Zscaler logo
ZscalerPosted 1 month ago

Staff Program Manager, Compliance

HybridMohali, Punjab, India

Full TimeSenior LevelLargeCybersecurity Services

Job Summary

Own and drive certification programs across SOC 2 Type II, ISO frameworks, and emerging standards while developing multi-year roadmaps anchored in customer commitments. Lead privacy and compliance readiness for the EU AI Act, NIST AI Risk Management Framework, and global privacy programs like GDPR and HIPAA. Partner with cross-functional teams to embed Compliance-as-Code practices and Zero Trust principles into the software development life cycle. Coordinate internal and external audits from scoping through executive readout while maintaining comprehensive documentation in GRC platforms. Advise engineering, legal, and business units by translating complex regulatory requirements into clear, actionable guidance.

Required Qualifications

  • Foundational understanding of AI/ML technologies
  • Experience leveraging, securing, or positioning AI-driven solutions to optimize outcomes within your functional domain
  • Extensive experience in compliance, security program management, GRC, or technical auditing within enterprise SaaS, cloud-native, or cybersecurity environments
  • Proven track record driving large-scale, multi-framework certification programs such as ISO 27001, SOC 2, or FedRAMP end-to-end
  • Hands-on experience with GRC automation tools and moving compliance programs from manual to automated, continuous monitoring
  • Deep understanding of global data privacy regulations
  • Experience translating emerging regulatory frameworks into practical implementation plans

Desired Qualifications

  • Advanced expertise in AI/ML system governance
  • Model risk management
  • Automated compliance verification for generative AI applications
  • Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
  • Strong technical fluency in cloud-native architectures
  • Knowledge of Zero Trust principles
  • Understanding of cryptographic standards
  • Experience with DevSecOps workflows

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce