Full-Time

Senior Machine Learning Engineer

Rubrik

Rubrik

5,001-10,000 employees

Cloud data management and enterprise backup

Compensation Overview

$188.5k - $282.7k/yr

+ Bonus + Equity

Palo Alto, CA, USA

In Person

Bachelor's, Master's, PhD

Category
AI & Machine Learning (1)
Required Skills
Python
PyTorch

Get referred to Rubrik

See people who can refer or advise you

Requirements
  • A Bachelor's degree (or higher) in Computer Science, Machine Learning, Computer Engineering, Statistics, or a closely related technical field is required.
  • 2+ years of professional ML experience with demonstrable end-to-end production ownership; you have taken models from training to serving real customer traffic and stayed accountable for them through post-launch iteration.
  • Proficiency in Python and PyTorch for production-grade training and evaluation.
  • Hands-on experience training, fine-tuning, or distilling language models or classifiers in a production setting, including supervised fine-tuning and at least one preference-optimization technique (DPO, RLAIF, or RLHF).
  • Production experience with serving frameworks (such as vLLM, SGLang, TensorRT-LLM, or equivalent), including optimization involving continuous batching, KV-cache strategy, and inference-time quantization.
  • Experience designing closed-loop ML systems, including the eval, telemetry, data-curation, and synthetic-data infrastructure that turns production signals back into training data and the next model release.
  • Comfort operating at production scale, debugging models that handle high queries-per-second in safety-critical request paths where errors have customer-visible consequences.
Responsibilities
  • Owning the full training lifecycle for the SLMs and classifiers in SAGE's real-time enforcement path, including base-model selection, supervised fine-tuning, preference optimization (DPO/RLAIF), and distillation from frontier teacher models.
  • Training anomaly and action-severity models that catch novel agent-side attack patterns at real-time decision latency, such as supply-chain compromises or emergent destructive behaviors not covered by any explicit policy.
  • Severity scores route the highest-impact events to Agent Rewind for precise remediation.
  • Designing adversarial training pipelines like purpose-built adversarial agents and automated red-teams whose outputs feed directly into the next training run, turning every discovered weakness into a permanent model improvement.
  • Pushing the pareto frontier of accuracy, latency, and cost for governance-specific tasks through deliberate post-training choices (LoRA, quantization-aware training, distillation recipes, GRPO, etc.) and validating the wins on production traffic patterns.
  • Designing multi-stage inference pipelines that handle both real-time enforcement and high-throughput batch workloads while processing billions of tokens daily across Global 2000 customer agent fleets.
  • Optimizing live deployments through shared GPU pools, KV-cache-aware routing, continuous batching, FP8/INT8 quantization, and speculative decoding to minimize inference cost while holding sub-second P99 SLOs.
  • Building serving-layer infrastructure that lets SAGE block agent prompts, responses, and tool calls in real time without becoming a latency bottleneck.
  • Owning canary, shadow, and A/B traffic patterns so new model variants are validated against live customer traffic before they take enforcement decisions.
  • Designing automated data curation pipelines that mine live customer environments for high-value per tenant training examples, such as long-tail violations, near-miss policy edges, or novel agent behaviors, and routing them back into the training loop for each customer.
  • Building automated policy back-testing by replaying historical agent traffic against new model and policy versions to catch regressions and recommend policy improvements before customer-visible deployment.
  • Building online evaluation systems for live model decisions, including shadow scoring, drift detection, calibration monitoring, and policy-coverage gap analysis.
  • Generating synthetic data using frontier teachers with evaluation that confirms synthetic data improves downstream quality, not just dataset size.
  • Building memory and context harnesses that fuse data sensitivity, identity, and historical agent behavior into real-time enforcement decisions to ensure SAGE reasons from each customer's specific context.
  • Mining agent insights across millions of sessions to surface security gaps, which are then turned into new policy proposals, refinements to existing policies, and signals about upstream issues across the agent ecosystem.
  • Building feedback loops that turn production decisions, customer-flagged false positives, and missed violations into one-click natural-language policy refinements to drive false-positive rates down without sacrificing recall.
  • Diagnosing model failures end-to-end and distinguishing data, training-recipe, architecture, and serving-layer root causes so fixes land in the right layer the first time.
  • Providing technical leadership on a pillar of the SAGE model stack, mentoring engineers ramping into ML, and shaping the team's technical roadmap.
  • Partnering with Product Management, customer-facing teams, and security analysts to translate customer agent-governance requirements into well-scoped modeling problems, and pushing back when ML is the wrong tool.
  • Communicating model behavior, tradeoffs, and limitations clearly to non-ML stakeholders, such as product managers and enterprise security leaders, so model decisions are made with full context.
  • Collaborating with Agent Cloud platform, security engineering, and AI research teams to integrate new SLMs into the real-time enforcement path with the right latency, observability, rollback, and tenancy guarantees.
Desired Qualifications
  • Deep background in AI safety and red-teaming, including hands-on experience with adversarial ML, prompt injection defense strategies, and automated evaluation suites for enterprise-grade LLM safety.
  • Expertise in model evaluation methodology, specifically building "LLM-as-judge" pipelines, calibration monitoring, and adversarial benchmarks that surface the subtle failure modes static metrics often overlook.
  • Experience with context-fusion and retrieval systems that synthesize disparate signals into high-fidelity model decisions.
  • Production experience with low-latency inference for streaming or safety-critical request paths where model throughput and P99 SLOs are paramount.
  • Mastery of label-efficient training and data mining, utilizing weak supervision, active learning, and embedding-based retrieval to surface the production examples that drive the most significant quality improvements.
  • Hands-on knowledge distillation experience, transferring capabilities from frontier teacher models to specialized, small-scale student models for production serving.
  • Familiarity with the agentic ecosystem, including tool-use frameworks, model gateway architectures, and autonomous agent patterns.
  • Active open-source contributions to mainstream ML training, serving, or evaluation libraries.

