Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.
Role
We are looking for a Staff Program Manager, Compliance to join our team. This is a Hybrid role, reporting to the Leader of Global Commercial Compliance in the Exposure Management & Security Operations department. At Zscaler, compliance is a strategic business enabler and a foundation of customer trust. As a Staff Program Manager, Compliance, you will be at the forefront of how a global, cloud-native cybersecurity leader governs, scales, and continuously evolves its compliance posture across an increasingly complex regulatory landscape. Working at the intersection of engineering, product, legal, and security, you will ensure that infrastructure, products, and processes meet and anticipate the world's most demanding standards.
What you’ll do (Role Expectations)
- Own and drive certification programs across SOC 2 Type II, ISO frameworks, and emerging standards while developing multi-year roadmaps anchored in customer commitments
- Lead privacy & compliance readiness for the EU AI Act, NIST AI Risk Management Framework, and global privacy programs like GDPR and HIPAA
- Partner with cross-functional teams to embed Compliance-as-Code practices and Zero Trust principles into the software development life cycle
- Coordinate internal and external audits from scoping through executive readout while maintaining comprehensive documentation in GRC platforms
- Advise engineering, legal, and business units by translating complex regulatory requirements into clear, actionable guidance
Who You Are (Success Profile)
- You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
- You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
- You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
- You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
- You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We’re Looking for (Minimum Qualifications)
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
- Extensive experience in compliance, security program management, GRC, or technical auditing within enterprise SaaS, cloud-native, or cybersecurity environments
- Proven track record driving large-scale, multi-framework certification programs such as ISO 27001, SOC 2, or FedRAMP end-to-end
- Hands-on experience with GRC automation tools and moving compliance programs from manual to automated, continuous monitoring
- Deep understanding of global data privacy regulations and experience translating emerging regulatory frameworks into practical implementation plans
What Will Make You Stand Out (Preferred Qualifications)
- Advanced expertise in AI/ML system governance, model risk management, or automated compliance verification for generative AI applications
- Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Strong technical fluency in cloud-native architectures, Zero Trust principles, cryptographic standards, and DevSecOps workflows
#LI-RM6 #LI-Hybrid
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Learn more about Zscaler's hybrid working model and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
Skills Required
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions
- Extensive experience in compliance, security program management, GRC, or technical auditing within enterprise SaaS, cloud-native, or cybersecurity environments
- Proven track record driving large-scale, multi-framework certification programs such as ISO 27001, SOC 2, or FedRAMP end-to-end
- Hands-on experience with GRC automation tools and moving compliance programs from manual to automated, continuous monitoring
- Deep understanding of global data privacy regulations and experience translating emerging regulatory frameworks into practical implementation plans
- Advanced expertise in AI/ML system governance, model risk management, or automated compliance verification for generative AI applications
- Professional certification such as CISSP, CISM, or CISA
- Strong technical fluency in cloud-native architectures, Zero Trust principles, cryptographic standards, and DevSecOps workflows
Zscaler Compensation & Benefits Highlights
-
Healthcare Strength — Coverage is described as comprehensive across medical, dental, and vision, with mental‑health access and targeted programs for complex and chronic needs. Inclusive options span fertility, gender‑affirming care, and specialized support such as menopause and cancer‑care navigation.
-
Parental & Family Support — Paid parental leave is outlined for all parents, with additional disability time for birthing parents and a ramp‑back period at full pay. Family‑building benefits and adoption assistance are also highlighted.
-
Equity Value & Accessibility — Equity grants (RSUs) and a discounted stock purchase plan are positioned as meaningful components of total rewards. Feedback suggests these programs enhance overall compensation, particularly in eligible roles.
Zscaler Insights
What We Do
Zscaler accelerates digital transformation so our customers can be more agile, efficient, resilient, and secure. Our cloud native Zero Trust Exchange platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Why Work With Us
Our impact comes from how we work—every day, in every decision, as one team. Our values and leadership principles are more than words; they're our operating system. They fuel a culture of execution where trust, transparency, and accountability help us deliver meaningful results for our customers, colleagues, and our company. www.zscaler.com/culture
Gallery
Zscaler Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.