Senior Manager - Commercial Compliance

Rubrik
Palo Alto CAPosted 26 March 2026

Job Description

About the team: The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our assets, provides awareness education to teams on security best practices for data protection, and ensures data governance and data sharing relationships with third parties to securely protect Rubrik information. About the role: The Senior Manager of Commercial Compliance is a hands-on, working manager responsible for leading Rubrik’s commercial compliance program through continuous monitoring, control execution oversight, and evidence-based reporting. This role reports to and partners closely with the Senior Director of GRC and cross-functional peers in Risk Management, Security Governance, Public Sector Compliance, and Customer Trust to develop and execute strategy that continuously strengthens Rubrik’s security posture. This position is primarily accountable for managing Rubrik’s Common Control Framework (CCF) and the end-to-end lifecycle of controls (design, implementation, testing/monitoring, evidence management, issue remediation, and continuous improvement). The Senior Manager will also lead support for customer audits and due diligence requests, and will drive the maintenance and achievement of key security certifications as outcomes of a strong, scalable compliance program. As a working manager, this leader will directly contribute to deliverables while also managing global resources (employees and/or contractors) to ensure consistent execution across regions and time zones. What you'll do: Lead continuous compliance monitoring activities, including control health reporting, metrics, and executive-ready status updates to GRC leadership. Own and evolve the Common Control Framework (CCF), including control rationalization, mapping to applicable standards/frameworks, and alignment with business and technology changes. Manage the control lifecycle: control design/updates, operationalization, testing, evidence collection, deficiency tracking, and remediation partnership. Partner with control owners across the organization to drive timely and high-quality control performance and evidence readiness. Coordinate and support customer audits, security questionnaires, and compliance-related customer inquiries in collaboration with Customer Trust and other stakeholders. Drive program execution to maintain and achieve security certifications/attestations (e.g., SOC 2, ISO 27001, etc.), including readiness planning and audit support. Collaborate with Risk Management, Security Governance, and Public Sector Compliance to align controls, risk treatment, and governance expectations across commercial and regulated requirements. Identify compliance program gaps and opportunities; prioritize improvements that increase automation, reduce audit burden, and improve scalability. Manage global compliance resources, setting priorities, developing talent, and ensuring consistent delivery across distributed teams. Experience you'll need: 8+ years of progressive experience in GRC, security/commercial compliance, audit, or related fields, including ownership of compliance programs in a SaaS/cloud or technology environment. 2+ years of people management experience, including leading distributed/global teams and/or managing contractors or managed service resources. Demonstrated experience managing a control framework and control lifecycle (design, implementation, testing, evidence, remediation) and operating a continuous compliance monitoring program. Hands-on experience supporting external audits and customer compliance engagements (e.g., SOC examinations, ISO audits, customer diligen ... (truncated, view full listing at source)
Apply Now

Direct link to company career page

AI Resume Fit Check

See exactly which skills you match and which are missing before you apply. Free, instant, no spam.

Check my resume fit

Free · No credit card

Share