Principal Vulnerability Management Engineer
About Zscaler
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.
We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.
Role
We are looking for a Principal Engineer, Vulnerability & Exposure Management to help modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets. This is a remote role based in India, reporting to the Senior Manager, Information Security Engineering.
This is an individual contributor role for someone who can operate strategically and technically: define the operating model, build scalable workflows, influence engineering teams, and still go deep into findings, coverage gaps, scanner limitations, and remediation paths. The right candidate will bring a builder mindset. We are not looking for someone who only runs scans, exports reports, and follows up on tickets. We are looking for someone who can improve the system itself.
What you’ll do (Role Expectations)
- Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability.
- Define advanced, risk-based prioritisation models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams.
- Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation.
- Drive external attack surface management (EASM) to map internet-facing assets while aggressively identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions.
- Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics.
Who You Are (Success Profile)
- You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful
- You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution
- You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact
- You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust
- You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose
What We’re Looking for (Minimum Qualifications)
- 12+ years of experience in security engineering or product security, including 7+ years of hands-on experience driving and scaling vulnerability and exposure management programs within complex environments
- Deep understanding of scanner mechanics (including authenticated/unauthenticated scanning, coverage gaps, and asset correlation) paired with proficiency in platforms like Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite
- Practical experience implementing risk-based frameworks that leverage modern exploitability signals, threat intelligence, KEV, EPSS, and asset criticality to prioritize threats effectively
- Hands-on automation capabilities using Python, PowerShell, APIs, data pipelines, or workflow orchestration platforms to eliminate manual operational overhead.
- Proven ability to partner collaboratively with engineering teams to drive remediation (without relying on heavy escalation) and translate complex technical data into clear insights for senior leadership
What Will Make You Stand Out (Preferred Qualifications)
- Extensive experience securing multi-cloud environments (AWS, Azure, GCP) and containerized architecture (Kubernetes), including image scanning, runtime security, and embedding security guardrails into CI/CD and DevSecOps pipelines.
- Proven track record in advanced vulnerability prioritization strategies (EASM, CTEM, and attack-path analysis) paired with the ability to integrate vulnerability data seamlessly into CMDBs, asset inventories, and ownership tracking systems.
- Deep familiarity with orchestration and ticketing platforms (Avalor, Nucleus, Tines, Jira, ServiceNow) to build AI-assisted, self-service triage, remediation, and reporting workflows that drive operational efficiency for engineering teams.
#LI-Hybrid #LI-PM5
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
Apply for this job
*
indicates a required field
.jpg?1700169058)