About The Position

Rubrik is hiring a Senior Manager to lead our Security Operations Center (SOC), including our FedRAMP-authorized environment. This role is responsible for incident response, detection, and monitoring within the SOC. The successful candidate will be tasked with enhancing the SOC's maturity, expanding coverage, and developing a strategy for AI integration. A key focus will be driving the AI SOC transformation to scale coverage, reduce alert fatigue, and allow analysts to concentrate on complex investigations. The role also includes owning SOC leadership for the FedRAMP environment, ensuring the same operational rigor is applied within that compliance boundary.

Requirements

  • 8+ years in security operations, incident response, or a related field.
  • Prior experience leading a SOC, including incident response, in a management or senior lead role.
  • Experience serving as an Incident Manager, leading incident investigations and coordinating across teams under pressure.
  • Experience building or maturing a SOC operating model: 24/7 coverage, playbooks, escalation processes.
  • Hands-on background in detection and response, with fluency in SIEM/SOAR platforms and common attacker tactics and techniques (MITRE ATT&CK).
  • Experience managing and developing SOC analysts, including hiring, mentoring, and performance management.
  • A track record of defining and reporting SOC metrics (MTTD, MTTR, coverage, etc.) to both technical and executive audiences.
  • Experience supporting compliance frameworks and audits (FedRAMP, SOC 2, ISO 27001, or similar).
  • Strong communication skills and comfort briefing executive leadership and cross-functional stakeholders on posture and incidents.
  • Must be a U.S. citizen, as required for FedRAMP responsibilities.

Nice To Haves

  • Direct FedRAMP experience is a strong plus.
  • Direct experience evaluating, piloting, or rolling out AI/ML-driven security tooling: AI-assisted triage, automated investigation, GenAI copilots for SOC work, and similar.
  • Experience operating within or leading a FedRAMP-authorized security function.
  • Comfort with cloud-native and SaaS environments in addition to traditional on-prem infrastructure.
  • Certifications like GCIH, GCFA, CISSP, or CISM are a plus.

Responsibilities

  • Hire, train, mentor, and evaluate SOC analysts across commercial and FedRAMP-scoped teams.
  • Build a culture of collaboration, ownership, and continuous learning within the SOC.
  • Ensure analysts are working on real alerts and not chasing noise.
  • Develop career paths, training programs, and succession planning for SOC analysts.
  • Direct 24/7 monitoring and ensure consistent coverage across shifts and regions.
  • Serve as Incident Manager for major security incidents, leading response and collaborating across InfoSec teams.
  • Drive continuous improvement of SOC processes, including incident response playbooks, runbooks, and escalation procedures.
  • Ensure incident response processes meet FedRAMP rigor.
  • Own the roadmap for AI-enabled SOC capabilities: AI-assisted triage, investigation support, response automation.
  • Deploy AI/ML and automation to reduce L1 toil and alert fatigue.
  • Work with Threat Operations and Security Engineering to evaluate, pilot, and roll out AI SOC tools.
  • Enable the safe use of AI tools internally and build the SOC's ability to detect and defend against AI-enabled threat actors.
  • Partner with Threat Operations to grow detection maturity and expand coverage across cloud, SaaS, on-prem, and FedRAMP systems.
  • Work with Threat Operations to close detection gaps, reduce false positives, and align detections with current threat intelligence and MITRE ATT&CK.
  • Feed incident findings back to Threat Operations for continuous improvement of detection logic.
  • Close the loop with Security Engineering to incorporate additional logging based on incident and investigation data.
  • Set the direction and operating model for a modern SOC.
  • Own planning, budgeting, staffing, and resource allocation, including for the FedRAMP-scoped team.
  • Track and report on key metrics like MTTD, MTTR, analyst workload, and detection coverage.
  • Evolve the operating model as the company scales.
  • Make strategic decisions on SIEM/SOAR platforms and automation.
  • Own the SOC's technology roadmap, including build-vs-buy decisions, vendor evaluation, and integration with the broader security stack.
  • Provide regular updates to CISO and executive leadership on security posture, SOC performance, and notable threats.
  • Represent the SOC in cross-functional and executive settings, translating technical detail into business risk.
  • Support FedRAMP and other security audits: evidence collection, control validation, remediation tracking for the SOC's scope.
  • Build and maintain compliance and operational hygiene reporting for commercial and FedRAMP environments.
  • Ensure SOC processes and documentation meet regulatory and contractual requirements.

Benefits

  • Bonus potential
  • Equity
  • Benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service