About this role
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.
Role
We are looking for a Principal Engineer, Vulnerability & Exposure Management to join our team. This is a hybrid role, reporting to the Senior Manager, Information Security Engineering in the Product Security department. This critical role helps modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets. As an individual contributor, you will operate both strategically and technically to define the operating model, build scalable workflows, influence engineering teams, and dive deep into findings, coverage gaps, scanner limitations, and remediation paths with a strong builder mindset.
What you’ll do (Role Expectations)
• Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability
• Define advanced, risk-based prioritization models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams
• Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation
• Drive external attack surface management (EASM) to map internet-facing assets while aggressively identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions
• Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics
Who You Are (Success Profile)
• You thrive in ambiguity. You're comfortable building the path as you wal