Back to jobs
New

Staff Threat Researcher

Bellevue, Washington, USA; Remote - USA; San Jose, California, USA; Santa Clara, California, USA; USA - Update Location

Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.

We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.

Role

We are looking for a Staff Threat Researcher to join our team. This is a remote role, reporting to the Manager Threat Research in the Threat Research Team. As our Staff Threat Researcher, you will serve as a highly technical subject matter expert on adversary tradecraft across endpoint, cloud, and identity environments. You will apply formal research methodologies to dissect and replicate complex cyber attacks, answering the critical questions of exactly how techniques work and how we can best detect them. By transforming your deep technical discoveries into practical attack automations and scalable detection recommendations, you will bridge the gap between theoretical research and operational defense. In this role, your expertise will directly strengthen our defensive capabilities, inform our detection engineering priorities, contribute to broader product strategy, and keep our customers a step ahead of evolving evasion tactics.

What you’ll do (Role Expectations)

  • Scope (with some guidance) and continuously refine research initiatives, applying an adversarial mindset to analyze emerging attack techniques, customer impact, and detection data sources across at least one operating system (Windows, macOS, Linux) and major Cloud/SaaS providers like AWS, Microsoft 365, and Okta
  • Dive deep into the technical components and detection optics underlying specific threats to fully comprehend how adversaries control and manipulate variations of a given technique
  • Leverage your endpoint and cloud expertise to engineer automated attack code, write test code to validate threat coverage, and develop proofs of concept for new detections
  • Collaborate across Zscaler to develop new detection methodologies and engineering recommendations, working closely with detection engineers, intelligence analysts, and threat hunters to prioritize and refine deliverables
  • Document and present your research findings and operational deliverables in an accessible, actionable manner to internal and external audiences, while serving as a technical mentor for colleagues pursuing research

Who You Are (Success Profile)

  • You thrive in ambiguity and are comfortable building the path as you walk it, viewing dynamic environments as an opportunity to construct impactful solutions from scratch.
  • You act like an owner with a mission-driven bias for action, navigating seamlessly between high-level strategy and hands-on execution while operating with uncompromised integrity.
  • You are a dedicated problem-solver energized by tackling complex challenges, knowing that solving the toughest problems creates the greatest organizational impact.
  • You are a high-trust collaborator who values team success over individual accolades, actively giving and receiving candid feedback to build trust and elevate team performance.
  • You embody a growth mindset as a continuous learner, actively seeking feedback to hone your skills, support your peers, and deliver purposeful results.

What We’re Looking for (Minimum Qualifications)

  • Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
  • Experience working with commercial Endpoint Detection & Response (EDR) and/or Cloud-based detection platforms
  • Software development experience in at least one scripting language (e.g. PowerShell, Python, etc.) and one compiled language (e.g. C, C++, Go, etc.)
  • Security experience in at least one cloud service provider (e.g. AWS, GCP, Azure) and Cloud architectures
  • Established record of public, community engagement (conference talks, blog posts, or webinars, etc.)
  • Experience managing code with git/GitHub

What Will Make You Stand Out (Preferred Qualifications)

  • Proven ability to leverage AI technologies and workflows to drive measurable operational efficiency
  • An established record of public community engagement, such as conference talks, technical blog posts, or webinars

#LI-KM9 #LI-Remote

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range

$122,500 - $175,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Learn more about Zscaler's hybrid working model and benefits here.

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Please enter your full address including city, state/region, country, and postal/pin code.

Select...
Select...
Select...
Select...
Zscaler Confidential Information *

In consideration of Zscaler, Inc. or any of its subsidiaries (together referred to as “Zscaler”) granting the opportunity to apply for a position with Zscaler, I agree (a) to use Confidential Information for the sole purpose of evaluating a position with Zscaler, (b) that I will not disclose Confidential Information to anyone outside of Zscaler, (c) that all Confidential Information disclosed by Zscaler (and any derivative works thereof) remains the property of Zscaler, and no license or other rights to Confidential Information is granted or implied, (d) not to use the systems of my current employer to access any Confidential Information or download any Confidential Information onto the systems of my current employer, (e) immediately upon request, to return or destroy all the embodiments and copies of any Confidential Information, and (f) that “Confidential Information” means any nonpublic information disclosed to me by Zscaler, which Zscaler labels or otherwise identifies as confidential or a reasonable person would understand to be confidential.

Zscaler Privacy Policy *

By proceeding with your application or engaging in the recruitment process with you acknowledge that we will collect, use, and store your personal information in accordance with the data privacy notice linked below. Should you have any concerns or questions about how your personal data is handled, please don't hesitate to reach out to privacy@zscaler.com.

Privacy Policy

Select...

To ensure compliance with laws on hiring government employees, please let us know if you have a potential conflict of interest. This may apply if you are a current or former government employee who is, or has been, involved in procurement or contract award activities for Zscaler products or services.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Zscaler’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...