Senior Director, Governance, Risk & Compliance
RubrikAbout the role
About the Information Security Team
Rubrik’s Information Security Team is charged with safeguarding Rubrik’s digital assets and customer data through proactive security measures, innovative solutions, and rigorous compliance practices. We strive to foster a culture of security awareness, mitigate risks effectively, and uphold the trust of our customers and stakeholders. We play a critical role in enabling the company to achieve its strategic objectives while safeguarding its reputation and ensuring the trust of its stakeholders.
This multifaceted team, has a range of responsibilities including:
- Security Operations: This team focuses on monitoring the company's networks, systems, and endpoints for potential security incidents. They use advanced tools to detect, analyze, and respond to threats in real-time.
- Incident Response: This group is tasked with quickly mitigating security breaches or incidents that may occur. They coordinate with other teams to contain and remediate any issues while minimizing impact.
- Governance, Risk, and Compliance (GRC): This team ensures that Rubrik adheres to industry regulations and standards related to information security. They manage audits, assess risks, and implement policies and procedures to maintain compliance.
- Security Engineering: Engineers in this team design and implement security solutions for Rubrik’s infrastructure and products. They may develop tools, configure security systems, and perform security assessments.
- Security Awareness and Training: Educating employees about cybersecurity best practices is crucial. This team creates training programs and awareness campaigns to help all staff understand their role in maintaining security.
- Threat Intelligence: By monitoring external threats and trends, this team provides proactive insights that help enhance Rubrik’s defenses against emerging cyber threats.
- Security Architecture: Architects design the overall security infrastructure and framework for Rubrik, ensuring that all systems are built with security in mind from the ground up.
- Risk Management: This team assesses and prioritizes security risks to the organization, helping to allocate resources effectively to address the most critical vulnerabilities.
The team works collaboratively across departments to protect the company's assets, maintain trust with customers, and uphold high standards of security in all operations.
Role & Responsibilities
Rubrik is actively recruiting for a Senior Director for Governance, Risk & Compliance (GRC), reporting directly to the Vice President & Chief Information Security Officer. In this role, you will enable and transform the risk management, compliance and security governance capabilities and resources of Rubrik. Rubrik is investing in these areas to address the evolving cybersecurity threat landscape, as well as regulatory compliance requirements as the company continues to grow.
The Senior Director, GRC role is a critical position within the organization and has responsibilities from a technology and process perspective across the organization globally. Working closely with the stakeholders across the company, this position will be responsible for continuing to build and enhance the GRC portfolio of efforts to raise the overall security and compliance posture for Rubrik.
This role is part of the Information Security leadership team and manages a global organization of 25+ people.
How will you make impact?
- In this role, you will be directly responsible for implementing, maintaining and improving policies, procedures and internal controls to assure compliance with applicable regulatory and legal requirements as well as industry best practices. You will drive risk analysis for internal and external third-party risk assessments by designing controls and implementing industry best practice processes for teams and technologies utilized across the organization. You will work across multiple frameworks and regulatory standards including, but not limited to, NIST CSF, ISO, GDPR, SOX, PCI, FedRamp, SOC2 etc.
- You will liaise with all business groups including but not limited to Finance, Legal, Audit, Engineering, IT, Product, Support, Marketing and Sales and other stakeholders globally to implement new solutions and processes as well as document and remediate outstanding issues.
- Under the general direction of the CISO, the role is responsible for project management and implementation of controls to build and enhance the GRC program. Additionally, you will be responsible for informing leadership of issues resulting from risk analysis and determining potential solutio
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s