yandex
zscaler
Страна
США
Зарплата
164 500 $ – 235 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
SeniorГибридПолная занятость

Senior Governance, Risk & Compliance Manager - NIST, FAIR

Оценка ИИ

Отличная вакансия в компании-лидере рынка кибербезопасности с прозрачным диапазоном зарплаты, сильным социальным пакетом и возможностью работать над передовыми AI-решениями.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена требованием более 10 лет опыта и глубокой экспертизы в специфических фреймворках (FAIR, MITRE ATT&CK), а также необходимостью совмещать технические навыки с бизнес-коммуникацией на уровне руководства.

Анализ зарплаты

Медиана195 000 $
Рынок160 000 $ – 240 000 $
Оценка ИИ

Предложенный диапазон ($164k - $235k) полностью соответствует и даже несколько превышает рыночные стандарты для Senior/Principal GRC ролей в Сан-Хосе, где медиана составляет около $190k-200k.

Сопроводительное письмо

I am writing to express my strong interest in the Senior GRC Manager position at Zscaler. With over a decade of experience in cybersecurity risk management and a deep expertise in the FAIR framework, I have consistently demonstrated the ability to translate complex technical threats into quantifiable business risks. My background in leveraging the MITRE ATT&CK framework to drive remediation strategies aligns perfectly with Zscaler’s mission to stay ahead of evolving threats in the AI age.

Throughout my career, I have excelled in building dynamic risk registers and managing policy exception processes in high-growth technology environments. I am particularly drawn to Zscaler’s 'impact over activity' philosophy and your commitment to transparency and constructive debate. I am confident that my technical leadership and proactive approach to risk governance will make a significant contribution to the Security GRC department and the overall resilience of your global infrastructure.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в zscaler уже сейчас

Присоединяйтесь к лидеру в области Zero Trust и помогите Zscaler защитить будущее цифровой трансформации!

Описание вакансии

About Zscaler

Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

Role

We are looking for a Cybersecurity Risk Management Principal to join our team. This is a hybrid role, going in to the San Jose, CA office 3 days a week.  You'll be reporting to the Sr. Director, Enterprise Risk Management within the Security GRC department. You will serve as a technical leader and subject matter expert, conducting sophisticated risk assessments and maintaining the strategic risk register to protect our global infrastructure. You'll bridge the gap between deep technical adversary tactics and high-level business impact to drive remediation across the enterprise.

What you’ll do (Role Expectations)

  • Lead comprehensive cyber risk assessments using qualitative and quantitative methods, such as FAIR, to identify and articulate threats to business stakeholders
  • Build and maintain a dynamic cyber risk register, ensuring prioritized risks and mitigation strategies are tracked and socialized with executive leadership
  • Run the day-to-day operations for Security Policy Exceptions and Risk Acceptance processes to ensure compliance and balanced risk-taking
  • Partner with Internal Audit, Compliance, and Security teams to embed risk management frameworks deeply into the enterprise risk lifecycle
  • Apply the MITRE ATT&CK framework to analyze adversary techniques and translate that intelligence into actionable enhancements for the organization’s security posture

Who You Are (Success Profile)

  • You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
  • You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
  • You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
  • You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
  • You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.

What We’re Looking for (Minimum Qualifications)

  • Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field
  • 10+ years of experience in cybersecurity risk management with a focus on risk assessments and threat modeling
  • Proficiency in the FAIR framework for risk quantification and the MITRE ATT&CK framework
  • Expert-level communication skills with the ability to translate complex technical risks into clear, actionable insights for business audiences
  • A results-driven approach to security risk management with a proven track record of solving complex security challenges

What Will Make You Stand Out (Preferred Qualifications)

  • Advanced certifications such as CISA, CISSP, CISM, CRISC, or FAIR
  • A Master’s degree in a technical or business-aligned field
  • Prior experience leading a Compliance or Cyber Risk management function within the technology industry

#LI-BH1 #LI-Hybrid

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range

$164,500—$235,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegallink.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Cybersecurity
  • Risk Management
  • CISA
  • CISSP
  • CISM
  • NIST
  • Compliance
  • Internal Audit
  • MITRE ATT&CK
  • GRC
  • CRISC
  • FAIR

Возможные вопросы на собеседовании

Проверка практического опыта использования ключевого для вакансии метода количественной оценки рисков.

Расскажите о самом сложном сценарии, который вы анализировали с помощью FAIR. Как вы определяли переменные и как результаты повлияли на бизнес-решение?

Вакансия требует умения связывать тактику злоумышленников с бизнес-рисками.

Как вы используете MITRE ATT&CK для приоритизации рисков в реестре и обоснования инвестиций в безопасность перед руководством?

Роль предполагает управление исключениями из политик безопасности.

Опишите ситуацию, когда бизнес-подразделение настаивало на исключении из политики безопасности, которое вы считали критическим. Как вы разрешили этот конфликт?

Zscaler ценит культуру 'владения' (ownership) и решения проблем.

Приведите пример, когда вы выявили пробел в процессах GRC и самостоятельно внедрили решение. С какими трудностями вы столкнулись?

Проверка способности работать в условиях неопределенности, указанной в профиле успеха.

Как вы подходите к оценке рисков для новых, быстро внедряемых технологий, таких как генеративный ИИ, где стандарты еще не полностью сформированы?

Похожие вакансии

SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
MTS Web Services
250 000 ₽ – 300 000 ₽

Старший эксперт SIEM

SeniorВ офисеРоссия
SIEM · SoC · Linux · Windows · macOS · CCNA · LPIC-1 · Cybersecurity · Incident Response · Network Security
+10 навыков
Инфосистемы Джет
Не указана

Старший инженер внедрения SIEM

SeniorВ офисеРоссия
SIEM · SOAR · SGRC · ArcSight · MaxPatrol SIEM · FortiSIEM · QRadar · Splunk · Linux · Windows Server · Information Security
+11 навыков
HaaS Platform
от 400 000 ₽

Pentester (Offensive Security)

SeniorУдалённоРоссия
Pentesting · Linux · Python · Bash · Burp Suite · NMAP · OWASP Top 10 · Network Security · Red Team · Vulnerability Assessment · Go · JavaScript · C++
+13 навыков
СберАвто
200 000 ₽ – 350 000 ₽

Специалист по информационной безопасности

SeniorУдалённоРоссия
Fortinet · Palo Alto Networks · Check Point · ELK stack · Splunk · Cisco Prime · MaxPatrol · ArcSight · SolarWinds · VPN · PKI · OSPF · EIGRP · BGP · Kaspersky Security Center · Cortex XDR · Solar Dozor · Ansible · Terraform · Vulnerability Management · Patch Management
+21 навыков
СберАвто
Не указана

Application security specialist

SeniorУдалённоРоссия
SAST · DAST · IAST · RASP · SCA · WAF · SSDLC · DevSecOps · OWASP · Linux · Python · Go · Threat Modeling
+13 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

zscaler
Страна
США
Зарплата
164 500 $ – 235 000 $