- 
        Staff Information Security Engineer (Vulnerability…
- Zscaler (Washington, DC)
- 
             About **Zscaler** Serving thousands of enterprise customers around the world including 45% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform, which is found in our SASE and SSE offerings, protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. Our Engineering team built the world’s largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy. We are looking for a Staff Information Security Engineer who will operate as a vulnerability management engineer inside the U.S. Federal IL6 (SCIF) environment. **This fully onsite role is based in, or near, the Washington, D.C. Metro Area and operates strictly within a U.S. SCIF, with no access to external networks or corporate systems, and adhering to one-way diode transfer protocols.** Reporting to the Senior Manager of Information Security Engineering, you will be responsible for: + Designing and running authenticated/unauthenticated network and host scanning using IL6-approved tools in air-gapped environments (e.g., Tenable.sc / Nessus Manager or similar) + Building Python/Go/PowerShell automations for scan orchestration, asset onboarding, policy tuning, and diode-ready reporting formats + Driving collaboration with IL6 service owners to eliminate exploitable risks and manage patch/hardening campaigns + Producing weekly and monthly reporting aligned to IL6 program cadence and diode data transfer policies + Maintaining documentation, including runbooks, SOPs, exception governance, and change control processes within the SCIF Minimum Qualifications + U.S. citizenship and active U.S. Top Secret (TS) clearance (must be maintained) + 5+ years in Vulnerability Management, or Security Engineering within restricted/SCIF environments, including air-gapped scanning (Tenable.sc/Nessus Manager or equivalents) and offline plugin lifecycle + Experience with CSPM concepts and Web Application Scanning (WAS) methodologies, plus strong scripting skills in Python, Go, or PowerShell for automation in disconnected environments + Solid understanding of risk-based prioritization (CVSS, EPSS), remediation lifecycle, and SLA governance What Will Make You Stand Out (Preferred Qualifications) + DoD 8570/8140 IAT Level II certification (e.g., Security+ CE, GSEC, SSCP, CySA+) + Understanding of cloud and container platforms adapted to classified environments (e.g., AWS C2S/SC2S constructs, ECS/Kubernetes, VM hardening), and external attack surface concepts within constrained perimeters + Exposure to FedRAMP High/Moderate operations, including monthly monitoring programs (scanning, evaluation, patching, reporting) and familiarity with Jira/ServiceNow for ticketing and exception management in isolated environments \#LI-Onsite \#LI-KM9 Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training. The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits. Base Pay Range $115,500—$165,000 USD At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: + Various health plans + Time off plans for vacation and sick time + Parental leave options + Retirement options + Education reimbursement + In-office perks, and more! Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here (https://www.zscaler.com/careers) . By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines. Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. _See more information by clicking on the_ Know Your Rights: Workplace Discrimination is Illegal (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12ScreenRdr.pdf) _link._ Pay Transparency Zscaler complies with all applicable federal, state, and local pay transparency rules. Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support. 
 
 
- 
        
Recent Jobs
- 
                
                    Staff Information Security Engineer (Vulnerability Management)
                
                - Zscaler (Washington, DC)