Staff Information Security Engineer (Vulnerability Management) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Zscaler · 4 days ago

Staff Information Security Engineer (Vulnerability Management)

Zscaler is a company focused on accelerating digital transformation and enhancing cybersecurity through its cloud-native Zero Trust Exchange platform. They are seeking a Staff Information Security Engineer to operate in a vulnerability management role within a U.S. Federal IL6 environment, where the engineer will be responsible for designing network scanning, automating processes, and collaborating with service owners to mitigate risks.

Cloud SecurityCyber SecurityEnterprise SoftwareSecurity
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Designing and running authenticated/unauthenticated network and host scanning using IL6-approved tools in air-gapped environments (e.g., Tenable.sc / Nessus Manager or similar)
Building Python/Go/PowerShell automations for scan orchestration, asset onboarding, policy tuning, and diode-ready reporting formats
Driving collaboration with IL6 service owners to eliminate exploitable risks and manage patch/hardening campaigns
Producing weekly and monthly reporting aligned to IL6 program cadence and diode data transfer policies
Maintaining documentation, including runbooks, SOPs, exception governance, and change control processes within the SCIF

Qualification

Vulnerability ManagementTenable.sc/Nessus ManagerScripting in Python/Go/PowerShellCSPM conceptsWeb Application ScanningDoD 8570/8140 IAT Level IIAWS C2S/SC2S constructsFedRAMP High/Moderate operationsJira/ServiceNow familiarity

Required

U.S. citizenship with an active U.S. Top Secret (TS) clearance (must be maintained)
5+ years of experience with one or more of the following: Vulnerability Management
Experience with Tenable.sc/Nessus Manager or equivalents
Experience with CSPM concepts and/or Web Application Scanning (WAS) methodologies with solid understanding of risk-based prioritization (CVSS, EPSS), remediation lifecycle, and SLA governance
Scripting skills in Python, Go, or PowerShell for automation in disconnected environments

Preferred

DoD 8570/8140 IAT Level II certification (e.g., Security+ CE, GSEC, SSCP, CySA+)
Understanding of cloud and container platforms adapted to classified environments (e.g., AWS C2S/SC2S constructs, ECS/Kubernetes, VM hardening), and external attack surface concepts within constrained perimeters
Exposure to FedRAMP High/Moderate operations, including monthly monitoring programs (scanning, evaluation, patching, reporting) and familiarity with Jira/ServiceNow for ticketing and exception management in isolated environments

Benefits

Various health plans
Time off plans for vacation and sick time
Parental leave options
Retirement options
Education reimbursement
In-office perks, and more!

Company

Zscaler is a global cloud-based information security company that enables secure digital transformation for mobile and cloud.

Funding

Current Stage
Public Company
Total Funding
$1.67B
Key Investors
TPG GrowthLightspeed Venture Partners
2025-07-01Post Ipo Debt· $1.5B
2024-04-23Post Ipo Equity· $22.7M
2018-03-16IPO

Leadership Team

leader-logo
Jay Chaudhry
CEO, Chairman & Founder
linkedin
leader-logo
Hemant Dabke
Area Vice President
linkedin
Company data provided by crunchbase