Rubrik provides data management and backup software that helps businesses protect their information across on-premises and cloud environments. The platform works by automating backup policies and integrating with services like AWS and Azure to ensure that data is stored in a format that cannot be encrypted or deleted by unauthorized users. Unlike traditional backup tools, Rubrik focuses on ransomware recovery by guaranteeing that backups remain untouched, allowing for near-instant restoration of databases and virtual machines. The company's goal is to simplify data protection while reducing the time and cost required for organizations to recover from cyberattacks.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

Palo Alto, California

Founded

2014

Get referred to Rubrik

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • FY2026 revenue rose 48% to $1.32 billion; subscription ARR hit $1.46 billion.
  • Sophos launched Rubrik-powered Microsoft 365 backup on June 1, 2026.
  • Wipro and Rubrik launched Enterprise Resilience as a Service on August 5, 2026.

What critics are saying

  • Commvault, Cohesity, Veeam, and Druva crowd Rubrik's core backup market.
  • Rubrik's AI governance launch at Black Hat 2026 expands execution risk before validation.
  • FY2027 revenue guidance grows 27%-28%, slower than FY2026's 48%; deceleration invites multiple compression.

What makes Rubrik unique

  • Rubrik pairs immutable backups with Agent Rewind, covering ransomware and agentic mistakes.
  • AWS European Sovereign Cloud support and London EMEA HQ deepen regulated-market footing.
  • Okta, Microsoft Entra ID, NetApp, and VMware integrations reduce deployment friction.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Yahoo Finance
Aug 11th, 2026
Rubrik director sold 721 shares at $75 ahead of stock rally

Rubrik director Yvonne Wassenaar sold 721 shares of Class A Common Stock at $75 on 3 August 2026, according to an SEC Form 4 filing. Following the sale, Wassenaar continues to directly hold 3,917 shares. The transaction appears routine rather than concerning. Rubrik reported strong performance in its fiscal 2027 first quarter in June, with revenue climbing 39% to $387.1 million. The company forecasts second-quarter sales between $395 million and $397 million. Rubrik has trailing twelve-month revenue of $1.4 billion but recorded a net loss of $288.6 million during the same period. The data security company serves large enterprises requiring robust protection solutions across hybrid and multi-cloud environments.

IT Pro
Aug 7th, 2026
Rubrik teams up with Wipro to launch 'enterprise resilience as a service' scheme.

