4 days ago

Senior Governance, Risk & Compliance Specialist

Zscaler

On Site
Full Time
$145,000
San Jose, CA

Job Overview

Job TitleSenior Governance, Risk & Compliance Specialist
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$145,000
LocationSan Jose, CA

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Zscaler

Zscaler is a pioneer and global leader in zero trust security. The world’s largest businesses, critical infrastructure organizations, and government agencies rely on Zscaler to secure users, branches, applications, data & devices, and to accelerate digital transformation initiatives. Distributed across more than 160 data centers globally, the Zscaler Zero Trust Exchange platform combined with advanced AI combats billions of cyber threats and policy violations every day and unlocks productivity gains for modern enterprises by reducing costs and complexity.

Here, impact in your role matters more than title and trust is built on results. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership and accountability.

We champion an “AI Forward, People First” philosophy to help us accelerate and innovate, empowering our people to embrace their potential. If you’re driven by purpose, thrive on solving complex challenges and want to make a positive difference on a global scale, we invite you to bring your talents to Zscaler to help shape the future of cybersecurity.

Role Overview: Senior Governance, Risk & Compliance Specialist

We are looking for a Senior Governance, Risk & Compliance Specialist to join our Technology Risk & Compliance team. This is a remote U.S. role with a preference for a hybrid schedule near San Jose, CA, reporting to the Director Technology Risk and Compliance. You will support the implementation, maintenance, and enhancement of integrated GRC frameworks for FedRAMP and DoD authorizations. Your work will directly influence business strategy by ensuring compliance activities are integrated into broader business processes while supporting our mission as a global cloud security leader.

What You’ll Do (Role Expectations)

  • Implement, maintain and enhance integrated GRC frameworks for FedRAMP and DoD authorizations, with a focus on continuous monitoring activities
  • Play a key role in the execution of ongoing significant change and annual assessment activities
  • Collaborate and communicate GRC requirements to a wide range of internal and external stakeholders
  • Own and maintain the Plan of Action and Milestone deliverable, keeping relevant stakeholders informed on risks to the system
  • Monitor relevant laws, regulations, and industry standards to understand impacts on authorized services and adjust processes or technical controls as needed

Who You Are (Success Profile)

  • You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
  • You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
  • You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
  • You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
  • You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.

What We’re Looking For (Minimum Qualifications)

  • 5+ years of experience supporting FedRAMP and DoD compliance programs
  • U.S. citizenship is required; an active U.S. Secret or Top Secret security clearance is preferred
  • Experience with processes and tools required for automating continuous monitoring activities
  • Expertise in assessing SaaS, PaaS, and IaaS cloud offerings with a clear understanding of shared control responsibilities
  • Experience assessing containerized applications in Kubernetes and understanding security best practices for AI/ML technologies

What Will Make You Stand Out (Preferred Qualifications)

  • Exceptional verbal and written communication skills tailored for both technical and non-technical audiences
  • Demonstrated strength in prioritizing tasks within a fast-paced, evolving environment
  • Bachelor's degree in Information Technology or a relevant field and certifications such as CISSP

Compensation & Benefits

Zscaler’s salary ranges are benchmarked and are determined by role and level. The base salary range listed for this full-time position excludes commission/bonus/equity (if applicable) + benefits. The base pay range is $119,000 - $170,000 USD. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including various health plans, time off, parental leave, retirement options, education reimbursement, and in-office perks.

Key skills/competency

  • FedRAMP compliance
  • DoD authorization
  • Governance Risk & Compliance (GRC)
  • Continuous monitoring
  • Cloud security assessment
  • SaaS, PaaS, IaaS
  • Kubernetes security
  • AI/ML security best practices
  • Risk management
  • Regulatory compliance

Tags:

Governance, Risk, Compliance Specialist
FedRAMP
DoD
GRC
continuous monitoring
risk management
compliance
stakeholder communication
regulatory monitoring
policy development
security frameworks
SaaS
PaaS
IaaS
Kubernetes
AI/ML security
cloud security
zero trust
security tools
cyber threats
data centers

Share Job:

How to Get Hired at Zscaler

  • Research Zscaler's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
  • Tailor your resume: Highlight extensive experience with FedRAMP, DoD compliance, GRC frameworks, and cloud security technologies.
  • Showcase ownership and problem-solving: Prepare specific examples demonstrating how you thrive in ambiguity and resolve complex technical challenges.
  • Emphasize collaboration and learning: Articulate your ability to work within high-trust teams, provide constructive feedback, and embrace continuous personal development.
  • Prepare for technical deep dives: Be ready to discuss your expertise in SaaS/PaaS/IaaS assessment, Kubernetes security, and AI/ML security best practices.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background