The Opportunity We are seeking a Zscaler Service Owner - Associate Director to join STS Network Security Technology and lead Zscaler services within Network Security.
This senior service leadership role is accountable for converting Zscaler platform investments into governed, supportable and measurable enterprise services. The role owns service strategy, roadmap, financial planning, service introduction, operational readiness, adoption, performance, risk, compliance, vendor outcomes and continuous improvement across the portfolio.
The approved service portfolio includes:
- Zscaler Al Firewall for secure Al access, including Zscaler Al Guard and Al Broker capabilities.
- Zscaler lnternet Access for secure outbound protection across cloud, office and data center traffic flows.
- Zscaler Private Access for private application access and reduction of internet-facing application exposure.
- Zscaler Cloud Gateway for controlled cloud and internet egress patterns aligned to Zero Trust operating requirements.
- Azure Zero Trust strategy for secure cloud networking, private access patterns and migration away from broad public exposure.
- Zscaler Deception for approved deception-based detection and response use cases within the Network Security service boundary.
The role will partner across Network Security, Architecture, Engineering, Operations, Cloud Technology, Enterprise Technology, ldentity, Data Protection, Monitoring and Response, Application Security, Service Lines and Zscaler to transition capabilities into sustainable global services.
Your Key ResponsibilitiesThe Zscaler Service Owner will provide strategic and operational leadership for services assigned to STS Network Security Technology.
Zscaler Platform Service Portfolio Ownership
- Define the service vision, scope, outcomes, roadmap and lifecycle for each assigned Zscaler platform capability within Network Security.
- Translate Zscaler platform objectives into clear service offerings, service tiers, customer journeys, support models and measurable outcomes.
- Maintain an integrated service portfolio limited to ZPA, ZlA, Zscaler Cloud Gateway, Al Firewall, Zscaler
- Deception and Azure Zero Trust strategy capabilities.
- Own service acceptance criteria and ensure project delivery is not complete until operational readiness, supportability, controls, documentation and ownership are in place.
- Prioritize enhancements, technical debt, resilience improvements and adoption initiatives based on business value, security risk and service performance.
Al Security Services
- Own the service delivery model for inline inspection and policy enforcement for user-to-Al, application-to-Al, agent-to-agent and Model Context Protocol-based communications within the approved Zscaler scope.
- Coordinate delivery and adoption of the Al Firewall service construct, where Al Guard and Al Broker form part of the capability set, including policy governance, service onboarding, operating procedures, telemetry, escalation and control evidence.
- Own service integration requirements with Al platforms, gateways, identity, data protection, monitoring, incident response and governance processes.
- Ensure Al security services support approved use cases while managing data leakage, unauthorized access, unsafe tool use and emerging Al-specific threats.
Zero Trust Outbound Traffic Services
- Own cloud and on-premises outbound security services delivered through Zscaler Cloud Gateway and Zscaler lnternet Access.
- Coordinate service design and adoption for routing, inspection, policy enforcement, threat prevention, encrypted traffic inspection and data protection.
- Define onboarding patterns, exception governance, customer responsibilities, service dependencies and operational hand-offs for cloud and data center environments.
- Establish service measures for coverage, policy compliance, availability, user impact and risk-reduction outcomes.
Private Access and Attack Surface Reduction
- Own the service roadmap for migrating eligible applications from public exposure and broad network access to identity-based, application-specific access.
- Lead the service model for Zscaler Private Access, least-privilege access, application segmentation and Zero Trust B2B connectivity.
- Partner with application, cloud and infrastructure owners to establish repeatable onboarding, validation, support and decommissioning processes.
- Govern service exceptions and ensure that residual public exposure or broad access is documented, risk-assessed and time-bound.
Azure Zero Trust Strategy and Segmentation Enablement
- Contribute to Azure Zero Trust strategy by defining secure segmentation, private access and workload connectivity principles within the approved service scope.
- Define service boundaries for user-to-application, application-to-application and workload connectivity patterns aligned to Zero Trust principles.
- Coordinate readiness across architecture, engineering, platform operations, application teams and support providers.
- Ensure approved segmentation and access patterns include policy models, exception processes, change controls, monitoring, recovery procedures and evidence requirements.
Service Strategy, Roadmap and Governance
- Create and maintain a multi-year service and capability roadmap aligned with the Zscaler platform service portfolio and STS Network Security strategy.
- Chair service governance forums and provide clear decisions, actions, dependencies, risks and escalations.
- Establish service policies, standards, operating models, RACl, controls and decision rights.
- Provide executive reporting on roadmap delivery, adoption, service health, security outcomes, financial position and material risks.
- Ensure roadmap commitments are aligned across Zscaler, STS Architecture, Engineering, Operations and dependent technology functions.
Service lntroduction and Operational Readiness
- Own the transition of new or enhanced Zscaler platform capabilities from program delivery into production-ready services.
- Define and approve operational readiness requirements covering support model, monitoring, alerting, runbooks, knowledge articles, capacity, continuity, access administration, escalation paths, training and vendor support.
- Ensure production acceptance includes control validation, service metrics, support agreements, documented dependencies and accountable owners.