Rubrik teams up with Wipro to launch 'enterprise resilience as a service' scheme. The new joint service aims to sharpen enterprise cyber resilience and recovery capabilities Rubrik and Wipro have announced a new partnership to build an 'enterprise resilience as a service' (ERaaS) scheme to counter growing cybersecurity threats. According to the duo, the consultancy-led scheme is designed to help enterprises "prevent, withstand, and rapidly recover from cyber and operational disruptions". As part of the service, Rubrik and Wipro will offer continuous resilience posture assessments alongside automated recovery capabilities. These will be delivered through Wipro's WINGS platform, a suite of AI-powered IT management tools. "Together with Rubrik's zero trust recovery capabilities, ERaaS will identify critical systems, map impact tolerances, and quickly establish recovery priorities," said Satish Yadavalli, Wipro's global business head for cloud, infrastructure, and security services. Latest Videos FromIT Pro Embracing green energy for data centers by migrating to Iceland Shifting away from the UK helped Shearwater GeoServices adopt green energy for low-cost, clean seismic processing 0 seconds of 1 minute, 21 seconds Volume 0% "Leveraging our consulting capabilities, we will work closely with clients to translate these insights into resilience-by-design architectures, governance frameworks, and recovery playbooks." In addition to AI tools, the ERaaS scheme will integrate Rubrik's cyber and data resilience platform. This provides enterprises with features such as immutable data protection, roll-back capabilities, and clean recovery points. Long-term, Rubrik said the aim is to sharpen enterprise resilience efforts, moving strategies away from a "periodic, incident-triggered function" to a proactive posture. Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

FilingReader
Aug 5th, 2026
Wipro and Rubrik launch resilience service.

Wipro and Rubrik launch resilience service. August 5, 2026 at 10:09 AM UTC - By FilingReader AI Wipro Limited has partnered with Rubrik to launch Enterprise Resilience as a Service, a consulting-led solution designed to help enterprises recover from cyber and operational disruptions. The service shifts organizations away from traditional backup models by operating as a continuously managed capability across technology and business processes. The offering leverages Wipro's AI-powered delivery platform and Rubrik's data resilience platform to automate recovery workflows. It integrates Zero Trust recovery capabilities, which include immutable protection, rollback of AI-driven changes, and threat-aware recovery. Wipro will use its consulting expertise to help clients identify critical systems and establish recovery priorities, translating these insights into resilience architectures. This report was generated by FilingReader's AI system from regulatory filings and company disclosures. To request a correction, contact [email protected]

iTWire
Aug 5th, 2026
Rubrik unveils Agent Identity to secure agentic actions in real-time.

