安全合规架构师
Security Compliance Architect
Zscaler(NASDAQ: ZS)加速数字化转型,使客户能够更加敏捷、高效、有韧性且安全。Zscaler Zero Trust Exchange™ 平台通过在任何位置安全连接用户、设备和应用程序,保护数千家客户免受网络攻击和数据丢失。该基于 SASE 的 Zero Trust Exchange 分布在全球 160 多个公共交换点以及边缘的数千个私有交换点,是全球最大的在线云安全平台。
我们相信未来的工作是“人类 + AI”,正在构建一个以 AI 为核心的企业,通过机器智能放大人类潜能,解决世界上最困难的安全挑战。我们以深入的客户需求为导向,致力于使命、成果以及彼此之间。我们通过三种核心行为将这些承诺付诸实践:以结果和影响建立信任、协作与责任,以及具有持续反馈的挑战文化。准备好在引领 AI 时代安全变革的公司中产生影响吗?加入我们吧,Zscaler。
职位
我们正在寻找一名安全合规架构师加入我们的团队。该职位优先考虑圣何塞,加利福尼亚州;远程候选人也将被考虑,该职位向暴露管理与安全运营部门的技术风险与合规总监汇报。你将塑造并扩展在高度监管的云环境中的安全合规性,将复杂的法规要求转化为实际的技术和操作解决方案。通过与跨职能团队紧密合作,你将支持授权工作,加强控制成熟度,并建立可扩展的合规实践,以促进业务增长。
你将做什么(职位期望)
- 领导符合 FedRAMP 和 DoD IL5 要求的云环境的安全合规架构的设计和实施
- 解释并实现来自 NIST SP 800-53、FedRAMP 和 DoD 云计算 SRG 等框架的控制要求
- 与工程和基础设施团队合作,构建符合规范、可扩展且安全的解决方案
- 推动审计准备,并作为合规架构专家为评估人员、审计员、客户和内部利益相关者提供支持
- 进行差距分析,识别控制缺陷,并与跨职能团队合作设计和实施合规操作的自动化解决方案
你是谁(成功画像)
- 你在模糊环境中茁壮成长。你
查看英文原文
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.
Role
We are looking for a Security Compliance Architect to join our team. This is a San Jose, CA preferred; remote candidates will be considered for the role, which is reporting to the Director, Technology Risk & Compliance in the Exposure Management & Security Operations department. You will shape and scale security compliance across highly regulated cloud environments, translating complex regulatory requirements into practical technical and operational solutions. By working closely with cross-functional teams, you will support authorization efforts, strengthen control maturity, and build scalable compliance practices that enable business growth.
What you’ll do (Role Expectations)
- Lead the design and implementation of security compliance architecture for cloud environments subject to FedRAMP and DoD IL5 requirements
- Interpret and operationalize control requirements from frameworks such as NIST SP 800-53, FedRAMP, and the DoD Cloud Computing SRG
- Partner with engineering and infrastructure teams to build compliant, scalable, and secure solutions
- Drive audit readiness and serve as a compliance architect SME for assessors, auditors, customers, and internal stakeholders
- Conduct gap assessments, identify control deficiencies, and partner with cross-functional teams to design and implement automation solutions for compliance operations
Who You Are (Success Profile)
- You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
- You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
- You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
- You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
- You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We’re Looking for (Minimum Qualifications)
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
- 8+ years of experience in security compliance, security architecture, GRC, cloud security, or related fields
- Demonstrated experience with FedRAMP compliance programs, authorization support, and DoD IL5 requirements
- Deep familiarity with NIST SP 800-53 and applying security controls in cloud environments such as AWS, Azure, and/or Google Cloud
- Strong documentation, program management, and cross-functional collaboration skills with experience automating compliance activities
What Will Make You Stand Out (Preferred Qualifications)
- Experience designing and deploying AI-forward automated solutions for control monitoring, evidence gathering, and compliance workflow optimization within regulated cloud frameworks
- Experience with privacy, data protection, or privacy-by-design programs
- Experience with additional frameworks such as CMMC, ISO 27001, SOC 2, FIPS 140-2/140-3, or StateRAMP
#LI-Remote #LI-JG1
Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.
The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.
Base Pay Range
$143,500—$205,000 USD
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Learn more about Zscaler's hybrid working model and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.