Zscaler

Sr Staff, Security Third Party Risk Management

Costa Rica

Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Information Security, CybersecurityIndustries

Senior Staff, Cybersecurity Third Party Risk Management

About Zscaler

Serving thousands of enterprise customers around the world including 40% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world’s largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange™ platform, which is found in our SASE and SSE offerings, protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler. Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.

Position Overview

We’re looking for a Senior Staff, Cybersecurity Third Party Risk Management professional to join our growing cybersecurity team, operating remotely within Costa Rica. Reporting to the Director of Security Strategy, Transformation & Vendor Risk Management, you will be responsible for:

Responsibilities

  • Conducting comprehensive risk assessments of third-party vendors to evaluate their cybersecurity posture, data protection practices, and compliance with relevant regulations, including managing the vendor intake process, collecting all necessary information and reviewing required evidence.
  • Partnering with procurement, legal, compliance, IT, and other functions to ensure due diligence is performed on vendors and partners prior to contract signing.
  • Monitoring and assessing the security of third parties and supporting the response and remediation of cybersecurity incidents involving vendors, ensuring steps are taken to reduce exposure.
  • Evaluating and implementing improvements to the TPRM program, including policies, procedures, templates, questionnaires, technical security standards and AI governance; analyzing regulatory and standards changes impacting vendor due diligence requirements.
  • Generating security risk rating metrics and creating reports summarizing risk assessments, issues, and mitigation plans while escalating potential risks or non-responses.

Requirements (Minimum Qualifications)

  • Experience: Minimum 7+ years of experience in one or more of the following cybersecurity roles: risk management, vendor risk assessments, incident response, security operations, security engineering, or network security.
  • Security Best Practices: Understanding of a broad set of security best practices including application security, secure software development lifecycles, risk management, data protection, encryption, identity and access management, security governance, and network security.
  • Frameworks & Standards: Experience with common cybersecurity frameworks and standards such as NIST, ISO 27001, SOC2, and GDPR.
  • Collaboration: Experience in collaborating and communicating with stakeholders across all levels and teams in multiple geographies.
  • Problem-Solving: Strong problem-solving skills and ability to handle complex risk assessment, threat modeling scenarios, and remediation of vulnerabilities.

Preferred Qualifications

  • Familiarity with GRC platforms and tools for vendor risk management.

Employment Type:

Location Type:

Salary:

Skills

Cybersecurity
Third Party Risk Management
Risk Assessments
Security Strategy
Vendor Risk
Cybersecurity Governance

Zscaler

Cloud-based cybersecurity and secure gateway services

About Zscaler

Zscaler provides cloud-based information security services, focusing on internet, web, and cloud security. Its platform functions as a secure gateway that inspects all internet traffic between users and applications, ensuring that threats are identified and stopped before they can access a client's network. This service is offered through a subscription model, allowing large enterprises and government organizations to select the level of security that meets their needs. Zscaler differentiates itself from competitors by offering a strong partner program that enhances market reach and provides partners with training and resources. The company's goal is to support secure digital transformation for its clients by delivering reliable security solutions.

San Jose, CaliforniaHeadquarters
2008Year Founded
$148.8MTotal Funding
IPOCompany Stage
Enterprise Software, CybersecurityIndustries
5,001-10,000Employees

Benefits

Comprehensive health plans
Supportive parental & family leave
On-demand learning & development
Company-sponsored volunteering
Global tuition assistance program
Guilt-free paid time off

Risks

Emerging cybersecurity firms may erode Zscaler's market share.
Economic downturns could impact Zscaler's subscription-based revenue model.
The retirement of CFO Mr. Canessa may lead to financial instability.

Differentiation

Zscaler offers a 100% cloud-based security platform, eliminating on-premise hardware needs.
The company is a Gartner magic quadrant leader for secure web gateways.
Zscaler's platform inspects all internet traffic, ensuring threats are neutralized pre-network.

Upsides

Zscaler's FY/25 guidance was revised upward, indicating strong financial performance.
The partnership with Bharti Airtel enhances Zscaler's zero-trust architecture offerings.
Zscaler's hiring of government experts strengthens its position in the public sector.

Land your dream remote job 3x faster with AI