Principal Vulnerability Management Engineer
Job description
About the role
Zscaler is seeking a Principal Engineer to modernize how the company identifies and mitigates security risks across its global infrastructure. This individual contributor role focuses on building scalable automation and risk-based models to secure cloud, application, and endpoint environments. The position sits within Product Security and reports to the Senior Manager, Information Security Engineering, where you will drive strategic initiatives that convert raw vulnerability and threat data into actionable engineering workflows. You will own the design and execution of programs that shift vulnerability management from a reactive reporting function to a proactive, product-oriented security capability. In this capacity, you will act as a technical visionary, defining the roadmap for risk-based prioritization and automated remediation across the organization. Your work will directly influence how the company measures and reduces its exposure posture in dynamic cloud and hybrid environments. This role requires a hands-on practitioner who thrives on solving complex infrastructure security challenges with data-driven decision-making.
Key facts
What you'll do
- Transform vulnerability management from a reporting function into a product security engineering capability by defining scalable processes and measurable outcomes.
- Develop risk-based prioritization models that leverage threat intelligence, business context, KEV feeds, and EPSS data to guide remediation efforts.
- Build and maintain automated pipelines that cover asset discovery, continuous scanning, intelligent triage, and dynamic remediation routing.
- Execute external attack surface management activities to identify, inventory, and map internet-facing assets and their associated risks.
- Partner closely with DevOps and IT teams to provide technical guidance, drive best practices, and improve the security posture of infrastructure as code.
- Design and implement integrations that normalize vulnerability findings from multiple vendors and internal tools into a unified risk view.
- Create dashboards, metrics, and reporting artifacts that communicate risk trends, program effectiveness, and exposure reduction to both technical and executive audiences.
- Collaborate with data scientists and platform engineers to explore and prototype AI and machine learning techniques that enhance vulnerability analysis.
- Establish feedback loops with development teams to ensure that security insights lead to timely and efficient remediation.
- Act as a subject matter expert for vulnerability management strategy, influencing architectural decisions and security standards across the organization.
Requirements
- Bring 12 or more years of total professional experience in security or product security engineering roles.
- Demonstrate 7 or more years of hands-on experience scaling vulnerability and exposure management programs in complex environments.
- Show proficiency with scanner mechanics, including both authenticated and unauthenticated scanning techniques and their limitations.
- Have practical experience with commercial and open source security tools such as Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite.
- Apply practical knowledge of AI and machine learning technologies to identify opportunities for security optimization and automation.
- Exhibit strong automation skills using scripting languages such as Python and PowerShell, along with robust API integrations.
- Understand how to design data pipelines that collect, transform, and normalize vulnerability and asset data from heterogeneous sources.
- Communicate effectively with technical and non-technical stakeholders, translating complex risk findings into clear recommendations.
Nice to have
- Apply experience using AI and machine learning not only for detection but also for predictive exposure analysis and automated remediation workflows.
- Demonstrate a background in securing multi-cloud environments, including AWS, Azure, and GCP, along with strong knowledge of Kubernetes container security.
- Show expertise in integrating vulnerability data with configuration management databases and dynamic asset inventory systems.
- Have familiarity with Cyber Threat Exposure Management and advanced attack-path analysis techniques to model risk across environments.
Skills & tools
- Scripting and programming with Python and PowerShell.
- Hands-on experience with Tenable, Qualys, Wiz, CrowdStrike, and Burp Suite.
- Cloud platform knowledge in AWS, Azure, GCP, and container orchestration with Kubernetes.
- Building and maintaining API orchestration and data pipelines for security operations.
Practical notes
- This is a hybrid role, allowing flexibility in how and where work is performed.
- The position is eligible for comprehensive benefits, including health plans, parental leave, retirement options, education reimbursement, and vacation time.
- Zscaler is committed to providing reasonable accommodations throughout the recruiting process for candidates with health conditions, religious beliefs, or neurodivergence.
About the company
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world's largest security data lake to power our cloud-native Zero Trust Exchange platform.