Principal Vulnerability Management Engineer

Zscaler · Bengaluru · 12+ yrs experience · Posted 2026-07-18

Tech stack: AWS, Azure, GCP, Go, Kubernetes, Python

Apply on the company site · Get a referral for this role

Zscaler salary & ratings · Zscaler interview process · More live openings

About the role

Responsibilities:
- We are looking for a Principal Engineer, Vulnerability & Exposure Management to join our team.
- This is a hybrid role, reporting to the Senior Manager, Information Security Engineering in the Product Security department.
- This critical role helps modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets.
- As an individual contributor, you will operate both strategically and technically to define the operating model, build scalable workflows, influence engineering teams, and dive deep into findings, coverage gaps, scanner limitations, and remediation paths with a strong builder mindset.
- Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability
- Define advanced, risk-based prioritization models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams
- Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation
- Drive external attack surface management (EASM) to map internet-facing assets while aggressively identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions
- Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics
Qualifications:
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
- 12+ years of experience in security engineering or product security, including 7+ years of hands-on experience driving and scaling vulnerability and exposure management programs within complex environments
- Deep understanding of scanner mechanics (including authenticated/unauthenticated scanning, coverage gaps, and asset correlation) paired with proficiency in platforms like Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite
- Practical experience implementing risk-based frameworks that leverage modern exploitability signals, threat intelligence, KEV, EPSS, and asset criticality to prioritize threats effectively
- Hands-on automation capabilities using Python, PowerShell, APIs, data pipelines, or workflow orchestration platforms to eliminate manual operational overhead, combined with a proven ability to partner collaboratively with engineering teams to drive remediation and translate complex technical data into clear insights for senior leadership
- Experience leveraging AI/ML technologies and advanced orchestration platforms to design intelligent, self-service triage, automated remediation routing, and predictive exposure analysis workflows
- Extensive experience securing multi-cloud environments (AWS, Azure, GCP) and containerized architecture (Kubernetes), including image scanning, runtime security, and embedding security guardrails into CI/CD and DevSecOps pipelines
- Proven track record in advanced vulnerability prioritization strategies (EASM, CTEM, and attack-path analysis) paired with the ability to integrate vulnerability data seamlessly into CMDBs, asset inventories, and ownership tracking systems

Qualifications

- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
- 12+ years of experience in security engineering or product security, including 7+ years of hands-on experience
- driving and scaling vulnerability and exposure management programs within complex environments
- Deep understanding of scanner mechanics (including authenticated/unauthenticated scanning, coverage gaps, and asset correlation) paired with proficiency in platforms like Tenable, Qualys, Wiz, CrowdStrike, or Burp Suite
- Practical experience implementing risk-based frameworks that leverage modern exploitability signals, threat intelligence, KEV, EPSS, and asset criticality to prioritize threats effectively
- Hands-on automation capabilities using Python, PowerShell, APIs, data pipelines, or workflow orchestration platforms to eliminate manual operational overhead, combined with a proven ability to partner collaboratively with engineering teams to drive remediation and translate complex technical data into clear insights for senior leadership
- Experience leveraging AI/ML technologies and advanced orchestration platforms to design intelligent, self-service triage, automated remediation routing, and predictive exposure analysis workflows
- Extensive experience securing multi-cloud environments (AWS, Azure, GCP) and containerized architecture (Kubernetes), including image scanning, runtime security, and embedding security guardrails into CI/CD and DevSecOps pipelines
- Proven track record in advanced vulnerability prioritization strategies (EASM, CTEM, and attack-path analysis) paired with the ability to integrate vulnerability data seamlessly into CMDBs, asset inventories, and ownership tracking systems

Responsibilities

- We are looking for a Principal Engineer, Vulnerability & Exposure Management to join our team.
- This is a hybrid role, reporting to the Senior Manager, Information Security Engineering in the Product Security department.
- This critical role helps modernize how we discover, prioritize, and reduce security exposure across infrastructure, cloud, applications, APIs, endpoints, containers, and internet-facing assets.
- As an individual contributor, you will operate both strategically and technically to define the operating model, build scalable workflows, influence engineering teams, and dive deep into findings, coverage gaps, scanner limitations, and remediation paths with a strong builder mindset.
- Lead comprehensive vulnerability and exposure management initiatives across infrastructure, cloud, APIs, and containers, evolving the function from a traditional reporting role into a high-leverage product security engineering capability
- Define advanced, risk-based prioritization models that go beyond standard CVSS by integrating threat intelligence and business context, drastically reducing noise and duplicate findings for engineering teams
- Design and deploy automated data pipelines, scripting, and workflow orchestration to streamline the entire lifecycle of asset discovery, authenticated scanning, triage, routing, and validation
- Drive external attack surface management (EASM) to map internet-facing assets while aggressively identifying program gaps, including unauthenticated scans, stale asset ownership, and untracked exceptions
- Collaborate directly with DevOps, IT, and Engineering teams to translate complex vulnerability data into practical technical guidance, durable infrastructure improvements, and leadership-ready performance metrics

More openings at Zscaler