Rubrik is a leading Security and AI Operations Company focused on data protection and cyber resilience. The Application Security Engineer will be responsible for ensuring Rubrik's products meet high security standards and collaborating with various stakeholders to enhance security in product development.
Responsibilities:
- Integrate security controls and practices into Rubrik’s secure SDLC and collaborate with Engineering to embed security into every phase of the development process
- Architect the agentic scaffolding, including containment boundaries and intervention points, required to govern and scale AI agents performing machine-speed vulnerability triage, research, and remediation
- Perform security assessments of applications, identifying vulnerabilities and weaknesses through both automated and manual testing techniques
- Carry out detailed analysis of identified vulnerabilities to ensure high fidelity findings are provided to Engineering teams
- Assist in identifying and implementing frictionless "shift-left" strategies to seamlessly and proactively prevent vulnerabilities earlier in the SDLC
- Aid in the collection, management and reporting of key Application Security metrics to track progress and identify trends
- Analyze and harden existing applications, automation, and deployment processes
- Participate in security design reviews and threat modeling of proposed products and feature releases
- Work with development teams, operations, governance, and other stakeholders to document security guidance, processes and standards for Rubrik products and services
Requirements:
- Bachelor's degree required; BS or MS in Computer Science, Information Technology, or a related field
- 5+ years' experience in Application Security, with experience across SDLC activities such as threat modeling, secure code review, vulnerability management, and penetration testing
- Proven track record of utilizing frontier models to build agentic workflows that scale security operations, successfully automating the end-to-end lifecycle of vulnerability discovery and remediation
- Knowledge of regulatory guidelines and standards such as FedRAMP, SOC2, ISO 27001 etc
- Broad knowledge of web, application, and cloud attack vectors and exploits
- Comprehension in multiple programming languages (Python, Go, Scala, C/C++, Javascript/Typescript)
- Working experience with CI/CD pipeline, containerization (Kubernetes, Docker, etc) and MicroServices
- Working knowledge of at least one major public cloud provider (AWS, GCP, Azure)
- Understanding of application security maturity model frameworks and how to apply them
- Foundational knowledge of deploying and securing SaaS applications and cloud environments
- Team player, ability to establish priorities, deal with conflicts, work independently, proceed with objectives and can-do attitude
- A self-starter with excellent critical thinking and problem solving skills
- Strong written and verbal communication skills