Zscaler

Federal Incident Response Lead (Principal Information Security Engineer)

McLean, Virginia, USA Full Time

About Zscaler

Zscaler accelerates digital transformation so our customers can be more agile, efficient, resilient, and secure. Our cloud native Zero Trust Exchange platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

Here, impact in your role matters more than title and trust is built on results. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership and accountability. 

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges and want to make a positive difference on a global scale, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

We are looking for a Federal Incident Response Lead (Principal Information Security Engineer) to join our team. This is a full-time onsite role based in Crystal City, VA, reporting to the Director of Federal Security Operations within the Enterprise Security department. You will establish and lead incident response operations from the ground up within a new, dedicated DoD/DoW IL6 cloud environment. You’ll drive end-to-end incident command, proactive threat hunting, and the operationalization of processes and tooling to ensure rapid response. This mission-critical role ensures our federal security practices align with DoD CC SRG and FedRAMP requirements.

What you’ll do (Role Expectations)

  • Establish and mature an Incident Response (IR) program within a new, dedicated, classified DoD environment (primarily DoD IL6 with FedRAMP and DoD IL5 support)
  • Lead end-to-end incident response, including triage, containment, eradication, recovery, and post-incident lessons learned with rigorous documentation
  • Stand up and lead a formal threat hunting capability to proactively investigate and mitigate potential security threats in an IL6 environments
  • Partner with security platform engineering to operationalize and tune SIEM/SOAR (Splunk Enterprise Security) content and playbooks, define detection requirements and coverage gaps, and ensure alerts are actionable for rapid response
  • Collaborate with cross-functional teams to develop and refine IR playbooks, procedures, and automation aligned with DoD CC SRG and FedRAMP

Who You Are (Success Profile)

  • You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
  • You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. You adapt to what’s needed, navigating seamlessly between high-level strategy and hands-on execution.
  • You are a problem-solver. You seek out challenges because you are energized by finding solutions, knowing that solving the hard problems delivers the biggest impact.
  • You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
  • You operate with urgency. You understand that in a high-growth environment, speed and quality are not mutually exclusive. You have a relentless focus on execution and a bias for action, delivering high-impact results quickly to win for the customer and the team.

What We’re Looking for (Minimum Qualifications)

  • US Citizenship and an active U.S. Secret Security Clearance (Top Secret preferred), with a willingness to participate in an on-call rotation (nights and weekends)
  • 8+ years leading incident response and DFIR in DoD/classified environments, with proven incident command experience in 24/7 operations
  • Experience establishing IR programs and formal threat hunting functions in cloud-centric federal environments
  • Hands-on leadership operationalizing and tuning SIEM/SOAR (preferably Splunk Enterprise Security) content and playbooks
  • Practical application of FedRAMP Moderate/High, NIST 800-53, DoD CC SRG, RMF, and DISA STIGs to IR processes and tooling

What Will Make You Stand Out (Preferred Qualifications)

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field
  • Have or be able to obtain advanced DoD 8140 DCWF certification
  • Experience operating in U.S. government cloud regions (AWS GovCloud/Secret or Azure Government/DoD/Secret) with DoD IL5/IL6 constraints

#LI-Onsite #LI-KM9

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range
$161,000$230,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks, and more!

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

Pay Transparency

Zscaler complies with all applicable federal, state, and local pay transparency rules.

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.