Senior Manager, Security Operations Center

Rubrik Job Board•Palo Alto, CA
•$212,800 - $319,200•Remote

About The Position

Rubrik is seeking a Senior Manager to lead its Security Operations Center (SOC), including its FedRAMP-authorized environment. This role is responsible for incident response, detection, and monitoring. The successful candidate will be tasked with enhancing the SOC's capabilities, including strengthening detection and incident response, expanding coverage in a complex environment, and developing a strategy for AI integration. A key focus will be driving the AI SOC transformation, scaling coverage, reducing alert fatigue, and enabling analysts to focus on complex investigations. The role also involves owning SOC leadership for the FedRAMP environment, ensuring the same rigor in detection, incident response, and operations within that compliance boundary.

Requirements

  • 8+ years in security operations, incident response, or a related field.
  • Prior experience leading a SOC, including incident response, in a management or senior lead role.
  • Experience serving as an Incident Manager, leading incident investigations and coordinating across teams under pressure.
  • Experience building or maturing a SOC operating model: 24/7 coverage, playbooks, escalation processes.
  • Hands-on background in detection and response, with fluency in SIEM/SOAR platforms and common attacker tactics and techniques (MITRE ATT&CK).
  • Experience managing and developing SOC analysts, including hiring, mentoring, and performance management.
  • A track record of defining and reporting SOC metrics (MTTD, MTTR, coverage, etc.) to both technical and executive audiences.
  • Experience supporting compliance frameworks and audits (FedRAMP, SOC 2, ISO 27001, or similar).
  • Strong communication skills and comfort briefing executive leadership and cross-functional stakeholders on posture and incidents.
  • Must be a U.S. citizen, as required for FedRAMP responsibilities.

Nice To Haves

  • Direct experience evaluating, piloting, or rolling out AI/ML-driven security tooling: AI-assisted triage, automated investigation, GenAI copilots for SOC work, and similar.
  • Experience operating within or leading a FedRAMP-authorized security function.
  • Comfort with cloud-native and SaaS environments in addition to traditional on-prem infrastructure.
  • Certifications like GCIH, GCFA, CISSP, or CISM are a plus.
  • Direct FedRAMP experience is a strong plus.

Responsibilities

  • Hire, train, mentor, and evaluate SOC analysts across both commercial and FedRAMP-scoped teams.
  • Build a culture of collaboration, ownership, and continuous learning within the SOC.
  • Ensure signal quality and analyst experience by focusing analysts on real alerts.
  • Develop career paths, training programs, and succession planning for SOC analysts.
  • Direct 24/7 monitoring and ensure consistent coverage across shifts and regions.
  • Serve as Incident Manager for major security incidents, leading response and collaborating across InfoSec teams.
  • Drive continuous improvement of SOC processes, including incident response playbooks, runbooks, and escalation procedures.
  • Ensure incident response processes meet FedRAMP requirements.
  • Own the roadmap for AI-enabled SOC capabilities, including AI-assisted triage, investigation support, and response automation.
  • Deploy AI/ML and automation to reduce L1 toil and alert fatigue.
  • Work with Threat Operations and Security Engineering to evaluate, pilot, and roll out AI SOC tools.
  • Enable the safe use of AI tools internally and build the SOC's ability to detect and defend against AI-enabled threat actors.
  • Partner with Threat Operations to grow detection maturity and expand coverage across cloud, SaaS, on-prem, and FedRAMP systems.
  • Work with Threat Operations to close detection gaps, reduce false positives, and align detections with current threat intelligence and MITRE ATT&CK.
  • Feed incident findings back to Threat Operations for continuous improvement of detection logic.
  • Collaborate with Security Engineering to incorporate additional logging based on incident and investigation data.
  • Set the direction and operating model for a modern SOC.
  • Own planning, budgeting, staffing, and resource allocation, including for the FedRAMP-scoped team.
  • Track and report on key metrics like MTTD, MTTR, analyst workload, and detection coverage.
  • Evolve the operating model as the company scales.
  • Make strategic decisions on SIEM/SOAR platforms and automation.
  • Own the SOC's technology roadmap, including build-vs-buy decisions, vendor evaluation, and integration.
  • Provide regular updates to CISO and executive leadership on security posture, SOC performance, and notable threats.
  • Represent the SOC in cross-functional and executive settings, translating technical detail into business risk.
  • Support FedRAMP and other security audits, including evidence collection, control validation, and remediation tracking for the SOC's scope.
  • Build and maintain compliance and operational hygiene reporting for both commercial and FedRAMP environments.
  • Ensure SOC processes and documentation meet regulatory and contractual requirements.

Benefits

  • bonus potential
  • equity
  • benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service