Sr. Staff, Security Research (Risk Management)

4 Months ago • 7 Years + • Cyber Security

Job Summary

Job Description

The Sr. Staff, Security Researcher at Zscaler's Cyber and Data Security Team conducts comprehensive risk assessments of third-party vendors, evaluating cybersecurity posture, data protection, and regulatory compliance. This role involves managing vendor intake, reviewing documentation, and collaborating with procurement, legal, compliance, and IT teams. Responsibilities include security monitoring of third parties, incident response support, and program improvements (policies, procedures, AI/ML tooling). The position also requires generating risk rating metrics and reports, identifying and escalating potential risks. This is a hybrid role requiring 3 days a week in the Escazu office.
Must have:
  • 7+ years in cybersecurity (risk management, vendor assessments, etc.)
  • Broad understanding of security best practices and technologies
  • Familiarity with cybersecurity standards (NIST, ISO 27001, SOC2, GDPR)
  • Excellent communication and collaboration skills
Good to have:
  • Experience with GRC tools, vendor management, and incident response
  • Knowledge of cloud security and third-party services (SaaS, PaaS)
  • Experience with AI/ML
Perks:
  • Various health plans
  • Time off plans
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks

Job Details

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. 

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. 

Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

We're looking for an experienced Sr Staff, Security Researcher to join our Cyber and Data Security Team.  This is a hybrid work environment, going in to our Escazu office 3 days a week.  Reporting to the VP, Corporate CISO, you will do the following: 

  • Risk Assessments: Conduct comprehensive risk assessments of third-party vendors to evaluate their cybersecurity posture, data protection practices, and compliance with relevant regulations. Manage the vendor intake process and review required documentation and evidence.
  • Cross-Functional Collaboration: Partner with procurement, legal, compliance, IT, and other functions to ensure appropriate due diligence is performed on vendors and partners before contract signing.
  • Security Monitoring: Monitor and assess the security of third parties, support the response and remediation of cybersecurity incidents involving third-party vendors, and ensure vendors are taking necessary steps to reduce their exposure.
  • Program Improvements: Evaluate and implement improvements to the Third-Party Risk Management (TPRM) program, including changes to policies, procedures, templates, questionnaires, technical security standards, guidelines, and AI/ML tooling. Analyze regulatory changes that may impact vendor due diligence requirements.
  • Reporting and Metrics: Generate security risk rating metrics and reports summarizing risk assessments, issues, and mitigation plans. Identify and report or escalate potential areas of risk or non-responses.

What We're Looking for (Minimum Qualifications)

  • Minimum 7+ years' experience in cybersecurity roles such as risk management, vendor risk assessments, incident response, security operations, security engineering, or network security.
  • Broad understanding of security best practices and technologies, including application security, secure software development lifecycles, risk management, data protection, encryption & key management, identity and access management, security operations, security governance, and network security.
  • Familiarity with cybersecurity standards such as NIST, ISO 27001, SOC2, and GDPR.
  • Excellent communication and interpersonal skills for effective collaboration with stakeholders at all levels, including geographically distributed teams, on risk assessment, threat modeling, and vulnerability remediation.

What Will Make You Stand Out (Preferred Qualifications)

  • Preferred experience with GRC (Governance, Risk, and Compliance), vendor management, and incident response tools.
  • Preferred knowledge of cloud security, third-party services (e.g., SaaS, PaaS), and AI/ML.

#LI-Hybrid

#LI-BH1

 

At Zscaler, we believe that diversity drives innovation, productivity, and success. We are looking for individuals from all backgrounds and identities to join our team and contribute to our mission to make doing business seamless and secure. We are guided by these principles as we create a representative and impactful team, and a culture where everyone belongs. For more information on our commitments to Diversity, Equity, Inclusion, and Belonging, visit the Corporate Responsibility page of our website.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is proud to be an equal opportunity and affirmative action employer. We celebrate diversity and are committed to creating an inclusive environment for all of our employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status or any other characteristics protected by federal, state, or local laws.

See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules. For additional information about the federal requirements, click here.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Similar Jobs

Axinous - Staff Software Development Engineer (Backend)

Axinous

Bengaluru, Karnataka, India (On-Site)
4 Months ago
ION - Network Design Engineer - 4307

ION

Woking, England, United Kingdom (On-Site)
6 Months ago
Rackspace Technology - Sr. Cloud Security Engineer

Rackspace Technology

United States (Remote)
3 Months ago
Axinous - Senior Sales Engineer - Major Accounts UK

Axinous

United Kingdom (Remote)
2 Months ago
DNEG - Security Operations Centre (SOC) Lead

DNEG

Mumbai, Maharashtra, India (On-Site)
5 Months ago
Mattel  Inc  - Manager IT - Governance, Risk & Compliance (GRC)

Mattel Inc

California, United States (On-Site)
4 Months ago
PwC - SRC_Cyber Strategy

PwC

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Microsoft - Customer Experience Program Manager

