.jpg?1700169058)
Threat Response Engineer (TRE) - Early Shift (6am-2pm MT)
zscaler • USA - Update Location
Posted: July 7, 2026
Job Description
Role
We are looking for a Threat Response Engineer (TRE) to join our team. This is a Remote (USA Only) role, reporting to the Senior Manager, Threat Response Engineering in the ZSS - Security Services department. In this position, you will be responsible for responding to confirmed compromises on customer endpoints subscribed to the Active Remediation MDR service.
What you’ll do (Role Expectations)
- Perform investigations into detected threats and leverage security products to analyze, contain, and remediate threats in customer environments
- Provide customers with thorough reports of actions taken to ensure clarity on environment cleanup and protection strategies
- Identify and implement effective response strategies to further enhance the security posture of the customer base
- Collaborate with Detection Engineering, Threat Hunting, Intel, and Product teams to develop innovative methods for timely threat remediation
- Prioritize and execute tasks effectively in a fast-paced operational environment while participating a 24x7 on-call rotation
Who You Are (Success Profile)
- You thrive in a dynamic, fast-paced environment, viewing ambiguity not as a hindrance but as the raw material to build meaningful solutions.
- You act like an owner with a strong passion for the mission and a bias for action, navigating seamlessly between high-level strategy and hands-on execution.
- You are a natural problem-solver who is energized by finding solutions to complex technical challenges, knowing that tackling hard problems delivers the biggest impact.
- You are a lifelong learner with a true growth mindset, actively seeking feedback to continuously develop yourself and become a stronger teammate.
- You are driven by innovation, possessing a deep curiosity for how things work and a belief in the power of technology to accelerate transformation.
What We’re Looking for (Minimum Qualifications)
- Strong analytical and problem-solving skills demonstrated through direct experience responding to security events and threats
- Experience with Endpoint Detection and Response (EDR) products including CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or CarbonBlack and familiarity with Identity security technologies
- Foundational understanding of internal system functionality for Windows and MacOS operating systems
- Demonstrated curiosity and active exploration of AI tools, with a proven history of integrating new technologies to enhance daily workflows and augment problem-solving
- Professional and articulate communication skills with the ability to provide clear technical documentation
- Ability to work Monday - Friday 6:00am - 2:00pm MT and participate in a recurring, monthly on-call rotation
What Will Make You Stand Out (Preferred Qualifications)
- Experience with security operations, enterprise technology, and network controls or protocols
- Experience utilizing AI-augmented development platforms to drive security automation, with a demonstrated capability to proactively refine or engineer new AI-based solutions that enhance operational velocity and tool efficacy
- Deep interest in staying current with the latest adversary tactics, techniques, and procedures
#LI-KM9 #LI-Remote
Additional Content
Role
We are looking for a Threat Response Engineer (TRE) to join our team. This is a Remote (USA Only) role, reporting to the Senior Manager, Threat Response Engineering in the ZSS - Security Services department. In this position, you will be responsible for responding to confirmed compromises on customer endpoints subscribed to the Active Remediation MDR service.
What you’ll do (Role Expectations)
- Perform investigations into detected threats and leverage security products to analyze, contain, and remediate threats in customer environments
- Provide customers with thorough reports of actions taken to ensure clarity on environment cleanup and protection strategies
- Identify and implement effective response strategies to further enhance the security posture of the customer base
- Collaborate with Detection Engineering, Threat Hunting, Intel, and Product teams to develop innovative methods for timely threat remediation
- Prioritize and execute tasks effectively in a fast-paced operational environment while participating a 24x7 on-call rotation
Who You Are (Success Profile)
- You thrive in a dynamic, fast-paced environment, viewing ambiguity not as a hindrance but as the raw material to build meaningful solutions.
- You act like an owner with a strong passion for the mission and a bias for action, navigating seamlessly between high-level strategy and hands-on execution.
- You are a natural problem-solver who is energized by finding solutions to complex technical challenges, knowing that tackling hard problems delivers the biggest impact.
- You are a lifelong learner with a true growth mindset, actively seeking feedback to continuously develop yourself and become a stronger teammate.
- You are driven by innovation, possessing a deep curiosity for how things work and a belief in the power of technology to accelerate transformation.
What We’re Looking for (Minimum Qualifications)
- Strong analytical and problem-solving skills demonstrated through direct experience responding to security events and threats
- Experience with Endpoint Detection and Response (EDR) products including CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or CarbonBlack and familiarity with Identity security technologies
- Foundational understanding of internal system functionality for Windows and MacOS operating systems
- Demonstrated curiosity and active exploration of AI tools, with a proven history of integrating new technologies to enhance daily workflows and augment problem-solving
- Professional and articulate communication skills with the ability to provide clear technical documentation
- Ability to work Monday - Friday 6:00am - 2:00pm MT and participate in a recurring, monthly on-call rotation
What Will Make You Stand Out (Preferred Qualifications)
- Experience with security operations, enterprise technology, and network controls or protocols
- Experience utilizing AI-augmented development platforms to drive security automation, with a demonstrated capability to proactively refine or engineer new AI-based solutions that enhance operational velocity and tool efficacy
- Deep interest in staying current with the latest adversary tactics, techniques, and procedures
#LI-KM9 #LI-Remote