Information Security Senior Analyst, PubSec Product Certification & Compliance
RubrikAbout the role
About the team:
The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our systems, provides awareness education to teams on security best practices for data protection, and ensures data sharing relationships with third parties in order to securely protect Rubrik information.
About the role:
At Rubrik, our mission is to secure the world's data. Within our Information Security team, the Public Sector Compliance Team plays a critical role in unlocking strategic US government markets. We're the team that builds trust by proving our platform's integrity against the highest standards of security.
We are looking for a proactive, technically-minded problem-solver to join us. This InfoSec Senior Analyst role is a unique opportunity for a talented individual from a background in engineering, technical program management, IT, or systems analysis to pivot their career into the high-demand field of cybersecurity compliance. You will leverage your existing skills in a new context, learning the intricacies of U.S. Public Sector security controls while making a tangible impact on our products and business from day one.
Where can you make an impact?
You'll be a bridge between our technology and the stringent requirements of the U.S. government. You won't just be checking boxes; you'll be deconstructing complex technical standards, testing our product(s) against security benchmarks, and working directly with engineering to ensure our platform is hardened and compliant. This is a hands-on, mostly tactical role where your analytical abilities and technical curiosity will be paramount. Success is measured by your ability to effectively identify control gaps and collaborate with others to facilitate their remediation.
For example, you might be tasked with running security evaluation tests for our DISA STIG, collaborating with engineers on meeting FIPS 140-2 cryptographic requirements, or managing the work plan for our next third-party Common Criteria evaluation. You will develop expertise rapidly, learning from top talent and growing into a go-to resource for public sector security at Rubrik.
What you'll do:
- Drive Key Compliance Activities: Take ownership of critical work assignments for essential government certifications such as Common Criteria, DISA STIG, DoDIN APL, Section 508 accessibility, and secured personnel facility visit coordination.
- Perform Technical Analysis & Testing: Conduct hands-on security testing and evaluation (ST&E) against product security baselines or standards. You will identify gaps, document findings, and partner with internal teams to close gaps and drive remediation.
- Translate Requirements into Action: Work closely with Product Management and Engineering to translate complex compliance standards (like NIST SP 800-171 / CMMC) into clear, actionable Jira tickets and development requirements.
- Develop Essential Documentation: Author and contribute to definitive compliance artifacts, including gap analyses, test plans, security control traceability matrices (SCTM), hardening guidance, and sections of our System Security Plans.
- Become a Subject Matter Expert: Develop a deep understanding of selected Rubrik products and how to configure and operate them securely, becoming a trusted advisor on hardening best practices for federal environments.
Experience you'll need:
We encourage you to apply even if you don't meet every single requirement. We value aptitude, a relentless drive to adapt, learn, and contribute, and a commitment to excellence in all the work you perform.
- Education: Bachelor’s degree or equivalent (preferably in a relevant field); supporting certifications (e.g., Security+, CISSP, CISA) a plus
- 5+ years of experience in a technical role such as Software/Systems Engineering, IT Infrastructure, Technical Program Management, Solutions Engineering, Backup Administration, or a similar field. Direct compliance experience is a plus, but not a prerequisite for a candidate with strong, transferable skills.
- Technical Aptitude: You have a proven ability to learn and understand complex technical subjects. You enjoy digging into how things work and are comfortable with concepts related to software configuration, networking, operating systems (Linux preferred), AI, and enterprise software.
- Analytical Problem-Solver: You are skilled at breaking down large, complex problems (like a government standard) into smaller, m
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s