About The Position

Zscaler is seeking a hands-on Security Architect/Engineer to join their Exposure Management & Security Operations team. This role is focused on building and shipping security capabilities for agentic AI systems, specifically LLM applications that involve planning, tool usage, memory management, and enterprise data integration. The position is implementation-focused, requiring the delivery of production code, secure building blocks, and reference implementations for both IT and Product teams. The company emphasizes an AI-forward approach, leveraging a large security data lake to power its Zero Trust Exchange platform and protect customers from cyberattacks and data loss. Zscaler values innovation, impact, transparency, and high-performing teams, fostering a culture of execution centered on customer obsession, collaboration, ownership, and accountability.

Requirements

  • Extensive experience designing and implementing agent runtimes including planning, tool calling, and memory/state controls.
  • 8+ years of experience shipping production security engineering solutions.
  • Strong coding skills in Python, TypeScript, or Node.
  • Practical experience integrating frontier model APIs with structured outputs, streaming, and safety controls.
  • Familiarity with agent frameworks such as LangGraph, LangChain, or Semantic Kernel and the ability to extend them securely.
  • Solid experience in cloud security for AWS, GCP, or Azure.
  • Kubernetes security and Infrastructure as Code experience.

Nice To Haves

  • Familiarity with OWASP LLM Top 10, MITRE ATLAS, or the NIST AI RMF.
  • Experience building red-team style testing or evaluation harnesses for LLM applications and agents.
  • Strong background in data security for RAG, including retrieval authorization and tenancy boundaries.

Responsibilities

  • Build secure agent runtimes, libraries, and reference implementations.
  • Implement core agent patterns such as planner/executor, tool routing, and RAG boundaries.
  • Build and secure MCP servers, clients, tool registries, and connector patterns with robust authentication, authorization, and audit logging.
  • Enforce secure-by-default controls including schema validation, tool allowlists, redaction, and policy checks.
  • Threat model and test agent workflows for prompt injection and data exfiltration to build repeatable security evaluations.

Benefits

  • Various health plans
  • Time off plans for vacation and sick time
  • Parental leave options
  • Retirement options
  • Education reimbursement
  • In-office perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service