Zscaler logo
Zscaler

Zscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, the company operates o

Principal Vulnerability Management Engineer

EngineerEngineerFull TimeRemoteLeadTeam 8,697Since 2007

Location

India

Posted

1 day ago

Salary

0

Seniority

Lead

Job Description

Principal Vulnerability Management Engineer

Zscaler

Role Description We are looking for a Principal Engineer, Vulnerability & Exposure Management to help modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets. This is a remote role based in India, reporting to the Senior Manager, Information Security Engineering. This is an individual contributor role for someone who can operate strategically and technically: - Define the operating model, build scalable workflows, influence engineering teams, and go deep into findings, coverage gaps, scanner limitations, and remediation paths. - We are looking for someone who can improve the system itself, not just run scans, export reports, and follow up on tickets. What you’ll do (Role Expectations) - Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability. - Define advanced, risk-based prioritization models that integrate threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams. - Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation. - Drive external attack surface management (EASM) to map internet-facing assets while identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions. - Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics. Qualifications - 12+ years of experience in security engineering or product security, including 7+ years of hands-on experience driving and scaling vulnerability and exposure management programs within complex environments. - Deep understanding of scanner mechanics (including authenticated/unauthenticated scanning, coverage gaps, and asset correlation) paired with proficiency in platforms like Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite. - Practical experience implementing risk-based frameworks that leverage modern exploitability signals, threat intelligence, KEV, EPSS, and asset criticality to prioritize threats effectively. - Hands-on automation capabilities using Python, PowerShell, APIs, data pipelines, or workflow orchestration platforms to eliminate manual operational overhead. - Proven ability to partner collaboratively with engineering teams to drive remediation and translate complex technical data into clear insights for senior leadership. Requirements - Extensive experience securing multi-cloud environments (AWS, Azure, GCP) and containerized architecture (Kubernetes), including image scanning, runtime security, and embedding security guardrails into CI/CD and DevSecOps pipelines. - Proven track record in advanced vulnerability prioritization strategies (EASM, CTEM, and attack-path analysis) paired with the ability to integrate vulnerability data seamlessly into CMDBs, asset inventories, and ownership tracking systems. - Deep familiarity with orchestration and ticketing platforms (Avalor, Nucleus, Tines, Jira, ServiceNow) to build AI-assisted, self-service triage, remediation, and reporting workflows that drive operational efficiency for engineering teams. Benefits - Various health plans - Time off plans for vacation and sick time - Parental leave options - Retirement options - Education reimbursement - In-office perks, and more!

Related Categories

Related Job Pages

More Engineer Jobs

Role Description Design, implement and maintain new features and functionalities for the SAAS platform, understanding the requirements of insurance businesses and translating them into scalable and efficient software solutions. - Work on both the front-end and back-end of the application, demonstrating expertise in various technologies, frameworks, and programming languages. - Work collaboratively with product, design, engineering teams, and UX designers to understand end-user requirements, use cases, and technical concepts, translating them into a cohesive and effective solution while ensuring a seamless user experience. - Optimize the performance of the application to handle large amounts of data and high user traffic, delivering a smooth user experience. - Participate in code reviews and enforce best coding practices, while also writing and executing unit tests and integration tests to maintain code quality. - Investigate and promptly fix bugs to maintain the reliability of the platform. - Ensure security and compliance by following best practices for securing web applications and adhering to relevant regulations in handling sensitive customer data. - Stay up-to-date with the latest technologies, frameworks, and best practices to ensure we remain competitive and innovative. - Design the platform with scalability and flexibility in mind, accommodating new features and changes as the number of clients and users grows. - Provide mentorship to junior developers, aiding in their technical growth and effective contribution to the team's goals. Qualifications - Proven experience 6 years as a Full Stack Engineer, working on complex SAAS applications. - Strong technical background with proficiency in front-end and back-end technologies, such as JavaScript, Vue, .NET Core, C#, GraphQL, MongoDB, Docker. - Familiarity with cloud platforms like AWS, Azure, or Google Cloud for building scalable applications. - Thorough understanding and practical experience with Test-Driven Development (TDD) to ensure robust and well-tested code. - Experience with unit, integration and function testing using front-end and back-end testing libraries. - Proficiency in Domain-Driven Design (DDD) principles to create a maintainable and modular architecture that aligns with business domains. - In-depth knowledge of web security best practices and experience in ensuring compliance with industry regulations. - Demonstrated experience in performance optimization for high-traffic web applications. - Experience with container technologies like Docker and good understanding of cloud infrastructure and solutions. - Experience with agile development methodologies and collaborating with cross-functional teams. - Excellent problem-solving skills and a proactive approach to troubleshooting and bug fixing. - Strong communication skills to effectively interact with both technical and non-technical team members with diverse backgrounds. - A passion for staying updated with the latest trends, technologies, and best practices in software development. Benefits - Competitive renumeration package. - International Environment. - 15 days annual leave, 10 sick leaves, special leaves. - Annual Performance Bonus. - Stock Options after 6 months. - Company activities and events. - Learning and development plan.

CET (UTC+1)
Miratech logo

Junior DialogFlow Engineer

Miratech

Helping Visionaries Change the World

Engineer1 day ago
Full TimeRemoteTeam 501-1,000Since 1989H1B No Sponsor

• Design, develop, and deploy chatbots and voice bots utilizing leading Conversational AI platforms such as Microsoft Bot Framework, Google CCAI, Dialogflow CX. • Craft clean, efficient, and maintainable code adhering to industry best practices and standards. • Develop custom components and tools to optimize the functionality and performance of our chatbot ecosystem. • Collaborate closely with developers, designers, and other stakeholders to meet project requirements and user expectations. • Leverage natural language processing (NLP), LLM and machine learning (ML) techniques, including TTS, STT, and SSML, to enable our chatbots to comprehend and respond intelligently to user inputs. • Integrate chatbot systems seamlessly with backend systems, databases, and APIs to facilitate smooth data exchange and interactions. • Investigate and resolve complex technical issues by analysing logs and debugging code for continuous improvement. • Stay ahead of the curve by keeping up-to-date with the latest trends and advancements in chatbot development.

India
FDA Ingenieros logo

Ingeniero/a Civil Estructural – Terreno

FDA Ingenieros

Desarrollamos proyectos de Ingeniería multidisciplinaria para la Mediana y Gran Minería.

Engineer1 day ago
Full TimeRemoteTeam 51-200Since 2000H1B No Sponsor

• Realizar levantamientos estructurales en terreno • Confeccionar documentos técnicos e informes RC22 • Revisar documentación técnica multidisciplinaria • Analizar y estudiar antecedentes técnicos de proyectos • Ejecutar visitas técnicas a terreno según requerimientos operacionales

Chile
FDA Ingenieros logo

Ingeniero/a Civil Eléctrico – Ingeniero/a de Proyectos

FDA Ingenieros

Desarrollamos proyectos de Ingeniería multidisciplinaria para la Mediana y Gran Minería.

Engineer1 day ago
Full TimeRemoteTeam 51-200Since 2000H1B No Sponsor

• Desarrollo de documentación de ingeniería desde prefactibilidad a detalle. • Trabajo con clientes para entender sus desafíos y necesidades, a través de soluciones adecuadas para cada proceso, teniendo foco en la mejor solución técnico-económica para cada desafío. • Trabajo de levantamiento en terreno.

Chile