资深技术项目经理 - 合规架构
Staff Technical Program Manager - Compliance Architecture
Zscaler (NASDAQ: ZS) 加速数字化转型,使客户能够更加敏捷、高效、有韧性且安全。Zscaler Zero Trust Exchange™ 平台通过在任何位置安全连接用户、设备和应用程序,保护数千家客户免受网络攻击和数据丢失。该基于 SASE 的 Zero Trust Exchange 分布在全球 160 多个公共交换点以及边缘的数千个私有交换点,是全球最大的内联云安全平台。
我们相信未来的工作是“人类 + AI”,正在构建一个以 AI 为核心的企业,通过机器智能放大人类潜能,解决世界上最复杂的安全挑战。我们以深入的客户需求为导向,致力于使命、成果以及彼此之间。我们通过三种核心行为将这些承诺付诸实践:以结果和影响建立信任、拥有与协作,以及具有持续反馈的挑战文化。准备好在引领 AI 时代安全变革的公司中产生影响吗?加入我们,成为 Zscaler 的一员。
职位
我们正在寻找一位资深合规架构师加入我们的团队。该职位为远程(如不在加州圣何塞地区)或混合办公(位于加州圣何塞)形式,向暴露管理与安全运营部门的技术风险与合规总监汇报。Zscaler 正在寻找一位经验丰富的资深合规架构师,作为合规团队的技术专家,将可扩展、可审计的合规要求嵌入产品和基础设施交付中。该职位将架构思维带入合规领域,与工程、产品、合规工程和授权运营(AuthOps)紧密合作,将监管和保证义务转化为明确的技术需求、标准化的实现模式和自动化验证。
你将负责(职位期望)
- 定义并维护企业隐私基线要求,通过将监管和保证期望(例如 NIST 800-53、FedRAMP/DoD IL5 中与隐私相关的控制措施,以及 ISO 27701/ISO 42001)转化为可衡量的技术标准和验收测试,将其嵌入到 SDLC 中
- 建立标准化的隐私设计模式(数据最小化、目的限制、保留/删除、隐私安全遥测、访问控制),并与工程/合规工程团队合作,通过 CI/CD 流程自动化验证和证据收集
查看英文原文
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.
Role
We are looking for a Staff Compliance Architect to join our team. This is a Remote (if located outside of the San Jose, CA area) or Hybrid (based in San Jose, CA) role, reporting to the Director, Technology Risk and Compliance in the Exposure Management & Security Operations department. Zscaler is seeking an experienced Staff Compliance Architect to serve as the compliance team’s technical subject matter expert and to embed scalable, auditable compliance requirements into product and infrastructure delivery. This role brings an architectural mindset to compliance, partnering closely with Engineering, Product, Compliance Engineering, and Authorization Operations (AuthOps) to translate regulatory and assurance obligations into clear technical requirements, standardized implementation patterns, and automated validation.
What you’ll do (Role Expectations)
- Define and maintain enterprise privacy baseline requirements, embedding them into the SDLC by translating regulatory and assurance expectations (e.g., NIST 800-53, FedRAMP/DoD IL5 privacy-relevant controls, and ISO 27701/ISO 42001) into measurable technical criteria and acceptance tests
- Establish standardized privacy-by-design patterns (data minimization, purpose limitation, retention/deletion, privacy-safe telemetry, access controls) and partner with Engineering/Compliance Engineering to automate validation and evidence collection through CI/CD guardrails and policy-as-code
- Conduct privacy architecture reviews and operational readiness assessments to identify data-handling risks (collection, use, sharing, storage, logging), and provide actionable remediation guidance aligned to engineering realities and delivery timelines
- Maintain authoritative data flow diagrams and processing narratives, ensuring data classifications, processing purposes, transfer points, trust boundaries, and retention expectations are current, consistent, and audit-ready
- Evaluate significant changes for impacts to data processing scope, trust boundaries, and authorization boundaries; drive cross-functional alignment across Engineering, Product, Security, and Legal/Privacy stakeholders and ensure decisions are documented for auditability
Who You Are (Success Profile)
- You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
- You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
- You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
- You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
- You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We’re Looking for (Minimum Qualifications)
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
- Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related field
- 5+ years of experience in compliance, security architecture, compliance engineering, or technical audit with a focus on translating control requirements into technical verification mechanisms
- Proven experience performing architecture reviews and gap analysis against FedRAMP High or DoD IL5 frameworks
- Proficiency in public cloud services (AWS, Azure, or GCP) paired with a strong track record of producing architecture diagrams, control narratives, and driving outcomes through engineering partnerships
What Will Make You Stand Out (Preferred Qualifications)
- Experience building automated data governance frameworks or compliance verification systems specifically tailored to generative AI applications and large language model (LLM) data trust boundaries
- Experience building automated control validation systems such as policy-as-code or CI/CD control gates
- Deep familiarity with identity and authorization architectures, trust boundaries, and professional compliance certifications such as CISSP, CISA, CCSP, or specialized cloud security credentials
#LI-JG1 #LI-Hybrid #LI-Remote
Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.
The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.
Base Pay Range
$119,000—$170,000 USD
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Learn more about Zscaler's hybrid working model and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.