Staff/sr Information Security Engineer

Rubrik Rubrik · Enterprise · Palo Alto, CA · Information Technology & Services

Staff/Sr Information Security Engineer responsible for the architectural direction of the Security Data platform and driving cross-functional security initiatives. This role will lead the design and delivery of AI-driven security capabilities, building and productionizing AI agents to automate SecOps workflows like alert triage and incident investigation, and evaluating LLMs/GenAI tooling. The role also involves defining and owning the long-term architecture of the Security Data infrastructure, establishing data quality standards, and championing engineering best practices across the SecEng organization.

What you'd actually do

  1. Define and own the long-term architecture of Rubrik's Security Data infrastructure.
  2. Partner with Threat Detection, Security Operations, GRC, Product Security, and Cloud Security teams to define shared platforms, resolve architectural dependencies, and drive alignment on cross-cutting technical decisions.
  3. Define and champion engineering best practices across SecEng: code quality, observability, incident readiness, cost management, and security-by-design.
  4. Lead the design and delivery of AI-driven security capabilities.
  5. Drive alignment across Engineering, Product, IT, and Legal on security platform roadmaps, data governance, and compliance requirements.

Skills

Required

  • Security Engineering
  • Security Data Management
  • Detection Engineering
  • Security Operations
  • Architectural decisions
  • Technical strategy
  • AI/LLMs
  • SecOps automation
  • Agentic workflows
  • SIEM
  • SOAR
  • Data platforms
  • Python
  • Multi-cloud (AWS, GCP, Azure)
  • Terraform
  • Communication
  • Influencing

Nice to have

  • Security Data strategy
  • Threat Detection engineering
  • data mesh
  • open table formats (Iceberg, Delta Lake)
  • major security incident response
  • compliance frameworks (SOC 2, ISO 27001, FedRAMP)

What the JD emphasized

  • deep expertise in Security Data Management, Detection Engineering, or Security Operations
  • demonstrated impact beyond a single team or domain
  • Proven ability to drive architectural decisions across multiple security domains
  • Comfortable owning end-to-end technical strategy, not just implementation
  • Demonstrated experience leveraging AI/LLMs to meaningfully improve SecOps outcomes
  • from rapid prototyping to production-grade agentic workflows
  • Deep, hands-on expertise with at least one enterprise SIEM
  • Proven experience architecting and operating large-scale data platforms
  • Experience with platforms handling 50–100 TB/day is strongly preferred
  • Strong proficiency in Python
  • Strong multi-cloud experience (AWS, GCP, Azure)
  • IaC fluency with Terraform
  • Ability to synthesize complex technical topics for both engineering and executive audiences
  • experience influencing without authority across organizational boundaries

Other signals

  • AI-driven security capabilities
  • AI agents that automate SecOps workflows
  • Evaluate and integrate LLMs and GenAI tooling