Rubrik unveils Agent Identity to secure agentic actions in real-time. Jennifer Smith, Content Manager | Published 5 Aug 2026 Rubrik Agent Cloud now monitors every agent and MCP server, controls access per tool call, and remediates unwanted actions Today at the Black Hat Conference, Rubrik (NYSE: RBRK), the Security and AI Operations Company, announced Rubrik Agent Identity, a powerful new AI-based solution to manage and control AI agents' access and permissions, addressing a key obstacle in enterprise agent deployment. AI agent deployments are rapidly evolving, with the potential to execute complex, automated workflows across SaaS applications, databases, and APIs at unprecedented speed and scale. Yet most organisations lack the capability to monitor and control agent access and actions at the necessary speed and scale. Rubrik Agent Identity is designed to reduce operational vulnerabilities that stem from agent identities by allowing customers to both monitor every agent and model context protocol (MCP) at runtime using AI, and to deliver just-in-time permissions per tool call. "Agents are no longer just synthesising information, they are acting on behalf of employees and using the access models we built for humans. Static credentials were never designed for autonomous actors," said Dev Rishi, General Manager of AI at Rubrik. "Agent Identity lets enterprises decide who can do what with agents and enforces it at each tool call, at the moment of action, with scoped, short-lived access. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute." Control AI Identity with AI Modern AI creates an unmonitored "shadow workforce" that bypasses traditional security boundaries. Because these systems often rely on broad, static credentials, a single compromised agent can trigger destructive, system-wide actions with zero visibility. According to recent data from Rubrik Zero Labs, 86% of global IT and security leaders expect AI agents to outpace their organisation's security guardrails within the next year, while only 23% report full visibility into the agents operating in their environments. Rubrik Agent Identity, delivered as an expansion of the Rubrik Agent Cloud platform, establishes a unified "Govern, Control, and Prove" model across the entire agent lifecycle. The new solution operates alongside Rubrik's established SAGE governance framework, and now provides four distinct Rubrik Agent Cloud pillars: * Agent Observability: Monitor every agent and MCP at runtime. * Agent Identity: Control access per tool call at speed and scale using fine-tuned AI. * Agent Runtime Security: SAGE intent-driven governance to enforce policies and detect agent errors in real time. * Agent Rewind: Undo agentic mistakes. Secure the Moment of Action: Rapid Posture Hardening in Three Steps The architecture introduces key capabilities designed to help enterprises rapidly harden their agentic identity posture: * Build an Agent Identity Inventory: Discover and catalog all active AI agents, MCP servers, skills, and plugins to immediately eliminate unmonitored shadow AI. * Delegate Least-Privilege Access: Scope access to specific MCP servers and tools by user and group using On-Behalf-Of federation, extending existing enterprise identity structures rather than replacing them. * Enforce with Just-In-Time Tokens: Eliminate standing permissions entirely by minting scoped, short-lived tokens per tool call, ensuring access is validated at runtime before execution. Enforce Runtime Access Control at the MCP Gateway To prevent malicious or erroneous actions before they occur, every MCP tool call must clear three distinct checkpoints before execution: * Behavioural Analysis: SAGE semantically evaluates the requested tool call, its context, input parameters, and potential operational impact before execution. * Access Policy Enforcement: Run-time security policies are verified at the infrastructure layer, enriched with SAGE context. * Identity Verification: The agent session is authenticated, and the system mints a short-lived token specifically scoped to that single tool call. If an unauthorised action is attempted, such as a write or modification without an explicit policy scope, the transaction is immediately blocked before execution. For unexpected agent behaviours, Agent Rewind instantly and precisely undoes an autonomous agent's destructive action, addressing the widespread industry concern where 88% of leaders worry about meeting recovery time objectives as agentic threats scale. Strategic Ecosystem Integrations Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identities to autonomous machine actors without requiring new directories. The MCP Gateway provides a unified security checkpoint for all API-based and MCP resources across the enterprise. Ultimately, Rubrik Agent Identity advances the company's vision to deliver Agentic Cyber Resilience to our customers, helping them keep pace with machine-speed attacks powered by frontier AI models.

GovConExec International
Jul 29th, 2026
Zscaler, Schwarz Digits collaborate to provide sovereign Zero Trust SASE service in Europe.

Zscaler, Schwarz Digits collaborate to provide sovereign Zero Trust SASE service in Europe. * Zscaler and Schwarz Digits have launched a sovereign SASE offering designed for organizations in Europe * The service combines Zscaler's Zero Trust Exchange platform with the STACKIT sovereign cloud infrastructure * Customer data will be hosted in German data centers and managed under European sovereignty requirements Zscaler, a company offering zero trust security, and Schwarz Group's IT and digital division, Schwarz Digits, have collaborated to provide a sovereign zero trust secure access service edge, or SASE, offering for customers in Europe. What does the zscaler-schwarz Digits partnership provide? The offering integrates Zscaler's Zero Trust Exchange platform with STACKIT, the sovereign cloud operated by Schwarz Digits, Zscaler said Tuesday. The service, hosted in German data centers and managed by STACKIT, is designed to help organizations address cybersecurity requirements while maintaining digital sovereignty. It covers deployment, operation, management and support of a cybersecurity cloud platform intended to protect customer data and operations from cyber threats while aligning with European legal requirements. The service is available to organizations in all industries and is tailored for mission-critical operations in defense, public administration, financial services and healthcare. Why are European customers seeking sovereign technology? The partnership comes as European organizations face growing cybersecurity challenges, including threats driven by artificial intelligence. The companies also pointed to regulatory requirements such as the Network and Information Security Directive 2, the Digital Operational Resilience Act and the AI Act as factors elevating the importance of cybersecurity and operational resilience. The announcement follows growing demand for sovereign technology offerings throughout Europe. Earlier this month, Atos launched Atos Sovereign Cloud, a service designed to help governments, defense organizations, healthcare providers and other regulated organizations maintain control over data, operations and compliance requirements while modernizing their IT environments. Rubrik also recently made its Security Cloud offering available on the AWS European Sovereign Cloud to support cyber resilience and compliance with DORA and NIS2 requirements. NiCE announced plans to make its agentic AI-powered customer experience platform available on the same AWS service to support data residency and digital sovereignty requirements for regulated organizations.