Information Security Program Manager, Continuous Monitoring - FedRAMP
RubrikAbout the role
About The Team:
The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our systems, provides awareness education to teams on security best practices for data protection, and ensures data sharing relationships with third parties in order to securely protect Rubrik information.
About the role:
Our Public Sector Product Certification and Compliance Team is looking for a success-driven, US-based Program Manager to organize, plan, and execute on continuous monitoring and related compliance activities for Rubrik’s government cloud service offering(s). This mission-critical position will enhance, control, and execute our compliance monitoring, continuous assurance, and monthly reporting programs in accordance with Rubrik’s Continuous Monitoring strategy and policy for FedRAMP and other product certification frameworks.
Externally, this role represents Rubrik with FedRAMP and StateRAMP PMOs, DISA, our Government / Agency Partner(s), and our third party assessment organization (3PAO). Internally, this role collaboratively influences product, engineering, compliance, and risk road maps. The incumbent will help Rubrik accelerate and assure the growth of our govcloud service offerings through diligent continuous monitoring, timely government reporting, and security assessment & authorization activities for in-scope product certifications.
Our ideal candidate is a subject matter expert in FedRAMP, NIST SP800-53, NIST SP800-171, and Department of Defense Impact Level security requirements, with previous experience in assessment, authorization, and continuous monitoring activities for a Cloud Service Provider (CSP vs. Cloud Hosting Platform Provider). They will also need to bring a relentless focus and accountability for results, and excellent leadership, communication, decision-making, and collaboration skills.
What you'll be doing:
Program / Development
- Program Manager / Service Lead / Control Owner for Rubrik’s Continuous Monitoring (ConMon) Compliance capability, covering requirements for FedRAMP, DoD Impact Level, CJIS, and similar frameworks. Others will perform scanning, inventory, and flaw remediation; your role is to ensure that effective ConMon strategy, plans, and related procedures are compliantly in place and working effectively, and that system vulnerabilities are appropriately POA&M-documented, managed to remediation, reported compliantly, and addressed on a timely basis.
- Maintain the calendar of continuous monitoring activities covering weekly, monthly, quarterly, and annual compliance requirements for FedRAMP, DoD Impact Level, and similar programs.
- As our secondary/backup Information Systems Security Officer (ISSO), collaborate with a range of stakeholders from individual contributors to senior leadership to external parties including Agency Partners and/or Third Party Security Assessor (3PAO).
- Drive activities related to the remediation of technical security and compliance risks with cross-functional teams, including, but not limited to, engaging third party services, managing remediation projects, leading groups to consensus and action, assigning and tracking work items, producing reports, and escalating risks and issues.
- Serve as a subject matter expert and an integral member of the Public Sector Product Certifications and Compliance Team, cultivating strong relationships across the company to aid in program transparency, strategic consensus, expectation setting, risk and vulnerability awareness, and continual process improvement.
- Monitor changes in relevant regulations, laws, and industry standards to adapt the program accordingly. Identify challenges with emerging compliance requirements and best practices to sustain compliance as the landscape evolves.
Operations
- Working with the primary ISSO, write, maintain, and disseminate all or parts of Rubrik’s government Authorization Package(s) and related artifacts as a cohesive body of work, obtaining content and updates from Control Owners when needed and ensuring the package is correct, complete, and current.
- Manage the Plan of Action and Milestones (POA&M) workbook and use it to log and report vulnerability remediation status for Rubrik’s government cloud service offering(s).
- Package and submit monthly ConMon reporting with remediation evidence, and independently manage similar duties for FedRAMP, StateRAMP, Department of Defense and other Autho
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s