Logo
Rubrik

SOC Team Lead - FedRAMP

Rubrik, Boise, Idaho, United States, 83708

Save Job

Overview

The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security develops systems to monitor and respond to attacks, provides awareness education on security best practices for data protection, and ensures secure data sharing relationships with third parties. About the role Rubrik’s Security Operations Center (SOC) team is responsible for threat detection and incident response, including monitoring, triaging, and escalating security alerts from across the enterprise. The SOC is the first to respond to cyber security incidents, report on cyber threats, and drive changes needed to protect the organization. As the Security Operations Incident Response Team Lead, FedRAMP you will lead and mentor a team of incident responders, oversee the full lifecycle of security incidents from detection to resolution, and ensure all activities adhere to stringent FedRAMP requirements. This role requires a deep understanding of incident response methodologies, security technologies, and the ability to operate effectively within a highly regulated environment. Responsibilities

Lead and act as the primary investigator during incident response (IR) activities, leveraging expertise in enterprise forensics. Ensure IR investigations are prioritized, escalated properly, and consistently thorough, accurate, and complete. Investigate escalated security alerts across Rubrik’s corporate network, endpoints, cloud, and SaaS environments. Collaborate with cross-functional teams to drive timely resolution of IR investigations and response actions. Develop and execute regular exercises to continuously improve the team's incident response capabilities. Maintain accurate incident case attributes and detailed investigation documentation. Oversee the entire vulnerability management lifecycle, including scanning, assessment, prioritization, tracking, and remediation across FedRAMP authorized systems. Analyze threats and vulnerabilities to determine their criticality and risk. Collaborate with the CTI team to identify, document, and report on InfoSec threats and emerging trends discovered during incident response activities. Lead after-action reviews and post-mortems to identify areas for improvement and implement lessons learned. Guide and train junior analysts, serving as an escalation point for complex investigations and questions. Contribute to program maturity by providing feedback to refine detection capabilities and response processes. Experience you\'ll need

8+ years of progressive experience in cybersecurity, with at least 2+ years in a security incident response leadership role. Strong technical expertise in SIEM (e.g., Sentinel, Splunk, QRadar), EDR (e.g., CrowdStrike, SentinelOne), IDS/IPS, firewalls, and cloud security tools. Deep understanding of incident response methodologies (NIST, SANS). Experience in environments subject to FedRAMP compliance (e.g., NIST SP 800-53, FedRAMP controls, JAB/Agency ATO processes). Excellent analytical, problem-solving, and decision-making skills under pressure. Strong communication and interpersonal skills; able to convey complex technical information to technical and non-technical audiences. Ability to work independently and as part of a team in a fast-paced, dynamic environment. Preferred Qualifications

Relevant security certifications (e.g., CISSP, GCIH, GCFA, CCNP Security, cloud security certifications). Vulnerability management or penetration testing certifications (e.g., PenTest+, OSCP, CEH) are a plus. Experience with Security Orchestration, Automation, and Response (SOAR) platforms. Familiarity with AWS, Azure, GCP security offerings. Proficiency in scripting languages (e.g., Python, PowerShell) for automation and analysis. Experience with digital forensics artifacts, techniques and tools. Knowledge of compliance frameworks beyond FedRAMP (e.g., HIPAA, PCI-DSS, ISO 27001). Security and Privacy Responsibilities

This position carries special Security and Privacy Responsibilities for protecting the U.S. Federal Government’s interests: Know, acknowledge, and follow system-specific security policies and procedures; Protect data and individual privacy per requirements and regulations; Perform ongoing activities in compliance with service and contractual obligations; Participate in role-based training and complete assignments on a timely basis; Report security issues promptly and aid investigation when needed; Support controlled changes and vulnerability remediation activities; Work collaboratively with Information Security in designing, implementing, assessing or enhancing system-specific security and privacy controls. Position Risk Designation

This position carries duties and responsibilities involving the U.S. Federal Government’s interests. Additional background checks with periodic re-screening may apply: Position Risk Designation: Non-Sensitive, Low Risk, Tier 1

– May require Standard Form 85 and Tier 1 Investigation for non-sensitive positions. Position Risk Designation: Non-Sensitive, Moderate Risk, Tier 2 (Public Trust)

– May require Standard Form 85P and Tier 2 Investigation for non-sensitive positions designated Moderate Risk. Position Risk Designation:Moderate Risk Law Enforcement (CJIS)

– May require fingerprint-based national criminal history background check within 30 days of hire. #LI-remote The salary ranges below reflect minimum and maximum targets for new hires in U.S. locations; actual offers depend on location, skills, experience, and training. US (SF Bay Area, DC Metro, NYC) Pay Range: $176,300—$264,400 USD US2 (all other US offices/remote) Pay Range: $158,700—$238,000 USD Join Us in Securing the World\'s Data Rubrik is on a mission to secure the world’s data. With Zero Trust Data Security, we help organizations achieve business resilience against cyberattacks, malicious insiders, and operational disruptions. Rubrik Security Cloud, powered by machine learning, secures data across enterprise, cloud, and SaaS applications. We help organizations uphold data integrity, deliver data availability that withstands adverse conditions, monitor data risks and threats, and restore businesses with their data when infrastructure is attacked. Equal Opportunity Employer/Veterans/Disabled Rubrik is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. Rubrik provides equal employment opportunities (EEO) to all employees and applicants; Rubrik complies with applicable state and local nondiscrimination laws. Reasonable accommodation requests can be directed to hr@rubrik.com. EEO IS THE LAW and related notices apply where legally required.

#J-18808-Ljbffr