- Страна
- США
- Зарплата
- 119 000 $ – 170 000 $
Откликайтесь
на вакансии с ИИ

Senior Governance, Risk & Compliance Specialist
Zscaler — топовая компания в сфере кибербезопасности с сильной культурой и прозрачной системой вознаграждения. Позиция предлагает отличный социальный пакет и возможность работать с передовыми технологиями (AI, Zero Trust).
Сложность вакансии
Высокая сложность обусловлена строгими требованиями к гражданству США и наличию допуска к секретной информации, а также необходимостью глубокой экспертизы в специфических стандартах FedRAMP и DoD.
Анализ зарплаты
Предложенный диапазон $119k–$170k полностью соответствует рыночным стандартам для Senior GRC ролей в США, особенно с учетом специфики FedRAMP, которая ценится выше стандартного комплаенса. Верхняя граница диапазона конкурентоспособна даже для дорогого рынка Сан-Хосе.
Сопроводительное письмо
I am writing to express my strong interest in the Senior Governance, Risk & Compliance Specialist position at Zscaler. With over five years of experience specializing in FedRAMP and DoD authorizations, I have a proven track record of managing complex compliance frameworks and continuous monitoring activities for large-scale SaaS and IaaS environments. My background in assessing containerized applications and my familiarity with security best practices for AI/ML technologies align perfectly with Zscaler's mission to secure the AI age.
Throughout my career, I have excelled in navigating the ambiguity of evolving regulatory landscapes, transforming complex requirements into actionable technical controls. I am particularly drawn to Zscaler’s 'impact over activity' philosophy and your commitment to transparency. My experience with Plan of Action and Milestones (POA&M) management and collaborating with diverse stakeholders ensures that I can contribute to the Technology Risk & Compliance team immediately. I am eager to bring my expertise in cloud security and my proactive problem-solving approach to help Zscaler maintain its position as a global leader in cybersecurity.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в zscaler уже сейчас
Присоединяйтесь к лидеру в сфере Zero Trust безопасности и помогите защитить государственные облачные сервисы нового поколения!
Описание вакансии
About Zscaler
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.
We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.
Role
We are looking for a Senior Governance, Risk & Compliance Specialist to join our Technology Risk & Compliance team. This is a remote U.S. role with a preference for a hybrid schedule near San Jose, CA, reporting to the Director Technology Risk and Compliance. You will support the implementation, maintenance, and enhancement of integrated GRC frameworks for FedRAMP and DoD authorizations. Your work will directly influence business strategy by ensuring compliance activities are integrated into broader business processes while supporting our mission as a global cloud security leader.
What you’ll do (Role Expectations)
- Implement, maintain and enhance integrated GRC frameworks for FedRAMP and DoD authorizations, with a focus on continuous monitoring activities
- Play a key role in the execution of ongoing significant change and annual assessment activities
- Collaborate and communicate GRC requirements to a wide range of internal and external stakeholders
- Own and maintain the Plan of Action and Milestone deliverable, keeping relevant stakeholders informed on risks to the system
- Monitor relevant laws, regulations, and industry standards to understand impacts on authorized services and adjust processes or technical controls as needed
Who You Are (Success Profile)
- You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
- You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
- You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
- You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
- You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We’re Looking for (Minimum Qualifications)
- 5+ years of experience supporting FedRAMP and DoD compliance programs
- U.S. citizenship is required; an active U.S. Secret or Top Secret security clearance is preferred
- Experience with processes and tools required for automating continuous monitoring activities
- Expertise in assessing SaaS, PaaS, and IaaS cloud offerings with a clear understanding of shared control responsibilities
- Experience assessing containerized applications in Kubernetes and understanding security best practices for AI/ML technologies
What Will Make You Stand Out (Preferred Qualifications)
- Exceptional verbal and written communication skills tailored for both technical and non-technical audiences
- Demonstrated strength in prioritizing tasks within a fast-paced, evolving environment
- Bachelor's degree in Information Technology or a relevant field and certifications such as CISSP
#LI-hybrid #LI-BH1
Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.
The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.
Base Pay Range
$119,000—$170,000 USD
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegallink.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Risk Management
- SaaS
- FedRAMP
- Kubernetes
- CISSP
- Cloud Security
- NIST 800-53
- GRC
- IaaS
- PaaS
- DoD SRG
Возможные вопросы на собеседовании
Кандидат должен понимать жизненный цикл авторизации и специфику работы с государственными органами США.
Опишите ваш опыт управления процессом ежегодной оценки (Annual Assessment) для систем с авторизацией FedRAMP High или Moderate.
Роль требует автоматизации процессов мониторинга для повышения эффективности.
Какие инструменты и методы вы использовали для автоматизации непрерывного мониторинга (Continuous Monitoring) в облачных средах?
Вакансия упоминает работу с Kubernetes и AI.
С какими основными рисками безопасности вы сталкивались при оценке контейнеризированных приложений в среде Kubernetes?
Управление рисками — ключевая часть роли.
Как вы приоритизируете пункты в POA&M (Plan of Action and Milestones), когда ресурсы команды ограничены, а сроки поджимают?
Проверка соответствия ценностям компании (ownership, collaboration).
Расскажите о случае, когда вам пришлось внедрять изменения в процессы GRC, которые встретили сопротивление со стороны технических команд. Как вы добились сотрудничества?
Похожие вакансии
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Старший эксперт SIEM
Старший инженер внедрения SIEM
Pentester (Offensive Security)
Специалист по информационной безопасности
Application security specialist
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США
- Зарплата
- 119 000 $ – 170 000 $