticated and unauthenticated scanning, scanner mechanics, coverage gaps, and asset correlation, with proficiency in Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite.
- Experience implementing risk-based prioritization using exploitability signals, threat intelligence, KEV, EPSS, and asset criticality.
- Hands-on automation experience with Python, PowerShell, APIs, data pipelines, or workflow orchestration platforms.
- Ability to collaborate with engineering teams to drive remediation and communicate technical findings to senior leadership.
- Preferred: experience securing AWS, Azure, and GCP environments and Kubernetes-based containerized architectures.
- Preferred: experience with image scanning, runtime security, CI/CD, DevSecOps, EASM, CTEM, attack-path analysis, CMDBs, asset inventories, and ownership tracking.
- Preferred: familiarity with Avalor, Nucleus, Tines, Jira, and ServiceNow for automated triage, remediation, and reporting workflows.
Benefits
- Various health plans
- Vacation and sick time off plans
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks
- Remote role based in India with a hybrid working model referenced
Tech Stack
Categories
About Zscaler
Zscaler (NASDAQ: ZS) is a pioneer and global leader in zero trust security. The world’s largest businesses, critical infrastructure organizations, and government agencies rely on Zscaler to secure users, branches, applications, data & devices, and to accelerate digital transformation initiatives. Distributed across 160+ data centers globally, the Zscaler Zero Trust Exchange™ platform combined with advanced AI combats billions of cyber threats and policy violations every day and unlocks productivity gains for modern enterprises by reducing costs and complexity. Stay Connected: LinkedIn: https://www.linkedin.com/company/zscaler Twitter: https://www.twitter.com/zscaler Facebook: https://www.facebook.com/Zscaler/ Instagram: https://www.instagram.com/zscalerinc/
