Staff Information Security Engineer (Vulnerability Management) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Zscaler · 1 day ago

Staff Information Security Engineer (Vulnerability Management)

Zscaler is a company focused on accelerating digital transformation and enhancing cybersecurity for its customers. They are seeking a Staff Information Security Engineer to operate within the U.S. Federal IL6 environment, focusing on vulnerability management and ensuring security protocols are strictly followed.

Cloud SecurityCyber SecurityEnterprise SoftwareSecurity
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Designing and running authenticated/unauthenticated network and host scanning using IL6-approved tools in air-gapped environments (e.g., Tenable.sc / Nessus Manager or similar)
Building Python/Go/PowerShell automations for scan orchestration, asset onboarding, policy tuning, and diode-ready reporting formats
Driving collaboration with IL6 service owners to eliminate exploitable risks and manage patch/hardening campaigns
Producing weekly and monthly reporting aligned to IL6 program cadence and diode data transfer policies
Maintaining documentation, including runbooks, SOPs, exception governance, and change control processes within the SCIF

Qualification

Vulnerability ManagementTenable.sc/Nessus ManagerPythonGoPowerShellCSPM conceptsWeb Application ScanningCVSSEPSSDoD 8570/8140 IAT Level II certificationAWS C2S/SC2SKubernetesFedRAMP High/Moderate operationsJiraServiceNow

Required

U.S. citizenship with an active U.S. Top Secret (TS) clearance (must be maintained)
5+ years of experience with one or more of the following: Vulnerability Management, Experience with Tenable.sc/Nessus Manager or equivalents, Experience with CSPM concepts and/or Web Application Scanning (WAS) methodologies with solid understanding of risk-based prioritization (CVSS, EPSS), remediation lifecycle, and SLA governance, Scripting skills in Python, Go, or PowerShell for automation in disconnected environments

Preferred

DoD 8570/8140 IAT Level II certification (e.g., Security+ CE, GSEC, SSCP, CySA+)
Understanding of cloud and container platforms adapted to classified environments (e.g., AWS C2S/SC2S constructs, ECS/Kubernetes, VM hardening), and external attack surface concepts within constrained perimeters
Exposure to FedRAMP High/Moderate operations, including monthly monitoring programs (scanning, evaluation, patching, reporting) and familiarity with Jira/ServiceNow for ticketing and exception management in isolated environments

Benefits

Various health plans
Time off plans for vacation and sick time
Parental leave options
Retirement options
Education reimbursement
In-office perks, and more!

Company

Zscaler is a global cloud-based information security company that enables secure digital transformation for mobile and cloud.

Funding

Current Stage
Public Company
Total Funding
$1.67B
Key Investors
TPG GrowthLightspeed Venture Partners
2025-07-01Post Ipo Debt· $1.5B
2024-04-23Post Ipo Equity· $22.7M
2018-03-16IPO

Leadership Team

leader-logo
Jay Chaudhry
CEO, Chairman & Founder
linkedin
leader-logo
Hemant Dabke
Area Vice President
linkedin
Company data provided by crunchbase