munotes®
Never miss an opening. Get the daily email.
Daily Tech Jobs India

Principal Vulnerability Management Engineer

Zscaler · Bangalore

Verified live on August 1, 2026
By the Daily Tech Jobs desk at munotes.in · Published · About us · Contact
Get every day's jobs where you already are
Zscaler
BangaloreFull-time12+ years

About this role

The highest experience bar in today's edition and an unusually well defined security engineering role. Zscaler wants someone to modernise how it finds and reduces security exposure across infrastructure, cloud, applications, APIs, endpoints, containers and internet facing assets. The posting is refreshingly direct about what it is not: it says the aim is to move vulnerability management away from being a reporting function and turn it into a product security engineering capability, which means building automated pipelines, scripting and workflow orchestration rather than producing scan reports. It also states in plain language that this is an individual contributor role. Twelve years overall with seven specifically in vulnerability and exposure management. Bangalore, hybrid.

Who this is for

What the posting asks for:
- 12+ years in security engineering or product security.
- Within that, 7+ years hands on driving and scaling vulnerability and exposure management programmes in complex environments.
- The ability to work both strategically and deep in the technical detail: findings, coverage gaps, scanner limitations and remediation paths.
- A builder mindset. The posting repeats this framing throughout.

Day to day:
- Leading vulnerability and exposure management across infrastructure, cloud, APIs and containers, evolving it from a reporting role into a product security engineering capability.
- Defining risk based prioritisation models that go beyond standard CVSS by folding in threat intelligence and business context, in order to cut noise and duplicate findings for engineering teams.
- Designing and deploying automated data pipelines, scripting and workflow orchestration across the whole lifecycle: asset discovery, authenticated scanning, triage, routing and validation.
- Driving external attack surface management to map internet facing assets, and identifying programme gaps such as unauthenticated scans and stale asset ownership.
- Influencing engineering teams rather than directing them.

Reporting and scope: reports to the Senior Manager, Information Security Engineering, in the Product Security department. The posting states directly that you operate as an individual contributor.

Location and office reality: Bangalore, hybrid. Days per week are not published.

Honest fit guidance: twelve years is real and so is the seven year vulnerability management specialisation. If your security background is broad but you have not owned a vulnerability management programme end to end, this is a stretch. If you have, the automation emphasis here is a better job than most roles with this title.
Apply on company site Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.
More roles like this, every day

Every link is checked live before we post it. Get the day's list in your inbox.

Free · one email a day · unsubscribe anytime

More from August 1, 2026

← Back to all jobs