Senior Manager, Security Operations Center
Rubrik · Palo Alto, CA
About this role
## About the team The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to help teams develop secure software and protect data and systems with appropriate security controls. It also develops systems to monitor and respond to attacks, provides security best-practice awareness education, and ensures data governance and secure data sharing with third parties. ## About the role Rubrik is hiring a **Senior Manager** to lead the **Security Operations Center (SOC)**, including our **FedRAMP-authorized environment**. Incident response is at the core of what the SOC does—alongside detection and monitoring—and this role owns it end-to-end. You’ll inherit a SOC that has already grown in scale and maturity, and your job is to take it further: stronger detection and incident response, broader coverage as the environment becomes more complex, and a real strategy for **AI in the SOC**. Driving the AI SOC transformation is a core part of this role—setting the strategy for how AI enables the SOC by scaling coverage beyond headcount, reducing alert fatigue on L1 analysts, and giving analysts more time for complex investigations and incident response. You’ll also own SOC leadership for the FedRAMP environment, applying the same detection, incident response, and operational rigor within that compliance boundary. ## What you’ll do ### Team Leadership & Development - Hire, train, mentor, and evaluate SOC analysts across both commercial and FedRAMP-scoped teams. - Build a culture of collaboration, ownership, and continuous learning within the SOC. - Monitor signal quality and analyst experience so analysts work real alerts—not noise. - Develop career paths, training programs, and succession planning for SOC analysts. ### Monitoring & Incident Response - Direct **24/7 monitoring** and ensure consistent coverage across shifts and regions. - Serve as **Incident Manager** for major security incidents, leading response and collaborating across InfoSec teams as needed. - Drive continuous improvement of SOC processes, including incident response playbooks, runbooks, and escalation procedures. - Ensure incident response processes meet the extra rigor required for **FedRAMP**. ### AI SOC Strategy & Tooling - Own the roadmap for AI-enabled SOC capabilities: AI-assisted triage, investigation support, and response automation. - Deploy AI/ML and automation to reduce L1 toil and alert fatigue so analysts focus on complex investigations. - Partner with Threat Operations and Security Engineering to evaluate, pilot, and roll out AI SOC tools. - Enable safe internal use of AI tools while building the SOC’s ability to detect and defend against AI-enabled threat actors. ### Detection Tuning & Coverage Expansion - Partner with Threat Operations to grow detection maturity and expand coverage across cloud, SaaS, on-prem, and FedRAMP systems. - Close detection gaps, reduce false positives, and keep detections aligned to current threat intel and **MITRE ATT&CK**. - Feed incident findings back to Threat Operations to continuously improve detection logic. - Work with Security Engineering to bring in additional logging based on incident and investigation data. ### Strategy & Operations Management - Set direction and operating model for a modern SOC. - Own planning, budgeting, staffing, and resource allocation
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.