Information Security Program Manager, FedRAMP Change Control
RubrikAbout the role
Information Security - Who We Are
Rubrik is seeking creative problem solvers with a passion for cyber security. In this role you will partner cross-functionally to help grow the business, secure the brand, and protect company and customer environments. You will be responsible for building and executing on security program initiatives and delivering technologies and improvements across security domains. Your work will enable strong cyber-defense capabilities that enhance the posture, maturity, and value of Rubrik’s information security organization as a whole.
What you'll be doing:
Information Security is looking for a US-based Program Manager to organize, plan, and execute on FedRAMP Change Control and related compliance activities for Rubrik’s government cloud service offering(s). This mission-critical position needs a Control Owner who will maintain the FedRAMP Configuration Management Plan, manage ongoing Change Requests, and chair our Change Control Board. This position performs Security Impact Analyses on all proposed changes and planned releases, recommends and justifies FedRAMP Significant Change determinations, enables timely Customer onboarding, and ensures compliant verification, training, and account management for Privileged Users. The incumbent must work with velocity and relentlessness to proactively cover these areas and more, ensuring due diligence in documenting our work in detail as well as our decisions and the associated rationale. As the program matures, you’ll also improve efficiency through helping others to automate manual processes and monitoring for the Change Control Program.
Working at Rubrik is dynamic and fast-paced, with strong, supportive leadership and amazing colleagues who enjoy getting things done. Assignments here can vary from operational tasks to delivering complex projects to starting new programs. Sometimes we’re running without a playbook, so bring your resourcefulness and be willing to flex in your assignments and priorities as needed to help the team. In return, your work here will make a difference every day. You’ll enjoy real work-life balance and knowing your contributions will be appreciated and rewarded. For remote workers, travel to HQ in Palo Alto, CA may be required one to four times per year.
Our ideal candidate:
The ideal candidate for this role is a leader-by-influence with a sense of humor who thrives in a fast-paced environment that can be like working at a startup. And let’s face it, you’re probably a NIST or security compliance nerd, much like we are. That said, you work at building strong relationships, being only as persnickety as you need to be when seeking consensus, herding cats, chasing status updates, and getting details documented.
You like to write and you’ve written plans, procedures, and documentation for both technical and non-technical audiences. Your writing and record-keeping is accurate, clear, and appropriately concise, involving others as needed to generate timely deliverables and quality work products.
You think working with FedRAMP controls from NIST SP 800-53 is fun (we agree!). Although you probably haven’t memorized all of them, you have a working knowledge of the FedRAMP security baselines and you can explain controls like AC-2, CM-2, and SI-2 to engineers and to executives. You can apply what you know to evaluate the impacts and risks of making changes where these (or other) FedRAMP controls apply, and you can help others support your analysis.
You probably have your CISSP certification or equivalent security and IT knowledge or experience. You’ve worked in at least one AWS, Azure, or GCP environment, so you understand cloud service concepts (VPC flow logs, key management, control planes) and you have been exposed to common cloud components like infrastructure as code (IaC), virtual machines (VM), and container-based (k8) architecture. These are essentials for doing Security Impact Analysis.
On top of the knowledge you’ll bring, you’re a great teammate who provides excellent service to stakeholders, and you hold yourself personally accountable for timely and successful results. You are comfortable taking responsibility for new things, working through ambiguity, solving problems, and relentlessly pursuing progress over perfection. If this is you, you will love it here.
Responsibilities
Program / Development
- Manage and serve as Control Owner for our FedRAMP Change Control Program. Others will request changes to the system; your role is to ensure these requests are conforming to requirements so the Change Control Board can understand the request. You may need to work with requesters to bring their requests up to standards.
- Collaborate with a range of stakeholders from individual contributors to senior leadership to external parties, to ensure t
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s