Jobs and Careers
RU

Senior Application Security Engineer - FedRAMP

Rubrik
Palo Alto, United StatesRemotefull_timeVerifiedPosted 1 May 2024
💰 $258,000/yr($154,800/yr$258,000/yr)

About the role

Company Description

Rubrik is one of the fastest growing companies in Silicon Valley, revolutionizing data protection and management in the emerging multi-cloud world. We are the leader in cloud data management and have raised over $553 million in venture funding, most recently at a valuation of $3.3 billion. Rubrik has been recognized as a Forbes Cloud 100 Company two years in a row and as a LinkedIn Top 10 startup. As cloud adoption continues to grow at an astounding rate, we’ll be solving some of its most interesting challenges while building a product unlike anything seen before. This is a massive challenge and we’re just getting started so there is a lot of opportunity for personal growth and contribution.

Information Security - Who We Are

The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our assets, provides awareness education to teams on security best practices for data protection, and ensures data governance and data sharing relationships with third parties in order to securely protect Rubrik information. 

Where can you make an impact?

Rubrik is seeking a Senior Application Security Engineer.  In this role, you will be responsible for ensuring that Rubrik's products and services are designed and implemented to the highest possible security standards.  You will partner with a variety of stakeholders across the business to achieve successful security outcomes in product and feature deliverables.

Responsibilities:

  • Actively participate in integrating security controls and practices into the SDLC and collaborate with Engineering to embed security into every phase of the development process.
  • Perform security assessments of applications, identifying vulnerabilities and weaknesses though both automated and manual testing techniques.
  • Remediate security issues identified during assessments and collaborate with Engineering teams to implement effective fixes and countermeasures.
  • Design and implement in-house security tools that will enhance security detection capabilities to provide our Engineering partners with high fidelity findings and actionable insights.
  • Monitor emerging trends and developments in the application security space, including tools, technologies and best practices to guard against emerging threats and vulnerabilities.
  • Collaborate with compliance teams to ensure that application security practices adhere to FedRAMP requirements and where necessary implement necessary controls, documentation and processes in support of maintaining compliance.
  • Participate in the annual audit process by providing documentation, evidence and expertise related to Rubrik’s application security practices.
  • Work with development teams, operations, governance, and other stakeholders to document security guidance, processes and standards for Rubrik products and services
  • Coordinate penetration testing / bug bounty programs and support the remediation effort

Ideal Background:

  • Bachelor’s degree required; BS or MS in Computer Science, Information Technology, or a related field
  • 8+ years’ experience in application security, with experience across SDLC activities such as threat modeling, secure code review, vulnerability management, and penetration testing
  • Prior experience working in environments with NIST 800-53, NIST 800-171 controls or FedRAMP requirements
  • Knowledge of regulatory guidelines and standards such as FedRAMP, SOC2, ISO 27001.
  • Broad knowledge of web, application, and cloud attack vectors and exploits
  • Comprehension in multiple programming languages (Python, Go, Scala, C/C++, Javascript/Typescript)
  • Experience with Bazel or similar build systems for secure build processes and dependency management in application development
  • Working experience with CI/CD pipeline, containerization (Kubernetes, Docker, etc) and MicroServices
  • Experience with deploying and securing SaaS applications and cloud environments at scale
  • Deep security subject matter expertise in at least one major public cloud provider (AWS, GCP, Azure) 
  • Understanding of application security maturity model frameworks and how to apply them
  • Team player, ability to establish priorities, deal with conflicts, work independently, proceed with objectives and can-do attitude
  • Ability to lead, guide and manage Application Security services and deliver

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Rubrik

View company profile →