Enterprise Security Engineer - FedRAMP
Role details
Job location
Tech stack
Job description
The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our systems, provides awareness education to teams on security best practices for data protection, and ensures data sharing relationships with third parties in order to securely protect Rubrik information., Rubrik is seeking an Enterprise Security Engineer. In this role, you will be responsible for ensuring that Rubrik's Corporate Enterprise IT technologies are designed and implemented to the highest possible security standards. You will partner with a variety of stakeholders across the business to improve the Security posture of SaaS applications, integrations, identity and access, endpoints, wireless network, and IOT devices..
What you'll do** **:
-
Design and implement security standards across Identity (Okta), Endpoint (Windows, MacOS, Linux), Secrets Management (Vault, Lastpass) and Business Applications (Salesforce, Glean, etc).
-
Partner with IT and other organizations to improve the security posture of enterprise applications, integrations, and access to sensitive and business data.
-
Actively participate in evaluation, development, and management of security and compliance policies within IT management systems such as JAMF, inTune, etc.
-
Analyze and harden existing applications, infrastructure, automation, and deployment processes: CircleCI, Github workflows, Tines, Zapier, etc.
-
Work with Corp IT teams, operations, governance, and other stakeholders to draft security standards and implement monitoring, alerting, and governance.
-
Review and approve application security review requests to ensure new applications used by Rubrik and employees are secure, monitored, and security standards are enforced.
-
Support the SOC in analyzing applicable threats, vulnerabilities, controls, and residual risks.
-
Partner with Vulnerability Management and Threat Operations to drive remediation of critical vulnerabilities and detection of IOC's in the environment.
-
Actively monitor and manage EDR policies.
-
Partner with the organization to deploy technologies for AI usage and security.
-
Leverage AI tools and agents to improve team performance, enterprise security capabilities, and team efficiency - do more with less and faster., This position carries special Security and Privacy Responsibilities for protecting the U.S. Federal Government's interests:
-
Know, acknowledge, and follow system-specific security policies and procedures;
-
Protect data and individual privacy per requirements and regulations;
-
Perform ongoing activities in compliance with service and contractual obligations;
-
Participate in role-based training, completing assignments on a timely basis;
-
Report security issues promptly, and aid investigation when needed;
-
Support controlled changes and vulnerability remediation activities; and
-
Work collaboratively with Information Security in designing, implementing, assessing or enhancing system-specific security and privacy controls.
Requirements
-
6+ years experience in enterprise security, with hands on experience in administration and design across Windows, Mac, Okta and public cloud infrastructure
-
Broad knowledge of enterprise attack vectors and exploits in both end-user and IT Apps
-
Subject matter expertise in business applications, endpoint and Identity management
-
Deep understanding of endpoint systems, corporate networking including wi-fi and IT application systems (Salesforce, Mulesoft, Lastpass, etc)
-
Programming experience in PowerShell, Python, Go or Java
-
Experience with deploying and securing Enterprise applications and environments at scale
-
Security and administrative expertise in at least one major public cloud provider (AWS, GCP, Azure)
-
Understanding of corporate security maturity model frameworks and how to apply them
-
Strong written and verbal communication skills
-
Knowledge of regulatory guidelines and standards such as SOC2, ISO 27001, FedRAMP, etc.