Principal Vulnerability Management Engineer
ZScaler
About the role
About Zscaler
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.
We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.
Role
We are looking for a Principal Engineer, Vulnerability & Exposure Management to help modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets. This is a remote role based in India, reporting to the Senior Manager, Information Security Engineering.
This is an individual contributor role for someone who can operate strategically and technically: define the operating model, build scalable workflows, influence engineering teams, and still go deep into findings, coverage gaps, scanner limitations, and remediation paths. The right candidate will bring a builder mindset. We are not looking for someone who only runs scans, exports reports, and follows up on tickets. We are looking for someone who can improve the system itself.
What you’ll do (Role Expectations)
Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability.
Define advanced, risk-based prioritisation models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams.
Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation.
Drive external attack surface manageme