Full-Time

Application Security Engineer

Rubrik

Rubrik

5,001-10,000 employees

Cloud data management and enterprise backup

Compensation Overview

$150.2k - $225.4k/yr

+ Bonus + Equity

Remote in USA

Remote

Category
IT & Security (1)
Required Skills
Kubernetes
Fedramp
Microsoft Azure
Python
JavaScript
Threat modeling
Docker
TypeScript
Vulnerability Analysis
Microservices
AWS
Go
Scala
penetration testing
C/C++
DevOps
Google Cloud Platform

Get referred to Rubrik

Find people who can refer or advise you

Requirements
  • Bachelor’s degree required; BS or MS in Computer Science, Information Technology, or a related field
  • 5+ years’ experience in Application Security, with experience across SDLC activities such as threat modeling, secure code review, vulnerability management, and penetration testing
  • Proven track record of utilizing frontier models to build agentic workflows that scale security operations, successfully automating the end-to-end lifecycle of vulnerability discovery and remediation
  • Knowledge of regulatory guidelines and standards such as FedRAMP, SOC2, ISO 27001 etc.
  • Broad knowledge of web, application, and cloud attack vectors and exploits
  • Comprehension in multiple programming languages (Python, Go, Scala, C/C++, Javascript/Typescript)
  • Working experience with CI/CD pipeline, containerization (Kubernetes, Docker, etc) and MicroServices
  • Working knowledge of at least one major public cloud provider (AWS, GCP, Azure)
  • Understanding of application security maturity model frameworks and how to apply them
  • Foundational knowledge of deploying and securing SaaS applications and cloud environments
  • Team player, ability to establish priorities, deal with conflicts, work independently, proceed with objectives and can-do attitude
  • A self-starter with excellent critical thinking and problem solving skills
  • Strong written and verbal communication skills
Responsibilities
  • Integrate security controls and practices into Rubrik’s secure SDLC and collaborate with Engineering to embed security into every phase of the development process.
  • Architect the agentic scaffolding, including containment boundaries and intervention points, required to govern and scale AI agents performing machine-speed vulnerability triage, research, and remediation.
  • Perform security assessments of applications, identifying vulnerabilities and weaknesses through both automated and manual testing techniques.
  • Carry out detailed analysis of identified vulnerabilities to ensure high fidelity findings are provided to Engineering teams.
  • Assist in identifying and implementing frictionless "shift-left" strategies to seamlessly and proactively prevent vulnerabilities earlier in the SDLC.
  • Aid in the collection, management and reporting of key Application Security metrics to track progress and identify trends.
  • Analyze and harden existing applications, automation, and deployment processes
  • Participate in security design reviews and threat modeling of proposed products and feature releases
  • Work with development teams, operations, governance, and other stakeholders to document security guidance, processes and standards for Rubrik products and services

Rubrik provides data management and backup software that helps businesses protect their information across on-premises and cloud environments. The platform works by automating backup policies and integrating with services like AWS and Azure to ensure that data is stored in a format that cannot be encrypted or deleted by unauthorized users. Unlike traditional backup tools, Rubrik focuses on ransomware recovery by guaranteeing that backups remain untouched, allowing for near-instant restoration of databases and virtual machines. The company's goal is to simplify data protection while reducing the time and cost required for organizations to recover from cyberattacks.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

Palo Alto, California

Founded

2014

Get referred to Rubrik

Find people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2027 revenue hit $387M, raising full-year guidance to $1.65B driven by AI security demand.
  • $500M UK investment over five years establishes London as European headquarters for data sovereignty needs.
  • Cognizant embeds Rubrik Agent Cloud into Neuro AI platform for real-time policy enforcement in regulated sectors.

What critics are saying

  • AWS, Azure, and GCP may natively embed AI agent security, making Rubrik Agent Cloud redundant by 2029.
  • Stock overvalued at 5.62X forward P/S versus 3.67X industry median, risking sell-off if AI growth stalls.
  • Strata.io acquisition integration with Okta and Microsoft Entra could fail, leaving authentication gaps during AI rollout.

What makes Rubrik unique

  • Rubrik AI executes multi-step cyber recovery workflows end-to-end in minutes instead of weeks.
  • Agent Rewind for Claude Code undoes unintended AI agent actions via immutable external snapshots.
  • Identity Resilience from Strata.io acquisition maintains authentication continuity when primary IdP fails automatically.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Yahoo Finance
Apr 11th, 2026
Rubrik lands AHA Preferred Cybersecurity Provider deal, targeting 5,000 US hospitals

Rubrik has been named an American Hospital Association Preferred Cybersecurity Provider, granting access to nearly 5,000 member hospitals through an exclusive Cyber Resilience Bundle. The deal offers identity recovery, Microsoft 365 protection and AI-driven services to help hospitals maintain operations during cyberattacks. The AHA endorsement strengthens Rubrik's healthcare credentials, particularly following its recent Microsoft Defender integration for identity threat detection. However, the company continues to face losses and premium valuation concerns. Rubrik's narrative projects $2.4 billion revenue and $268.7 million earnings by 2029, requiring 21.5% annual revenue growth. Cautious analysts forecast roughly 24.3% annual growth to $2.3 billion by 2029 with no profitability, citing concerns about ongoing reinvestment needs and competitive pressure limiting progress towards profitability.

