Cookie Consent by FreePrivacyPolicy.com
+49 69 959 0919 12

Senior Governance Risk Compliance Manager

  • Framework Ventures




About Zscaler Zscaler is a pioneer and global leader in zero trust security. The world’s largest businesses, critical infrastructure organizations, and government agencies rely on Zscaler to secure users, branches, applications, data & devices, and to accelerate digital transformation initiatives. Distributed across more than 160 data centers globally, the Zscaler Zero Trust Exchange platform combined with advanced AI combats billions of cyber threats and policy violations every day and unlocks productivity gains for modern enterprises by reducing costs and complexity. Here, impact in your role matters more than title and trust is built on results. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership and accountability. We champion an “AI Forward, People First” philosophy to help us accelerate and innovate, empowering our people to embrace their potential. If you’re driven by purpose, thrive on solving complex challenges and want to make a positive difference on a global scale, we invite you to bring your talents to Zscaler to help shape the future of cybersecurity. Role We are looking for a Cybersecurity Risk Management Principal to join our team. This is a hybrid role, going in the San Jose, CA office 3 days a week. You will report to the Sr. Director, Enterprise Risk Management within the Security GRC department. As a technical leader and subject matter expert, you will conduct sophisticated risk assessments and maintain the strategic risk register to protect our global infrastructure. You will bridge the gap between deep technical adversary tactics and high‑level business impact to drive remediation across the enterprise. Role Expectations Lead comprehensive cyber risk assessments using qualitative and quantitative methods, such as FAIR, to identify and articulate threats to business stakeholders. Build and maintain a dynamic cyber risk register, ensuring prioritized risks and mitigation strategies are tracked and socialized with executive leadership. Run the day‑to‑day operations for Security Policy Exceptions and Risk Acceptance processes to ensure compliance and balanced risk‑taking. Partner with Internal Audit, Compliance, and Security teams to embed risk management frameworks deeply into the enterprise risk lifecycle. Apply the MITRE ATT&CK framework to analyze adversary techniques and translate that intelligence into actionable enhancements for the organization’s security posture. Success Profile You thrive in ambiguity and build the path as you walk it. You embrace a dynamic environment, seeing ambiguity as raw material to build something meaningful. You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging a dynamic range: the ability to navigate seamlessly between high‑level strategy and hands‑on execution. You are a problem‑solver. You run towards challenges because you are laser‑focused on finding the solution, knowing that solving the hard problems delivers the biggest impact. You are a high‑trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust. You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose. Minimum Qualifications Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field. 10+ years of experience in cybersecurity risk management with a focus on risk assessments and threat modeling. Proficiency in the FAIR framework for risk quantification and the MITRE ATT&CK framework. Expert‑level communication skills with the ability to translate complex technical risks into clear, actionable insights for business audiences. A results‑driven approach to security risk management with a proven track record of solving complex security challenges. Preferred Qualifications Advanced certifications such as CISA, CISSP, CISM, CRISC, or FAIR. A Master’s degree in a technical or business‑aligned field. Prior experience leading a Compliance or Cyber Risk management function within the technology industry. Salary Range Salary ranges are benchmarked and are determined by role and level. The base pay range for this full‑time position excludes commission/bonus/equity (if applicable) + benefits. Base Pay Range: $147,000 – $210,000 USD. Benefits Various health plans Time off plans for vacation and sick time Parental leave options Retirement options Education reimbursement In‑office perks, and more! Employment Practices Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status or any other characteristic protected by federal, state, or local laws. Pay Transparency Zscaler complies with all applicable federal, state, and local pay transparency rules. #J-18808-Ljbffr

Job Location
Stelle mit anderen teilen: