About the job
About Zscaler
Zscaler stands as a trailblazer and a global authority in zero trust cybersecurity. Major corporations, critical infrastructure entities, and government bodies across the globe depend on Zscaler to safeguard users, branches, applications, data, and devices while propelling digital transformation efforts. With over 160 data centers worldwide, the Zscaler Zero Trust Exchange platform, powered by advanced AI, counters billions of cyber threats and policy breaches daily, enhancing productivity for modern enterprises by minimizing costs and complexity.
At Zscaler, the impact of your role supersedes titles, and trust is cultivated through tangible results. We champion transparency and appreciate constructive, honest discussions, our focus is on rapidly deriving the best ideas. We foster high-performing teams capable of making significant impacts swiftly and efficiently. To achieve this, we are nurturing a culture centered on customer obsession, collaboration, ownership, and accountability.
We uphold an “AI Forward, People First” philosophy to fuel acceleration and innovation, empowering our employees to realize their full potential. If you are motivated by purpose, thrive in solving intricate challenges, and wish to make a positive global impact, we welcome you to join Zscaler and help shape the future of cybersecurity.
Role
We are in search of a Cybersecurity Risk Management Principal to become part of our team. This hybrid role requires in-person presence in the San Jose, CA office three days a week. You will report directly to the Sr. Director of Enterprise Risk Management within the Security GRC department. As a technical leader and subject matter expert, you will conduct advanced risk assessments and uphold the strategic risk register to safeguard our global infrastructure. You will connect the dots between intricate technical adversary tactics and overarching business impacts to facilitate remediation across the organization.
What you’ll do (Role Expectations)
Lead thorough cyber risk evaluations using both qualitative and quantitative approaches, such as FAIR, to pinpoint and communicate threats to business stakeholders.
Develop and sustain a dynamic cyber risk register, ensuring prioritized risks and mitigation strategies are monitored and communicated to executive leadership.
Oversee daily operations for Security Policy Exceptions and Risk Acceptance processes to guarantee compliance while balancing risk-taking.
Collaborate with Internal Audit, ...