Yahoo Finance
Apr 10th, 2026
Rubrik's Agent Cloud enters AI security market, faces competition from CrowdStrike and Palo Alto Networks

Rubrik has launched Rubrik Agent Cloud (RAC), extending its platform into AI security to monitor, govern and recover AI-driven workflows. The technology addresses emerging risks from AI agents, including identity misuse and vulnerabilities, by enforcing policies and detecting threats. RAC strengthens Rubrik's land-and-expand strategy, allowing existing customers to adopt it as an additional module whilst increasing contract value. Early integrations with Microsoft Copilot and Amazon Bedrock enhance adoption potential. The Zacks Consensus Estimate projects 21.79% revenue growth for fiscal 2027. The move intensifies competition with CrowdStrike and Palo Alto Networks, both offering AI-powered security solutions. CrowdStrike's AI-native Falcon platform and Palo Alto's Prisma AIRS and AgentiX products position them as strong rivals in the AI security space.

Yahoo Finance
Mar 24th, 2026
Rubrik integrates with Microsoft Defender to accelerate identity attack recovery

Rubrik announced a new integration with Microsoft Defender at RSAC 2026. The partnership combines Microsoft Defender's real-time identity threat detection with Rubrik's automated identity rollback and recovery capabilities, enabling faster response to identity-based attacks. The integration allows organisations to reverse malicious identity changes and restore infrastructure in hours rather than days. "Detection is only half of the battle," said Anneka Gupta, Rubrik's Chief Product Officer. "By combining Microsoft Defender's threat detection with Rubrik Identity Resilience, we give security and IAM teams the power to move from a detected compromise to a trusted, recovered state in hours, instead of days." The announcement was made at the RSA Conference 2026.

Business Wire
Mar 23rd, 2026
Rubrik unveils SAGE, first AI governance engine for real-time autonomous agent control

Rubrik has launched its Semantic AI Governance Engine (SAGE), the data security industry's first AI governance engine designed to secure and control autonomous agents in real time. SAGE powers Rubrik Agent Cloud, replacing static manual oversight with intent-driven governance for enterprise AI deployment. The system uses Rubrik's custom Small Language Model to interpret the semantic meaning of policies rather than relying on keyword searches. Key features include semantic policy interpretation, adaptive policy improvement and integrated remediation through Rubrik Agent Rewind. In benchmarking tests, Rubrik's custom SLM processed messages five times faster than OpenAI's GPT-5.2 whilst achieving higher accuracy in detecting policy violations. The technology addresses the governance bottleneck currently stalling enterprise AI deployment by providing real-time command centre capabilities for agentic operations.

Rubrik
Mar 23rd, 2026
Microsoft and Rubrik integration delivers complete identity attack response.

Microsoft and Rubrik integration delivers complete identity attack response. Microsoft Defender and Rubrik Identity Resilience create a unified detection-to-recovery offering; customers achieve trusted recovery in hours instead of days SAN FRANCISCO - March 23, 2026 - Rubrik (NYSE: RBRK), the security and AI operations company, today announced a new integration with Microsoft Defender at RSAC 2026, enabling organizations to move from identity threat detection to rapid remediation and trusted recovery. The integration connects Microsoft's real-time identity threat detection with Rubrik's automated identity rollback and recovery capabilities, helping organizations respond faster to identity-based attacks. Identity has become the primary target for modern cyberattacks. According to Rubrik Zero Labs research, 90% of IT and security leaders say identity-driven cyberattacks are their organization's top concern. Yet most security tools stop at detection, leaving organizations to manually investigate malicious changes and restore compromised identity systems. "Detection is only half of the battle," said Anneka Gupta, Chief Product Officer at Rubrik. "Organizations need the ability to quickly and surgically reverse malicious identity changes and completely restore their infrastructure. By combining Microsoft Defender's threat detection with Rubrik Identity Resilience, we give security and IAM teams the power to move from a detected compromise to a trusted, recovered state in hours, instead of days." With this integration, organizations can extend Microsoft Defender detections directly into Rubrik's identity recovery workflows, allowing teams to investigate incidents, reverse malicious identity changes, and restore trust across hybrid environments. Joint Rubrik and Microsoft Defender customers can now: * Understand attack impact faster by correlating threat alerts with identity changes. * Reverse malicious identity modifications without performing full domain restores. * Restore trusted identity states using immutable recovery points. * Maintain visibility across hybrid identity environments, including Active Directory and Entra ID. The integration builds on Rubrik's continued investment and broader vision for Identity Resilience, focused on ensuring identity systems remain trusted, available, and recoverable in the face of cyberattacks, operational disruptions, and evolving compliance requirements. Over the past 15 months, Rubrik has rapidly expanded its identity capabilities, introducing recovery for Active Directory and Entra ID, expanding protection to multi-identity provider environments including Okta, and launching Identity Resilience capabilities that help organizations investigate incidents and reverse malicious changes. The company has also expanded ecosystem integrations with leading security platforms including CrowdStrike Falcon Identity Protection and now Microsoft Defender, connecting threat detection with automated remediation and trusted recovery. For more on how Rubrik is redefining identity security, read more here. About Rubrik Rubrik (NYSE: RBRK) is the Security and AI Operations Company. The company's data security platform secures and recovers data from cyber threats and operational disruptions. Rubrik has been recognized as a Leader in the Gartner(R) Magic Quadrant(TM) for Enterprise Backup and Recovery Software Solutions for two consecutive years and is trusted by over 6,600+ customers across the globe, including world-renowned enterprises and government organizations. For more information, visit www.rubrik.com and follow @rubrikInc on X (formerly Twitter). Media Contact Meghan Fintland Head of Global PR 925.785.9192 [email protected] Press inquiries.