Rubrik is revolutionizing data protection and management in the multi-cloud world. We simplify backup and recovery, accelerate cloud adoption, and secure against cyberthreats. Join us in designing and building critical software systems, implementing security features, and hardening our products. You'll also be responsible for vulnerability assessment, compliance, and certifications. Strong technical skills in encryption, network security, and identity and access management are required. Experience with SaaS products and FedRAMP risk assessments is a plus.
About Rubrik
Rubrik is one of the fastest-growing companies in Silicon Valley, revolutionizing data protection, and management in the emerging multi-cloud world. We are the leader in cloud data management, delivering a single platform to manage and protect data in the cloud, at the edge, and on-premises. Enterprises choose Rubrik to simplify backup and recovery, accelerate cloud adoption, enable automation at scale, and secure against cyberthreats. We’ve been recognized as a Forbes Cloud 100 Company two years in a row and as a LinkedIn Top 10 startup.
Rubrik provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age or disability. In addition to federal law requirements, Rubrik complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Responsibilities
- You’ll design, implement, and evolve critical, high-quality, scalable software systems
- You’ll understand security protocols and use them as building blocks to build security features
- You'll work on new security-related product features to make customer data more secure
- You’ll identify attack surfaces and build solutions to harden Rubrik products
- You’ll review designs and implementations of general product features to ensure security best practices are followed
- You will evangelize secure coding practices across all engineering teams
- You will be expected to create highly effective documentation to enable the engineering team to use existing security primitives safely
- You will partner with the Information security team during regular assessment of Vulnerabilities identified by infrastructure scan, evaluate and perform risk assessment towards the product. Prioritizing the vulnerabilities discovered along with remediation timelines
- Understand Complex technical security architectures (including cloud architecture) and apply that to Compliance and Certifications as needed
- Participate in product and production support operations focused on Identities and Access Management (IAM) and Role Based Access Controls (RBAC) strategies and implementations
- Be the technical Security Point of for Rubrik products with regards to security aspects
- Demonstrate ownership and accountability for product roadmap
- Strongly influence decision makers and stakeholders to achieve consistently raise the security bar
- Support for mentoring, team building and recruitment activities in a company where security is critical priority
- Help develop a complex security system using cipher and algorithm along with various key rotation techniques to protect data from misuse
Preferred Skills:
- Experience in data-security and information security. This experience should be demonstrated through practical applications in protecting sensitive data and defending against various cyber-attacks
- Data protection for both data in rest and data in flight - Need to be aware of the latest security standards and protocols for both encryption and communication
- Provide Identity and Access Management(IAM) advisory, solution architecting and consulting to internal teams.
- Well versed in the best practices while dealing with secrets and other sensitive information - Need to also educate the team as a whole.
- Strong technical skills, especially in areas like encryption, network security, application security, cloud security, and identity and access management. These skills should be complemented by a thorough understanding of computer science fundamentals and systems architecture. Experience in systems administration for Linux and Windows operating systems would good to have
- Familiarity with the security challenges that arise in the context of SaaS products, microservices architecture and containerization. And familiarity with security and encryption practices on a Linux machine.
- At least 5 years for technology-focused FedRAMP risk assessments and remediation management. Prior FedRAMP Moderate, High IL5 assessment experience is a plus
Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field (Master's degree is a plus)
- Proficiency in using applied cryptography to ensure the privacy and integrity of data
- Proficiency in identifying common classes of vulnerabilities (e.g., OWASP Top 10)
- Deep understanding of Linux internals, containers and virtualization
- Experience in architecting and developing security features for large scale systems
- Proficiency in core security principles and commonly used protocols and technologies
- Excellent problem-solving and communication skills.
- Ability to work independently and as part of a team