SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 212,800 - 319,200 / annual
Rubrik is seeking a Senior Manager to lead its Security Operations Center (SOC), including FedRAMP-authorized operations. This is a hands-on leadership role overseeing incident response, detection, monitoring, and a strategic AI transformation of the SOC.
You will manage SOC analysts across both commercial and FedRAMP-scoped teams, building a culture of collaboration and continuous learning. Key responsibilities include hiring, training, mentoring, and evaluating analysts; developing career paths and succession planning; and maintaining signal quality to reduce alert fatigue.
Operationally, you will direct 24/7 monitoring and coverage across shifts and regions, serve as Incident Manager for major security incidents, and drive continuous improvement of incident response playbooks, runbooks, and escalation procedures. You will ensure all processes meet FedRAMP compliance rigor.
A core focus is owning the AI SOC strategy and roadmap: deploying AI/ML and automation to reduce L1 toil, evaluating and piloting AI-enabled tools (triage, investigation support, response automation), and building the SOC's ability to detect and defend against AI-enabled threat actors.
You will partner with Threat Operations to expand detection maturity and coverage as Rubrik's environment grows (cloud, SaaS, on-prem, FedRAMP systems), close detection gaps, reduce false positives, and keep detections aligned to threat intelligence and MITRE ATT&CK. You will feed incident findings back to drive continuous improvement and work with Security Engineering to enhance logging.
Strategically, you will set the direction and operating model for a modern SOC, own planning, budgeting, staffing, and resource allocation, and track key metrics (MTTD, MTTR, coverage, analyst workload). You will report regularly to the CISO and executive leadership on security posture and SOC performance, translating technical detail into business risk.
You will also support FedRAMP and other security audits through evidence collection, control validation, and remediation tracking, and maintain compliance and operational hygiene reporting for both commercial and FedRAMP environments.
REQUIREMENTS:
- 8+ years in security operations, incident response, or related field, including prior experience leading a SOC in a management or senior lead role
- Experience serving as an Incident Manager, leading incident investigations and coordinating across teams under pressure
- Experience building or maturing a SOC operating model: 24/7 coverage, playbooks, escalation processes
- Hands-on background in detection and response with fluency in SIEM/SOAR platforms and MITRE ATT&CK
- Experience managing and developing SOC analysts: hiring, mentoring, performance management
- Track record of defining and reporting SOC metrics (MTTD, MTTR, coverage) to technical and executive audiences
- Experience supporting compliance frameworks and audits (FedRAMP, SOC 2, ISO 27001, or similar); direct FedRAMP experience is a strong plus
- Strong communication skills and comfort briefing executive leadership and cross-functional stakeholders
- Must be a U.S. citizen, as required for FedRAMP responsibilities
PREFERRED:
- Direct experience evaluating, piloting, or rolling out AI/ML-driven security tooling (AI-assisted triage, automated investigation, GenAI copilots)
- Experience operating within or leading a FedRAMP-authorized security function
- Comfort with cloud-native and SaaS environments in addition to traditional on-prem infrastructure
- Certifications: GCIH, GCFA, CISSP, or CISM