Staff Program Manager, Compliance
Role
We are looking for a Staff Program Manager, Compliance to join our team. This is a Hybrid role, reporting to the Leader of Global Commercial Compliance in the Exposure Management & Security Operations department. At Zscaler, compliance is a strategic business enabler and a foundation of customer trust. As a Staff Program Manager, Compliance, you will be at the forefront of how a global, cloud-native cybersecurity leader governs, scales, and continuously evolves its compliance posture across an increasingly complex regulatory landscape. Working at the intersection of engineering, product, legal, and security, you will ensure that infrastructure, products, and processes meet and anticipate the world's most demanding standards.
What you'll do (Role Expectations)
- Own and drive certification programs across SOC 2 Type II, ISO frameworks, and emerging standards while developing multi-year roadmaps anchored in customer commitments
- Lead privacy & compliance readiness for the EU AI Act, NIST AI Risk Management Framework, and global privacy programs like GDPR and HIPAA
- Partner with cross-functional teams to embed Compliance-as-Code practices and Zero Trust principles into the software development life cycle
- Coordinate internal and external audits from scoping through executive readout while maintaining comprehensive documentation in GRC platforms
- Advise engineering, legal, and business units by translating complex regulatory requirements into clear, actionable guidance
Who You Are (Success Profile)
- You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
- You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
- You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
- You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback-knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
- You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We're Looking for (Minimum Qualifications)
- Foundational understanding of AI/ML technologies and experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
- Extensive experience in compliance, security program management, GRC, or technical auditing within enterprise SaaS, cloud-native, or cybersecurity environments
- Proven track record driving large-scale, multi-framework certification programs such as ISO 27001, SOC 2, or FedRAMP end-to-end
- Hands-on experience with GRC automation tools and moving compliance programs from manual to automated, continuous monitoring
- Deep understanding of global data privacy regulations and experience translating emerging regulatory frameworks into practical implementation plans
What Will Make You Stand Out (Preferred Qualifications)
- Advanced expertise in AI/ML system governance, model risk management, or automated compliance verification for generative AI applications
- Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Strong technical fluency in cloud-native architectures, Zero Trust principles, cryptographic standards, and DevSecOps workflows
#LI-RM6 #LI-Hybrid