Sr Staff, Security Third Party Risk Management

3 Months ago • 7 Years + • Risk Management

Job Summary

Job Description

As a Senior Staff, Cybersecurity Third Party Risk Management professional, you will be responsible for conducting risk assessments of third-party vendors, ensuring their cybersecurity posture and data protection practices align with regulations. You will collaborate with various teams to perform due diligence on vendors, monitor third-party security, and improve the TPRM program. You'll analyze regulatory changes and generate reports on risk assessments and mitigation plans. You should have at least 7 years of experience in cybersecurity, including risk management and vendor risk assessments, and understand various security best practices and frameworks.
Must have:
  • 7+ years experience in cybersecurity roles
  • Understanding of security best practices
  • Experience with security frameworks like NIST
Good to have:
  • Familiarity with GRC platforms
  • Knowledge of cloud security and AI/ML
Perks:
  • Various health plans
  • Time off for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks

Job Details

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform, which is found in our SASE and SSE offerings, protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. 

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

We’re looking for a Senior Staff, Cybersecurity Third Party Risk Management professional to join our growing cybersecurity team, operating remotely within Costa Rica. Reporting to the Director of Security Strategy, Transformation & Vendor Risk Management, you will be responsible for:

  • Conducting comprehensive risk assessments of third-party vendors to evaluate their cybersecurity posture, data protection practices, and compliance with relevant regulations, including managing the vendor intake process, collecting all necessary information and reviewing required evidence
  • Partnering with procurement, legal, compliance, IT, and other functions to ensure due diligence is performed on vendors and partners prior to contract signing
  • Monitoring and assessing the security of third parties and supporting the response and remediation of cybersecurity incidents involving vendors, ensuring steps are taken to reduce exposure
  • Evaluating and implementing improvements to the TPRM program, including policies, procedures, templates, questionnaires, technical security standards and AI governance; analyzing regulatory and standards changes impacting vendor due diligence requirements
  • Generating security risk rating metrics and creating reports summarizing risk assessments, issues, and mitigation plans while escalating potential risks or non-responses

What We’re Looking for (Minimum Qualifications)

  • Minimum 7+ years of experience in one or more of the following cybersecurity roles: risk management, vendor risk assessments, incident response, security operations, security engineering, or network security
  • Understanding of a broad set of security best practices including application security, secure software development lifecycles, risk management, data protection, encryption, identity and access management, security governance, and network security
  • Experience with common cybersecurity frameworks and standards such as NIST, ISO 27001, SOC2, and GDPR
  • Experience in collaborating and communicating with stakeholders across all levels and teams in multiple geographies.
  • Strong problem-solving skills and ability to handle complex risk assessment, threat modeling scenarios, and remediation of vulnerabilities

What Will Make You Stand Out (Preferred Qualifications)

  • Familiarity with GRC platforms and tools for vendor risk management or incident response
  • Knowledge of cloud security, third-party services (e.g., SaaS, PaaS), and AI/ML

#LI-Remote 

#LI-YC2

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Similar Jobs

NCR Voyix - Buyer II

NCR Voyix

India (Remote)
3 Weeks ago
Britive - SENIOR QA ENGINEER

Britive

Bengaluru, Karnataka, India (Remote)
9 Months ago
Scale AI - Head of Solution Engineering, Enterprise

Scale AI

San Francisco, California, United States (On-Site)
3 Months ago
Nasdaq - Commercial Management – Sr. Analyst

Nasdaq

Mumbai, Maharashtra, India (On-Site)
1 Year ago
Highspot - Senior Product Manager, Search and AI

Highspot

Hyderabad, Telangana, India (Hybrid)
2 Months ago
Jane Street - Technology Governance & Risk Specialist

Jane Street

London, England, United Kingdom (On-Site)
3 Months ago
PwC - Assurance - Manager - Risk Assurance (FRM)

PwC

Jakarta, Jakarta, Indonesia (On-Site)
10 Months ago
bytedance - Fraud Risk Strategy Expert - Global Payment

bytedance

Singapore (On-Site)
9 Months ago
Epic Games - Third Party Risk Management Analyst

Epic Games

Cary, North Carolina, United States (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Coupa - Customer Solution Partner

Coupa

State Of São Paulo, Brazil (Hybrid)
1 Month ago
USE Insider - Chatbot Integration & Onboarding Specialist - Arabic Speaker

USE Insider

Istanbul, İstanbul, Türkiye (Hybrid)
2 Weeks ago
Workato - Senior AI Solutions Engineer

Workato

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Zenoti - Sales Development Representative - Outbound

