Staff Information Security EngineerWhat You'll DoWe are seeking a Staff Security Engineer to serve as a technical anchor across the Information Security organization. You will own the architectural direction of our Security Data platform while simultaneously driving cross-functional security initiatives that span multiple teams and domains. This is a high-leverage, hands-on role that blends deep technical execution with organization-wide influence - shaping how Rubrik detects, responds to, and learns from threats at scale.
You will be the go-to technical leader for complex, ambiguous problems that cut across team boundaries, setting standards and raising the engineering bar across SecEng.
Core ResponsibilitiesSecurity Data Platform - Architecture & OwnershipDefine and own the long-term architecture of Rubrik's Security Data infrastructure. Drive the evolution from SIEM-centric operations toward a composable Security Data Lake (Snowflake, BigQuery, Databricks), ensuring the platform is scalable, cost-efficient, and fit-for-purpose for SOC, Threat Detection, GRC, and Compliance workloads. Establish data quality standards, schema governance, and ingestion SLAs across all security telemetry pipelines.
Technical Leadership Across SecEngPartner with Threat Detection, Security Operations, GRC, Product Security, and Cloud Security teams to define shared platforms, resolve architectural dependencies, and drive alignment on cross-cutting technical decisions. Own the "how we build" as much as the "what we build."
Engineering Standards & EnablementDefine and champion engineering best practices across SecEng: code quality, observability, incident readiness, cost management, and security-by-design. Conduct architecture reviews for major initiatives across teams. Mentor Junior engineers, accelerating their technical growth through code reviews, design feedback, and pairing.
AI & Agentic Security AutomationLead the design and delivery of AI-driven security capabilities. Build and productionize AI agents that automate Tier 1/2 SecOps workflows - including alert triage, incident investigation, enrichment, and response. Evaluate and integrate LLMs and GenAI tooling to create force-multiplying capabilities across the security organization.
Strategic Cross-Team CollaborationDrive alignment across Engineering, Product, IT, and Legal on security platform roadmaps, data governance, and compliance requirements. Represent InfoSec in cross-functional technical forums. Translate ambiguous business requirements into concrete technical strategies that multiple teams can execute against.
Infrastructure & Platform EngineeringOwn the deployment and lifecycle of security tooling across cloud environments (AWS, GCP, Azure). Drive Terraform-based IaC practices, manage Kubernetes-based security sidecars and policies, and ensure platform reliability through SLOs and automated runbooks.
Security Operations - Escalation & OversightServe as the senior technical escalation point for complex Security Operations challenges: SIEM/SOAR health, major incident response, vendor evaluations, and architectural POCs. Drive post-incident technical reviews that produce durable improvements to detection and response capabilities.
Qualifications- Experience: 12+ years in Security Engineering, with deep expertise in Security Data Management, Detection Engineering, or Security Operations - and demonstrated impact beyond a single team or domain.
- Technical Breadth: Proven ability to drive architectural decisions across multiple security domains (e.g., SIEM, data platforms, cloud security, detection). Comfortable owning end-to-end technical strategy, not just implementation.
- AI Fluency: Demonstrated experience leveraging AI/LLMs to meaningfully improve SecOps outcomes - from rapid prototyping to production-grade agentic workflows.
- SIEM & SOAR Mastery: Deep, hands-on expertise with at least one enterprise SIEM (Splunk, Microsoft Sentinel, Elastic) and a SOAR platform (Splunk SOAR, Palo Alto XSOAR, or equivalent).
- Security Data Platforms: Proven experience architecting and operating large-scale data platforms (Snowflake, BigQuery, Databricks). Experience with platforms handling 50-100 TB/day is strongly preferred.
- Programming: Strong proficiency in Python; experience with data pipeline and orchestration frameworks (Spark,, Airflow, or equivalent).
- Cloud Infrastructure: Strong multi-cloud experience (AWS, GCP, Azure); IaC fluency with Terraform.
- Communication: Ability to synthesize complex technical topics for both engineering and executive audiences; experience influencing without authority across organizational boundaries.
Nice to Have- Experience defining or contributing to a Security Data strategy at the organizational level.
- Hands-on background in Threat Detection engineering (detection-as-code, MITRE ATT&CK coverage mapping).
- Familiarity with data mesh or open table formats (Iceberg, Delta Lake) in a security context.
- Experience leading or contributing to major security incident response (e.g., supply chain, nation-state, ransomware).
- Exposure to compliance frameworks (SOC 2, ISO 27001, FedRAMP) and how they intersect with security data retention and access controls.
- Background in building internal security platforms or developer-facing security tooling.
- Experience in container orchestration (Kubernetes/EKS/GKE) and CI/CD security integrations.
The minimum and maximum base salaries for this role are posted below; additionally, the role is eligible for bonus potential, equity and benefits. The range displayed reflects the minimum and maximum target for new hire salaries for the role based on U.S. location. Within the range, the salary offered will be determined by work location and additional factors, including job-related skills, experience, and relevant education or training.
US Pay Range
$212,800-$319,200 USD