Project Manager, Security Operations Portfolio - FedRAMP
See more jobs from Rubrik, Inc.about 2 months old
About the team:
The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our assets, provides awareness education to teams on security best practices for data protection, and ensures data governance and data sharing relationships with third parties in order to securely protect Rubrik information.
Rubrik is seeking a ninja-skilled Project Manager to organize, plan, schedule, and deliver on our dynamic portfolio of technical and cross-functional initiatives related to our government security programs and related risk remediation. The ideal candidate will take a pragmatic approach to ensuring continual progress across multiple overlapping assignments, holding themselves accountable for adding value through the project outcomes they drive and achieve.
The successful incumbent will be a hands-on, proactive self-starter who collaborates effectively with InfoSec leadership, Compliance, and our business partners across the organization. Getting things done here requires persistence in clearing obstacles, applying just the right level of project management rigor, and working consistently with a due sense of urgency and velocity.
A high-performing Project Manager in this environment is first and foremost a leader by influence who uses the PMBOK, but that’s only one of many tools in their arsenal. They must also bring security domain expertise, internal consulting skills, willingness to be an additional pair of hands at times, and a relentless focus on setting, managing, and meeting stakeholder expectations. Success means owning the initiatives and moving them through to completion vs. simply facilitating and documenting the work of others. You’ll need to know or learn the subject matter, look for other initiatives that might impact your assignments, and actively lead all assigned initiatives to success from launch to closure.
In addition to continually (re)prioritizing initiatives and executing on these priorities, the Project Manager is responsible for sprint and milestone planning using Jira, Confluence, backlog management, and ongoing status reporting to a variety of stakeholders and audiences.
A solid PM at Rubrik must do so much more than create and manage project schedules:
- bring disparate stakeholders to consensus on charter, priorities, and timing.
- drive organizational change and security maturity.
- address operational issues and processes needing improvement.
- define requirements and success criteria for targeted outcomes.
- move the needle on security remediation and risk reduction.
- handle project owner scope while getting leaders to handle service owner scope.
Reporting to the PMO Lead, this position will work responsively with multiple InfoSec Leaders to shape the plans and road map for InfoSec initiatives, ensuring accountability for timely completion of assigned and scheduled work. They will use solid communication and collaboration skills to manage stakeholder expectations and participation, and to resolve or escalate issues to keep things moving forward.
What You’ll Do:
- Drive multiple overlapping InfoSec initiatives in a hands-on Project Manager role.
- Define project plans and schedules to meet deadlines and timelines.
- Work with Management to address security maturity pain points and challenges.
- Implement projects using formal and informal tools and methods tailored to an appropriate degree of project management rigor.
- Lead, plan, execute, and control assigned InfoSec initiatives.
- Effectively influence and collaborate with others to achieve continual progress while effectively managing risks and changes.
- Manage milestones and complexities by leading through them.
- Anticipate issues so as to avoid them; escalate risks and blockers to leadership.
- Understand the landscape of related projects that may impact assigned initiatives.
Experience you’ll need:
- 5-8 years prior work experience in a similar role in a SaaS company of small to medium size.
- Experience working with public cloud and compliance initiatives.
- Knowledge of regulatory guidelines and standards such as SOC2, ISO 27001, FedRAMP, etc. FedRAMP experience preferred.
- Bias for action, especially in working through conflict or addressing ambiguity.
- Solid delivery skills as a project / program manager, handling concurrent initiatives.
- Pragmatic use of PMBOK / Project / Program Management/Agile best practices; applying these and other methods creatively to achieve targeted outcomes.
- Driven to organize, establish, and improve processes, balancing speed, efficiency, and effectiveness with internal customer involvement, consensus, and satisfaction.
- Superb interpersonal, verbal, and written communication skills with the ability to convey complex concepts to a broad range of technical and non-technical audiences.
- Familiarity with sprint planning and use of JIRA a plus
- Bachelor’s degree required; in Information Security, Information Technology Management, Engineering, Business Management, or a related field is preferred.
- PMP / PgMP / equivalent and CISSP / CISA / CISM or similar certification(s)
- Understanding of cloud security maturity model frameworks and how to apply them
- Strong written and verbal communication skills
Rubrik provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, Rubrik complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Security and Privacy Responsibilities:
This position carries special Security and Privacy Responsibilities for protecting the U.S. Federal Government’s interests:
- Know, acknowledge, and follow system-specific security policies and procedures;
- Protect data and individual privacy per requirements and regulations;
- Perform ongoing activities in compliance with service and contractual obligations;
- Participate in role-based training, completing assignments on a timely basis;
- Report security issues promptly, and aid investigation when needed;
- Support controlled changes and vulnerability remediation activities; and
- Work collaboratively with Information Security in designing, implementing, assessing or enhancing system-specific security and privacy controls.
Position Risk Designation:
This position carries duties and responsibilities involving the U.S. Federal Government’s interests. The selected incumbent may be subject to one or both of the additional background checks with periodic re-screening as noted below:
Position Risk Designation: Non-Sensitive, Low Risk, Tier 1
Incumbents without access to U.S. Government data may be required to complete Standard Form 85 and undergo a Tier 1 Investigation (T1) for non-sensitive positions of Low Risk. (Baseline screening; formerly National Agency Check and Inquiries (NACI)).
Position Risk Designation: Non-Sensitive, Moderate Risk, Tier 2 (Public Trust)
Incumbents with access to U.S. Government data may be required to complete Standard Form 85P and undergo Tier 2 (T2) Investigation for non-sensitive positions designated Moderate Risk.
Position Risk Designation:Moderate Risk Law Enforcement (CJIS)
When hired for a position where access to Moderate Risk criminal justice information is required, the employee must complete a fingerprint-based national criminal history background check within 30 days after the employee’s start date.
#LI-Remote
#LI-DNI
Join Us in Securing the World's Data
Rubrik (NYSE: RBRK) is on a mission to secure the world’s data. With Zero Trust Data Security™, we help organizations achieve business resilience against cyberattacks, malicious insiders, and operational disruptions. Rubrik Security Cloud, powered by machine learning, secures data across enterprise, cloud, and SaaS applications. We help organizations uphold data integrity, deliver data availability that withstands adverse conditions, continuously monitor data risks and threats, and restore businesses with their data when infrastructure is attacked.
Linkedin | X (formerly Twitter) | Instagram | Rubrik.com
Diversity, Equity & Inclusion @ Rubrik
At Rubrik we are committed to building and sustaining a culture where people of all backgrounds are valued, know they belong, and believe they can succeed here.
Rubrik's goal is to hire and promote the best person for the job, no matter their background. In doing so, Rubrik is committed to correcting systemic processes and cultural norms that have prevented equal representation. This means we review our current efforts with the intent to offer fair hiring, promotion, and compensation opportunities to people from historically underrepresented communities, and strive to create a company culture where all employees feel they can bring their authentic selves to work and be successful.
Our DEI strategy focuses on three core areas of our business and culture:
-
Our Company: Build a diverse company that provides equitable access to growth and success for all employees globally.
-
Our Culture: Create an inclusive environment where authenticity thrives and people of all backgrounds feel like they belong.
-
Our Communities: Expand our commitment to diversity, equity, & inclusion within and beyond our company walls to invest in future generations of underrepresented talent and bring innovation to our clients.
Equal Opportunity Employer/Veterans/Disabled
Rubrik is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
Rubrik provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Rubrik complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please contact us at [email protected] if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
EEO IS THE LAW - POSTER SUPPLEMENT