Zenoti

Hyderabad, Telangana, India (On-Site)
1 Month ago
Synthesia - Trust Operations Analyst

Synthesia

New York, United States (Remote)
1 Month ago
DevRev - Recruiter (Go-to-Market & Technical Functions)

DevRev

Ljubljana, Ljubljana, Slovenia (Hybrid)
1 Month ago
Stibo Systems - Solution Architect

Stibo Systems

São Paulo, Brazil (Hybrid)
1 Year ago
SparkCognition - DevOps Engineer

SparkCognition

Bengaluru, Karnataka, India (On-Site)
11 Months ago
Agara labs - Senior Enterprise Account Executive

Agara labs

California City, California, United States (Remote)
3 Months ago
USE Insider - Senior Digital Designer

USE Insider

Türkiye (Remote)
7 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Costa Rica

Syniverse - Messaging Trust Data Analyst

Syniverse

San José Province, Costa Rica (Hybrid)
1 Year ago
Arkose Labs - Platform Engineer

Arkose Labs

San José Province, Costa Rica (Remote)
3 Months ago
Evolution  - Certification Specialist (Costa Rica)

Evolution

San José, San José Province, Costa Rica (On-Site)
1 Year ago
Granicus - Digital Advertising Support Specialist

Granicus

Costa Rica (Remote)
6 Months ago
Veeam Software - Manager, Sales Development

Veeam Software

Cariari, Provincia De Puntarenas, Costa Rica (On-Site)
3 Months ago
Autodesk - Business Analyst

Autodesk

Costa Rica (Remote)
2 Months ago
Wind River - Senior Payroll Analyst

Wind River

San José Province, Costa Rica (On-Site)
1 Month ago
Zuora - Sr Database Engineer (MySQL)

Zuora

Costa Rica (Hybrid)
2 Months ago
Publicis Groupe - Content Creator

Publicis Groupe

Heredia, Costa Rica (Hybrid)
4 Weeks ago
Veeam Software - Sales Development Representative - FRENCH & ENGLISH

Veeam Software

San José Province, Costa Rica (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Risk Management Jobs

PwC - Associate Enterprise Risk Management - Roma (OTS)

PwC

Rome, Lazio, Italy (On-Site)
10 Months ago
Guardian - Vendor Assessment & Risk Controls Lead

Guardian

Holmdel, New Jersey, United States (Hybrid)
3 Weeks ago
DraftKings - Risk Operations Associate

DraftKings

Sofia, Sofia City Province, Bulgaria (On-Site)
3 Weeks ago
Ion - Senior Risk Analyst, Italy

Ion

Pisa, Tuscany, Italy (On-Site)
10 Months ago
Remote - Payroll Risk & Compliance Lead - APAC

Remote

Philippines (Remote)
3 Weeks ago
Xepelin - Risk & Portfolio Director

Xepelin

Santiago, Santiago Metropolitan Region, Chile (Hybrid)
3 Months ago
London stock Exchange - Senior Manager - Risk Coverage

London stock Exchange

London, England, United Kingdom (On-Site)
1 Month ago
Nintendo - Risk Management Specialist (m/f/d)

Nintendo

Frankfurt Am Main, Hessen, Germany (On-Site)
10 Months ago
Go Fund Me - Risk Analyst

Go Fund Me

(Remote)
1 Month ago
PwC - Risk Services - Risk Regulatory & Compliance, Insurance

PwC

Singapore (On-Site)
10 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Zscaler enables the world’s leading organizations to securely transform their networks and applications for a mobile and cloud first world. Its flagship services, Zscaler Internet Access and Zscaler Private Access, create fast, secure connections between users and applications, regardless of device, location, or network. Zscaler services are 100% cloud-delivered and offer the simplicity, enhanced security, and improved user experience that traditional appliances or hybrid solutions are unable to match. Used in more than 185 countries, Zscaler operates the world’s largest cloud security platform, protecting thousands of enterprises and government agencies from cyberattacks and data loss.



Stay Connected:

LinkedIn: https://www.linkedin.com/company/zscaler

Twitter: https://www.twitter.com/zscaler

Facebook: https://www.facebook.com/Zscaler/

Bengaluru, Karnataka, India (Hybrid)

Hyderabad, Telangana, India (Hybrid)

Hyderabad, Telangana, India (Hybrid)

San Jose, California, United States (Remote)

Bengaluru, Karnataka, India (Hybrid)

Bengaluru, Karnataka, India (Hybrid)

Bellevue, Washington, United States (Remote)

Bengaluru, Karnataka, India (Hybrid)

San Jose, California, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Zscaler

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug