Zscaler Logo

Zscaler

Staff Information Security Engineer (Vulnerability Management)

Posted 7 Days Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in McLean, VA
116K-165K Annually
Senior level
Remote or Hybrid
Hiring Remotely in McLean, VA
116K-165K Annually
Senior level
The Staff Information Security Engineer will manage vulnerability assessments, automate scans using specific tools, and collaborate on risk management in a SCIF environment.
The summary above was generated by AI

About Zscaler

Zscaler accelerates digital transformation so our customers can be more agile, efficient, resilient, and secure. Our cloud native Zero Trust Exchange platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Here, impact in your role matters more than title and trust is built on results. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership and accountability. 

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges and want to make a positive difference on a global scale, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

Zscaler is expanding its U.S. Federal operations to support customers across multiple government departments. We are looking for a Staff Information Security Engineer who will report to the Senior Manager of Information Security Engineering to operate as a vulnerability management engineer inside the U.S. Federal IL6 (SCIF) environment. This is a fully onsite role based in the Crystal City / Arlington, VA area. The position operates strictly within a U.S. SCIF environment, requiring autonomy and adherence to one-way diode transfer protocols with no access to external networks or corporate systems.

What you’ll do (Role Expectations)

  • Designing and running authenticated/unauthenticated network and host scanning using IL6-approved tools in air-gapped environments (e.g., Tenable.sc / Nessus Manager or similar)
  • Building Python/Go/PowerShell automations for scan orchestration, asset onboarding, policy tuning, and diode-ready reporting formats
  • Driving collaboration with IL6 service owners to eliminate exploitable risks and manage patch/hardening campaigns
  • Producing weekly and monthly reporting aligned to IL6 program cadence and diode data transfer policies
  • Maintaining documentation, including runbooks, SOPs, exception governance, and change control processes within the SCIF

Who You Are (Success Profile)

  • You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
  • You are a problem-solver. You seek out challenges because you are energized by finding solutions, knowing that solving the hard problems delivers the biggest impact.
  • You are a learner. You have a true growth mindset and never stop developing yourself, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
  • You operate with urgency. You understand that in a high-growth environment, speed and quality are not mutually exclusive. You have a relentless focus on execution and a bias for action, delivering high-impact results quickly to win for the customer and the team.
  • You lead with integrity. You do the right thing, even when it’s hard. You hold yourself and others to a high standard of accountability and build trust by matching your words with consistent, transparent action.

What We’re Looking for (Minimum Qualifications)

  • U.S. citizenship with an active U.S. Top Secret (TS) clearance (must be maintained)  
  • 5+ years of experience with one or more of the following:
    • Vulnerability Management
    • Experience with Tenable.sc/Nessus Manager or equivalents
    • Experience with CSPM concepts and/or Web Application Scanning (WAS) methodologies with solid understanding of risk-based prioritization (CVSS, EPSS), remediation lifecycle, and SLA governance
    • Scripting skills in Python, Go, or PowerShell for automation in disconnected environments

What Will Make You Stand Out (Preferred Qualifications)

  • DoD 8570/8140 IAT Level II certification (e.g., Security+ CE, GSEC, SSCP, CySA+)
  • Understanding of cloud and container platforms adapted to classified environments (e.g., AWS C2S/SC2S constructs, ECS/Kubernetes, VM hardening), and external attack surface concepts within constrained perimeters
  • Exposure to FedRAMP High/Moderate operations, including monthly monitoring programs (scanning, evaluation, patching, reporting) and familiarity with Jira/ServiceNow for ticketing and exception management in isolated environments

#LI-Onsite #LI-KM9

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range
$115,500$165,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

Top Skills

Go
Nessus Manager
Powershell
Python
Tenable.Sc

Similar Jobs at Zscaler

3 Days Ago
Remote or Hybrid
McLean, VA, USA
116K-165K Annually
Senior level
116K-165K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
The Staff Information Security Engineer will manage vulnerability scans, automate processes using Python/Go/PowerShell, and enhance security posture in a SCIF environment while maintaining compliance.
Top Skills: Aws C2SGoJIRAKubernetesNessus ManagerPowershellPythonServicenowTenable.Sc
3 Days Ago
Remote or Hybrid
McLean, VA, USA
116K-165K Annually
Senior level
116K-165K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
The Staff Information Security Engineer will manage vulnerability scans, automate processes using Python/Go/PowerShell, and enhance security posture in a SCIF environment while maintaining compliance.
Top Skills: Aws C2SGoJIRAKubernetesNessus ManagerPowershellPythonServicenowTenable.Sc
4 Days Ago
Remote or Hybrid
USA
119K-145K Annually
Mid level
119K-145K Annually
Mid level
Cloud • Information Technology • Security • Software • Cybersecurity
The Enterprise Technical Account Manager acts as the technical liaison for enterprise customers, ensuring successful implementation and usage of Red Canary's security products while maximizing value and addressing technical requirements.
Top Skills: Amazon Web ServicesCrowdstrike FalconGoogle Cloud PlatformAzureMicrosoft Defender XdrMicrosoft Entra IdOktaPalo Alto Cortex XdrSentinelone SingularitySQLZscaler Internet AccessZscaler Private Access

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account