- Coordinate early-life support and confirm exit criteria before capabilities move to business-as-usual operations.
- Prevent unsupported technology deployment by making service readiness and evidence mandatory delivery gates.
Service Performance and Continuous lmprovement
- Define and govern service-level objectives, key performance indicators, risk indicators and outcome measures.
- Review service availability, incidents, problems, changes, capacity, adoption, policy effectiveness and customer experience.
- Lead major service reviews and ensure root causes, systemic issues and corrective actions are owned throughclosure.
- Use operational data and customer feedback to improve service quality, resilience, automation and usability.
- Drive standardization and automation across onboarding, policy management, evidence collection, reporting and control validation.
Risk, Control and Compliance Accountability
- Ensure services operate in accordance with EY security requirements, architecture standards, change controls and audit expectations.
- Own service-level control design, evidence requirements, control operation oversight and remediation tracking.
- Maintain an auditable record of service decisions, exceptions, risk acceptance, control validation and closure evidence.
- Partner with risk, compliance, privacy, data protection and legal stakeholders where Al security and Zscaler platform services introduce additional obligations.
Financial, Commercial and Vendor Management
- Own service financial planning, forecasts, licensing assumptions, support costs and investment proposals.
- Develop business cases for service expansion, adoption and remediation priorities.
- Act as the senior service relationship lead for Zscaler and relevant delivery partners.
- Govern vendor performance against contractual commitments, support agreements, product roadmaps,implementation outcomes and service levels.
- Drive license utilization, value realization and cost optimization without reducing required security outcomes.
- Coordinate product roadmap discussions so emerging Zscaler capabilities are assessed against Network Security priorities and operating requirements.
Stakeholder, Adoption and Customer Leadership
- Build trusted relationships with STS leadership, Network Security platform stakeholders, technology functions, service lines and business stakeholders.
- Communicate the purpose, value, service boundaries, adoption requirements and customer responsibilities for each capability.
- Create stakeholder-specific adoption plans and ensure application, cloud, infrastructure and user communities can consume services consistently.
- Lead resolution of cross-functional dependencies and escalate decisions that affect scope, risk, funding, schedule or service viability.
- Translate complex security and technology matters into clear executive decisions and business outcomes.
Leadership and Team Development
- Lead a global virtual service team spanning service management, architecture, engineering, operations, project delivery and vendor resources.
- Set clear objectives, accountability and ways of working across teams that may not report directly into the role.
- Coach service managers, product specialists and technical leads in service ownership and outcome-based delivery.
- Promote a culture of evidence-led delivery, customer focus, automation, operational discipline and continuous improvement.
- Act as the senior escalation point for service-level issues, competing priorities and material delivery risks.
Skills and Attributes for Success - We are interested in candidates who combine strategic service ownership, cybersecurity expertise, commercial discipline and pragmatic delivery leadership in a complex global enterprise.
- Demonstrated ability to own an enterprise security service from strategy and investment through transition, operation, improvement and retirement.
- Strong understanding of Zero Trust, Security Service Edge, secure access, segmentation, cloud networking andAl security service concepts.
- Ability to translate programs and product capabilities into consumable, governed and supportable services.
- Strong command of lT service management practices, including service design, transition, incident, problem, change, availability, capacity, continuity and continual improvement.
- Experience defining service metrics and presenting service performance, risk, value and roadmap decisions to senior stakeholders.
- Commercial and vendor management capability, including licensing, support agreements, roadmap influence and value realization.
- Ability to lead through influence across global, cross-functional and cross-border teams.
- Excellent written and verbal communication, negotiation, decision-making and executive stakeholder management skills.
- Ability to operate effectively in an ambiguous, fast-moving environment where Al-related risks, technologies and business priorities continue to evolve.
To Qualify for the Role, You Must Have - Bachelor's degree in Computer Science, lnformation Technology, Engineering, Cybersecurity, Business Management or equivalent experience.
- 18+ years of overall experience across cybersecurity, network security and infrastructure security.
- 8+ years of experience with Zscaler platforms and services, including service ownership, delivery leadership, product management or operations leadership for global technology services.
- Experience managing enterprise-scale security or network services in a complex global environment.
- Deep experience with Zscaler services in the defined scope, including ZPA, ZlA, Zscaler Cloud Gateway, Al Firewall and Zscaler Deception, with working knowledge of Azure Zero Trust strategy and secure access patterns.
- Experience supporting enterprise adoption of new technology capabilities and establishing sustainable operating and support models.
- Experience managing service financials, vendor relationships, risks, controls, audit requirements and executive governance.
- Experience leading major transformation initiatives that require coordination across architecture, engineering operations and business stakeholders.
- Strong English communication skills, both written and verbal.
ldeally, You'll Also Have - Experience delivering services for secure Al adoption, GenAl platforms, Al agents or Al-enabled applications.
- Knowledge of Zscaler Al Firewall capabilities, including Al Guard and Al Broker, together with ZPA, ZlA, Zscaler Cloud Gateway, Zscaler Deception and Azure Zero Trust strategy.
- Unders