About the role
<h2>About the team:</h2> <p>The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our systems, provides awareness education to teams on security best practices for data protection, and ensures data sharing relationships with third parties in order to securely protect Rubrik information.</p> <h2>About the role:</h2> <p>Rubrik’s Security Operations Center (SOC) plays a strategic role in protecting customer and internal data, enabling Rubrik’s secure growth and maintaining its reputation as a trusted leader in data and AI security. The SOC is the first to respond to cyber security incidents, report on cyber threats, and recommend changes needed to further protect the organization.&nbsp;</p> <h2>What you'll do:</h2> <ul> <li>Monitor and respond to security alerts across Rubrik’s corporate network, endpoints, cloud, and SaaS environments.</li> <li>Rapidly detect and accurately identify signs of intrusions and other malicious activity.&nbsp;</li> <li>Manage the end-to-end incident response lifecycle, encompassing triage, deep-dive investigations, and remediation to ensure accurate identification of root causes and organizational impact.</li> <li>Partner with vulnerability management, FedRAMP, and engineering teams to assess threats, prioritize vulnerabilities, and drive timely remediation efforts.</li> <li>Collaborate with cross functional teams to drive resolution of events.</li> <li>Contribute to overall program maturity through providing feedback and ideas to refine and improve detection capabilities and response processes.</li> <li>Update and maintain accurate incident case attributes and investigation details.</li> <li>Reviewing, documenting, and updating existing SOC processes.</li> </ul> <h2>Experience you'll need:</h2> <ul> <li>Bachelor’s degree in Cybersecurity, Information Systems, or other related technical disciplines, or equivalent experience.</li> <li>3+ years of experience in Security Operations Center including security investigations and incident response.</li> <li>Relevant Security Certifications (SANS, CompTia, ISC2, etc.) preferred.</li> <li>Excellent communication and writing skills, with experience in direct written communication and report writing; effectively telling the details of what happened.</li> <li>Experience utilizing incident analysis and investigation techniques. Applying and optimizing playbo