About this role
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.
Role
We are looking for a Staff Compliance Architect to join our team. This is a Remote (if located outside of the San Jose, CA area) or Hybrid (based in San Jose, CA) role, reporting to the Director, Technology Risk and Compliance in the Exposure Management & Security Operations department. Zscaler is seeking an experienced Staff Compliance Architect to serve as the compliance team’s technical subject matter expert and to embed scalable, auditable compliance requirements into product and infrastructure delivery. This role brings an architectural mindset to compliance, partnering closely with Engineering, Product, Compliance Engineering, and Authorization Operations (AuthOps) to translate regulatory and assurance obligations into clear technical requirements, standardized implementation patterns, and automated validation.
What you’ll do (Role Expectations)
• Define and maintain enterprise privacy baseline requirements, embedding them into the SDLC by translating regulatory and assurance expectations (e.g., NIST 800-53, FedRAMP/DoD IL5 privacy-relevant controls, and ISO 27701/ISO 42001) into measurable technical criteria and acceptance tests
• Establish standardized privacy-by-design patterns (data minimization, purpose limitation, retention/deletion, privacy-safe telemetry, access controls) and partner with Engineering/Compliance Engineering to automate validation and evidence collection through CI/CD guardrails and policy-as-code
• Conduct privacy architecture reviews and operational readiness assessments to identify data-handling risks (collection, use, sharing, storage, logging), and provide actionable remediation guidance aligned to engineering realities and delivery timelines
• Maintain authoritative data flow diagrams and processing narratives, ensuring data classifications, processing purposes, transfer points, trust boundaries, and retention expectations are current, consiste