All roles

Senior Governance, Risk & Compliance Manager - NIST, FAIR

Remote · USA Full-time New today

About the position Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability. We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity. Role We are looking for a Cybersecurity Risk Management Principal to join our team. This is a hybrid role, going in to the San Jose, CA office 3 days a week. You'll be reporting to the Sr. Director, Enterprise Risk Management within the Security GRC department. You will serve as a technical leader and subject matter expert, conducting sophisticated risk assessments and maintaining the strategic risk register to protect our global infrastructure. You'll bridge the gap between deep technical adversary tactics and high-level business impact to drive remediation across the enterprise.

Responsibilities

  • Lead comprehensive cyber risk assessments using qualitative and quantitative methods, such as FAIR, to identify and articulate threats to business stakeholders
  • Build and maintain a dynamic cyber risk register, ensuring prioritized risks and mitigation strategies are tracked and socialized with executive leadership
  • Run the day-to-day operations for Security Policy Exceptions and Risk Acceptance processes to ensure compliance and balanced risk-taking
  • Partner with Internal Audit, Compliance, and Security teams to embed risk management frameworks deeply into the enterprise risk lifecycle
  • Apply the MITRE ATT&CK framework to analyze adversary techniques and translate that intelligence into actionable enhancements for the organization’s security posture

Requirements

  • Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field
  • 10+ years of experience in cybersecurity risk management with a focus on risk assessments and threat modeling
  • Proficiency in the FAIR framework for risk quantification and the MITRE ATT&CK framework
  • Expert-level communication skills with the ability to translate complex technical risks into clear, actionable insights for business audiences
  • A results-driven approach to security risk management with a proven track record of solving complex security challenges

Nice-to-haves

  • Advanced certifications such as CISA, CISSP, CISM, CRISC, or FAIR
  • A Master’s degree in a technical or business-aligned field
  • Prior experience leading a Compliance or Cyber Risk management function within the technology industry

Benefits

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Apply tot his job Apply To this Job

Related roles

Sales Development Representative

Remote · USA Full-time

Business Developer Specialist (PA/DE)

Remote · USA Full-time

Customer Service HRS Specialist - Bilingual-1

Remote · USA Full-time

Lead Revenue Cycle Supervisor Associate - Epic AR

Remote · USA Full-time

Data Operations Engineer Associate

Remote · USA Full-time

Senior Consultant - Epic Hospital Billing Consultant

Remote · USA Full-time

Mobile Developer (Sweat equity, unpaid)

Remote · USA Full-time

UX/Product Lead (Core Team, Equity-Based, Remote Europe)

Remote · USA Full-time

Healthcare Change Management Sr. Consultant--WEST COAST

Remote · USA Full-time

FM Senior Consultant - Audit Support

Remote · USA Full-time

Risk Analyst - 2026 Summer Internship Program – Amazon Store

Remote · USA Full-time

YouTube Moderator Jobs (Remote) $75000/Yearly

Remote · USA Full-time

Urgently Require Studio City RC - Recreation Instructor (Dance) in Studio City, CA

Remote · USA Full-time

Application Security Engineer II (Remote)

Remote · USA Full-time

Seeking Virtual School Assignments As An SLP, Then Read Below For Upcoming SY

Remote · USA Full-time

Experienced Associate Customer Success Manager – Bilingual Support for arenaflex's Global Client Base

Remote · USA Full-time

RESUMES MODIFICATION SERVICES - Gandhipuram ID-1180 – Amazon Store

Remote · USA Full-time

Entry-Level Remote Customer Service Chat Representative – No Experience Required – Join arenaflex for a Home‑Based Support Career

Remote · USA Full-time

[Remote/WFM] Medicaid Network Provider Relations Manager

Remote · USA Full-time

Experienced Full-Time Customer Service Representative – Delivering Exceptional Customer Experiences at arenaflex

Remote · USA Full-time