yandex
Z
zscaler
Страна
США
Зарплата
115 500 $ – 165 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
В офисеПолная занятость

Staff Information Security Engineer (Vulnerability Management)

Оценка ИИ

Привлекательная позиция в ведущей компании в сфере кибербезопасности с конкурентной зарплатой и серьезными социальными льготами. Работа над критически важными государственными проектами обеспечивает высокую стабильность и профессиональный престиж.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена требованием действующего допуска Top Secret (TS) и необходимостью работы в изолированных средах (SCIF/IL6). Роль требует глубоких знаний специфических протоколов передачи данных (однонаправленные диоды) и опыта работы с государственными стандартами США.

Анализ зарплаты

Медиана155 000 $
Рынок130 000 $ – 185 000 $
Оценка ИИ

Предложенный диапазон ($115k - $165k) соответствует рыночным стандартам для специалистов по информационной безопасности в Арлингтоне, однако для уровня Staff с допуском Top Secret верхняя граница может быть несколько консервативной. Специалисты с активным TS-допуском в этом регионе часто претендуют на премии за секретность.

Сопроводительное письмо

I am writing to express my strong interest in the Staff Information Security Engineer position at Zscaler. With over five years of experience in vulnerability management and a current Top Secret clearance, I am well-prepared to contribute to the security of the U.S. Federal IL6 environment. My background in automating scan orchestrations using Python and managing Tenable.sc in air-gapped environments aligns perfectly with the technical requirements of this role.

Throughout my career, I have focused on risk-based prioritization and the remediation lifecycle within highly regulated frameworks. I am particularly drawn to Zscaler’s commitment to 'impact over activity' and the challenge of maintaining a multitenant architecture within a SCIF. I am confident that my expertise in VM hardening and my proactive approach to solving complex security challenges will make me a valuable asset to your Product Security team.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в zscaler уже сейчас

Присоединяйтесь к Zscaler, чтобы защищать критически важные государственные системы в эпоху ИИ!

Описание вакансии

About Zscaler

Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

Role

We are looking for a Staff Information Security Engineer to join our Engineering team. This is a fully onsite role based in the Crystal City / Arlington, VA Area, reporting to the VP, Product Security. You will operate as a vulnerability management engineer inside the U.S. Federal IL6 (SCIF) environment. This role is critical to maintaining our multitenant architecture and global security footprint, ensuring we enable organizations worldwide to harness speed and agility while operating strictly within a U.S. SCIF and adhering to one-way diode transfer protocols.

What you’ll do (Role Expectations)

  • Design and execute authenticated and unauthenticated network and host scanning using IL6-approved tools like Tenable.sc or Nessus Manager within air-gapped environments
  • Build Python, Go, or PowerShell automations for scan orchestration, asset onboarding, policy tuning, and diode-ready reporting formats
  • Drive collaboration with IL6 service owners to eliminate exploitable risks and manage comprehensive patch and hardening campaigns
  • Produce weekly and monthly reporting aligned to IL6 program cadence and diode data transfer policies
  • Maintain essential documentation including runbooks, SOPs, exception governance, and change control processes within the SCIF environment

Who You Are (Success Profile)

  • You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
  • You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
  • You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
  • You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
  • You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.

What We’re Looking for (Minimum Qualifications)

U.S. citizenship and a current, active U.S. Top Secret (TS) clearance and 5+ years of experience in one or more of the following

  • Vulnerability Management
  • Experience with Tenable.sc/Nessus Manager or equivalents
  • Experience with CSPM concepts and/or Web Application Scanning (WAS) methodologies with solid understanding of risk-based prioritization (CVSS, EPSS), remediation lifecycle, and SLA governance
  • Scripting skills in Python, Go, or PowerShell for automation in disconnected environments

What Will Make You Stand Out (Preferred Qualifications)

  • DoD 8570/8140 IAT Level II certification such as Security+ CE, GSEC, SSCP, or CySA+
  • Understanding of cloud and container platforms adapted to classified environments including AWS C2S/SC2S constructs, ECS/Kubernetes, and VM hardening
  • Exposure to FedRAMP High/Moderate operations and ticketing management in isolated environments using Jira or ServiceNow

#LI-Onsite #LI-KM9

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range

$115,500—$165,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegallink.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • AWS
  • Python
  • Kubernetes
  • Vulnerability Management
  • Jira
  • Go
  • PowerShell
  • ServiceNow
  • Nessus
  • CSPM
  • CVSS
  • EPSS
  • Tenable.sc
  • Web Application Scanning

Возможные вопросы на собеседовании

Роль предполагает работу в изолированной среде IL6. Важно понимать, как кандидат справляется с техническими ограничениями таких систем.

Опишите ваш опыт управления уязвимостями в физически изолированных (air-gapped) средах. С какими основными трудностями вы сталкивались при обновлении сигнатур и передаче отчетов?

Вакансия требует навыков автоматизации на Python, Go или PowerShell.

Расскажите о конкретном инструменте или скрипте, который вы разработали для автоматизации процесса сканирования или обработки данных об уязвимостях. Какую проблему он решил?

Работа ведется в среде IL6 с использованием диодов передачи данных.

Каков ваш опыт работы с протоколами однонаправленной передачи данных (data diodes)? Как вы обеспечиваете целостность и конфиденциальность данных при их передаче из защищенного контура?

Позиция уровня Staff требует умения приоритизировать задачи.

Как вы используете метрики CVSS и EPSS для приоритизации устранения уязвимостей в условиях ограниченных ресурсов и строгих SLA?

Упоминание FedRAMP и стандартов DoD указывает на необходимость соблюдения комплаенса.

Каков ваш опыт подготовки отчетности для соответствия требованиям FedRAMP High или DoD SRG? Как вы взаимодействуете с владельцами систем для ускорения процесса патчинга?

Похожие вакансии

J
JETLYN
210 000 ₽ – 260 000 ₽

Специалист по защите информации (Mobile Security Engineer)

SeniorУдалённоРоссия
iOS · Cryptography · Jailbreak · HTTPS · REST API · gRPC · TCP · UDP · HTTP · Protobuf · JSON · Avro · MessagePack · Reverse Engineering
+14 навыков
AG
Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
S
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
И
ИНФОБЕЗ
100 000 ₽ – 500 000 ₽

Специалист по информационной безопасности (Пентестер)

УдалённоРоссия
Kali Linux · Metasploit · NMAP · Burp Suite · sqlmap · OWASP Top 10 · C++ · Python · JavaScript · PHP · MSSQL · MySQL · RCE
+13 навыков
OZ
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
Не указана

Senior AppSecOps Engineer

SeniorУдалённоБеларусь
AppSec · C++ · Go · Java · SAST · SCA · Svace · CodeScoring · Jira · GitLab · GCC · Make · Linux Kernel
+13 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

Z
zscaler
Страна
США
Зарплата
115 500 $ – 165 000 $