Microsoft

San José, San José Province, Costa Rica (On-Site)
4 Months ago
Normalyze - Customer Success Engineer - Data Security - Implementation - DSPM - Bangalore

Normalyze

Bengaluru, Karnataka, India (Remote)
6 Months ago
ByteDance - Senior Software Engineer, Global Payment Security

ByteDance

San Jose, California, United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Interactive Brokers - Senior Cloud Security Engineer

Interactive Brokers

Fort Lauderdale, Florida, United States (Hybrid)
6 Months ago
Sinch - Product Security Engineer

Sinch

India (Remote)
2 Months ago
Nielsen Holdings - Data Engineer

Nielsen Holdings

Mumbai, Maharashtra, India (Hybrid)
4 Months ago
Canva - Senior Software Engineer - Cloud Security & Compliance, remote across ANZ

Canva

Sydney, New South Wales, Australia (Remote)
4 Months ago
Rush Street Interactive - Infrastructure Security Engineer

Rush Street Interactive

Estonia (Hybrid)
2 Months ago
PwC - Senior Security Engineers (Entra ID/AD)

PwC

Sofia, Sofia City Province, Bulgaria (On-Site)
6 Months ago
Animoca Brands - Security Operations Engineer

Animoca Brands

Hong Kong (On-Site)
3 Months ago
PwC - Managed Services - Technology - Cloud Security Associate

PwC

Riyadh, Riyadh Province, Saudi Arabia (On-Site)
3 Months ago
Playtech - Junior Cloud Security Engineer

Playtech

Kyiv, Kyiv City, Ukraine (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Escazu, San José Province, Costa Rica

Hitachi - Dynamics CE Consultant (remote*/Costa Rica-based)

Hitachi

San José, San José Province, Costa Rica (Remote)
6 Months ago
Granicus - Customer Success Consultant

Granicus

Costa Rica (Remote)
6 Months ago
Hitachi - Associate F&O Finance Consultant

Hitachi

San José, San José Province, Costa Rica (On-Site)
6 Months ago
Intel Corporation - SoC Design Engineer Student

Intel Corporation

San José, San José Province, Costa Rica (Hybrid)
4 Months ago
Axinous - Technical Account Manager

Axinous

Costa Rica (Remote)
2 Months ago
Intel Corporation - Web Application Development Engineer

Intel Corporation

San José, San José Province, Costa Rica (Hybrid)
4 Months ago
Nagarro - Associate Staff Engineer

Nagarro

San José Province, Costa Rica (On-Site)
6 Months ago
Granicus - Data Insights Analyst

Granicus

Costa Rica (Remote)
6 Months ago
Hitachi - Senior Software Engineer

Hitachi

San José, San José Province, Costa Rica (Remote)
6 Months ago
Intel Corporation - AMR Rebates Team Lead and SME Analyst

Intel Corporation

San José, San José Province, Costa Rica (Hybrid)
5 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Unity - Senior Infrastructure Security Manager

Unity

Austin, Texas, United States (On-Site)
6 Months ago
PwC - Financial Sector Information Protection Consultant

PwC

Amsterdam, North Holland, Netherlands (Hybrid)
3 Months ago
NVIDIA - Senior Security Engineer, Purple Team - GPU Firmware

NVIDIA

Santa Clara, California, United States (On-Site)
3 Months ago
ION - Senior Security Architect

ION

Italy (On-Site)
6 Months ago
Polygon Labs - Senior Security Engineer (Rust)

Polygon Labs

(Remote)
3 Months ago
Xsolla - Application Security Specialist

Xsolla

Baku, Azerbaijan (On-Site)
5 Months ago
ESL FACEIT Group - EFG - Information Security Analyst

ESL FACEIT Group - EFG

United Kingdom (Remote)
3 Months ago
The Walt Disney Company - Agent(e) de Sécurité F/H/NB - CDI

The Walt Disney Company

Île-de-France, France (On-Site)
3 Months ago
PwC - Senior Associate - Data Engineer - D&AT IFS

PwC

Bengaluru, Karnataka, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Axonius gives customers the confidence to control complexity by mitigating threats, navigating risk, automating response actions, and informing business-level strategy. With solutions for both cyber asset attack surface management (CAASM) and SaaS management, Axonius is deployed in minutes and integrates with hundreds of data sources to provide a comprehensive asset inventory, uncover gaps, and automatically validate and enforce policies. Cited as one of the fastest-growing cybersecurity startups, with accolades from CNBC, Forbes, and Fortune, Axonius covers millions of assets, including devices and cloud assets, user accounts, and SaaS applications, for customers around the world. For more, visit Axonius.com.

Virginia, United States (Remote)

Perth, Western Australia, Australia (Remote)

Sahibzada Ajit Singh Nagar, Punjab, India (On-Site)

Hyderabad, Telangana, India (Remote)

North Carolina, United States (Remote)

Tamil Nadu, India (Remote)

Wisconsin, United States (Remote)

United Kingdom (Remote)

View All Jobs

Get notified when new jobs are added by Axinous

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug