5 months ago
Bengaluru, IndiaStaff+
Responsibilities
- Lead vulnerability and exposure management across infrastructure, cloud, APIs, containers, and other organizational assets.
- Define risk-based prioritization models that incorporate threat intelligence, business context, exploitability, and asset criticality.
- Design and deploy automated pipelines and workflow orchestration for asset discovery, authenticated scanning, triage, routing, and validation.
- Drive external attack surface management and identify gaps such as unauthenticated scans, stale ownership, and untracked exceptions.
- Partner with DevOps, IT, and engineering teams to translate vulnerability data into remediation guidance, infrastructure improvements, and leadership metrics.
- Build a scalable product security engineering capability rather than operating only as a reporting and ticket-follow-up function.
Requirements
- 12+ years of experience in security engineering or product security, including 7+ years driving and scaling vulnerability and exposure management programs in complex environments.
- Deep understanding of authenticated and unauthenticated scanning, scanner mechanics, coverage gaps, and asset correlation, with proficiency in Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite.
- Experience implementing risk-based prioritization using exploitability signals, threat intelligence, KEV, EPSS, and asset criticality.
- Hands-on automation experience with Python, PowerShell, APIs, data pipelines, or workflow orchestration platforms.
- Ability to collaborate with engineering teams to drive remediation and communicate technical findings to senior leadership.
- Preferred: experience securing AWS, Azure, and GCP environments and Kubernetes-based containerized architectures.
- Preferred: experience with image scanning, runtime security, CI/CD, DevSecOps, EASM, CTEM, attack-path analysis, CMDBs, asset inventories, and ownership tracking.
- Preferred: familiarity with Avalor, Nucleus, Tines, Jira, and ServiceNow for automated triage, remediation, and reporting workflows.
Benefits
- Various health plans
- Vacation and sick time off plans
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks
- Remote role based in India with a hybrid working model referenced
Tech Stack
Categories
About Zscaler
Zscaler builds a cloud-delivered zero trust security platform that replaces traditional network security appliances for enterprises and public-sector organizations. Its Zero Trust Exchange provides secure web gateway, zero trust access, CASB, and cloud firewall services, sold as subscriptions and delivered across 160+ global data centers. Founded in 2007 and headquartered in San Jose, it is a public company on NASDAQ (ZS) serving thousands of customers worldwide.
