Trigger
Rubrik launched Rubrik AI on June 9. The press release names autonomous agent guardrails as "auditable, attributable, and reversible." The Director, Product Design posting updated July 15 on Greenhouse. Palo Alto. $250K–$351K. ~60-person design team, 30+ in HQ.
Product launch creates an entirely new interaction surface. Refreshed Director search follows five weeks later. That sequence is a company staffing the design problem the launch just made real. High confidence.
Window
Greenhouse metadata shows a projected offer accept of September 1. Six weeks. Recruiter Noopur Mer posted about this role within the last week, calling it a strategic leadership hire for "major future AI investments." The July 15 update is a refreshed slate, not a stale listing.
Move this week. Six weeks to projected offer accept. The slate is fresh.
What this trigger means for the design org
Read Rubrik's product blog before you do anything else. Customers define outcomes — clean recovery, blast-radius containment — and the agent handles sequencing at machine speed. The blog states the design constraint plainly:
"If an action cannot be undone, Rubrik AI surfaces the decision for human review instead of proceeding unilaterally."
That surface did not exist at Rubrik six weeks ago. The moment between autonomous execution and irreversible action is now a product surface. It needs a designer. The Director posting confirms it: the role asks for someone who can work across "AI, immutable backups, and ransomware defense."
The signal that matters more. A Staff PM role is being hired to own the AI Platform's governance, guardrails, failure handling, and multi-tool orchestration. The design leader who fills this Director seat walks into a PM counterpart already framing the same problem space. That is a mandate with infrastructure behind it, not a wish list.
Your angle
Narrative fit: Rubrik used "auditable, attributable, and reversible" to describe guardrails for autonomous agent actions. Your Trust essay names the exact mechanism: the Decision Gate handoff, where automation stops and human accountability begins. You did not borrow their language. They arrived at yours independently. No other candidate in this search can claim that convergence.
Lead with the Trust essay. Open with the vocabulary match. Then name Thermo Fisher: five autonomous agents running continuously across nine pharma sites, one non-negotiable human gate for batch QA regulatory release, $20M+ in recovered margin. Different domain. Identical design architecture. Rubrik AI routing irreversible recovery actions to human review is the same structural pattern you already built and shipped.
TinyFish gives you current-role context: you are building enterprise AI agents in production, working through agent traces, auditability, and governance daily. That is practitioner depth. Do not cite TinyFish work as portfolio proof.
Who to contact
Primary — Oded Klimer, VP/Head of Design
LinkedIn. Credited as VP/Head of Design on Rubrik's Red Dot award entry and named on both iF Design submissions. Posted about Rubrik Forward saying Rubrik put design "front and center" during its leap into the AI threat landscape. Likely the hiring manager or the hiring manager's direct report. Anneka Gupta is CPO; the Director likely reports to Klimer, but nothing confirms this. Ask early.
Public fingerprint: Two signals worth reading together. The Forward post tells you he values design influence at the strategic layer during a product pivot. The Red Dot and iF submissions tell you something different: a VP Design who enters work for international design awards cares about external craft recognition as a measure of team quality. Expect him to evaluate your portfolio for design rigor, not just strategic narrative.
Warm path: None found. Cold outreach.
Secondary — Mukul Bisht, Senior Director, Product Design
LinkedIn. Credited on both Red Dot and iF entries. Posted ~3 months ago about hiring a Senior Manager to partner with him, PM, and Engineering on cyber resilience and AI security products. Could be a peer to this Director role or the direct hiring manager. Probe carefully before positioning relative to him.
Procedural — Noopur Mer, Recruiter
LinkedIn. Listed as contact on the posting (noopur.mer@rubrik.com). Posted within the last week promoting this role. Parallel channel, not a substitute for reaching the design buyer.
Outreach messages
Warm message to Oded Klimer
(assumes introduction has been made)
Oded — thank you for making time. The reason I asked [mutual connection] for the introduction: Rubrik AI's guardrails language — "auditable, attributable, and reversible" — describes the exact design problem I published a framework for this year in "Trust Is the New Interface." I built the production version of that pattern at Thermo Fisher, where five autonomous agents ran across nine pharma sites with one non-negotiable human gate for regulatory release. I'd love 20 minutes on how your team is approaching the control surface layer for Rubrik AI.
Cold message to Oded Klimer
Subject: The irreversibility surface in Rubrik AI
Oded — your Forward post about Rubrik putting design front and center during the AI threat landscape shift caught my attention, because the hardest design problem in that shift is the one your team just created: the surface where autonomous recovery stops and asks a human whether to proceed. I published a framework for exactly this — the Decision Gate handoff — in "Trust Is the New Interface" earlier this year, and I built the production version at Thermo Fisher: five agents across nine pharma sites, one human gate for regulatory release, $20M+ in recovered margin. I'm currently Head of Product at TinyFish (enterprise web agents, Series A), building agent auditability and governance daily. Would 20 minutes on how you're approaching the guardrails layer be useful?
Cold message to Noopur Mer
Subject: The guardrails design layer in Rubrik AI
Noopur — I saw your post about the Director of Design role and the AI investment mandate. The reason I'm reaching out directly rather than applying cold: Rubrik AI's "auditable, attributable, and reversible" guardrails describe a design problem I've already named and solved. My published essay "Trust Is the New Interface" maps the Decision Gate — the moment autonomous action stops for human review — and I built this pattern at Thermo Fisher across nine pharma sites with $20M+ in recovered margin. I'm currently leading product at TinyFish (enterprise AI agents), so this is my daily work. Happy to send my portfolio and the essay. What's the best way into the conversation?
What not to say
- Do not frame this as a "cybersecurity design" opportunity. The posting never uses "cybersecurity" in the role description. Rubrik's design team thinks in terms of enterprise UX and AI interaction patterns.
- Do not lead with Alibaba or B2B platform scale. This role is about the AI control surface problem. Alibaba is secondary evidence of enterprise credibility if it comes up in conversation. Nothing more.
The non-obvious thing
The Staff PM posting for Rubrik Security Cloud AI Platform describes the PM's job as designing "systems for AI agents to make good decisions, act safely, and scale across the product surface," including governance, guardrails, permissions, multi-tool orchestration, and failure handling. This role is being hired alongside the Director of Design.
The guardrails layer is being staffed as a product surface right now. Competing candidates will pitch "I can help you think about AI trust." You pitch "I've published the framework your PM counterpart is already building toward, and here's what the design layer looks like." One of those conversations ends with a next step.
Warning signs
Glassdoor reports 3.1 work-life balance across 898 reviews. Indeed shows 2.9. A January 2026 PM review describes "confusing strategic clarity" and leadership messaging that doesn't translate into actionable direction. Company-wide signals, not design-specific.
The design org itself shows strong maturity markers: Aura design system winning iF 2026, structured weekly critiques, 30+ patents, VP of Design in seat. Ask directly in conversation how the AI product roadmap translates into design team priorities and headcount. Not a reason to hold.
- Rubrik's UX Research hiring: The Senior User Researcher II posting says the role will "create and evolve research agents and research platforms" and accelerate learning velocity through AI, which tells you the design org is building AI into its own practice, not just the product.
- Mukul Bisht's Senior Manager search: His LinkedIn post from roughly three months ago about hiring a Senior Manager for cyber resilience and AI security products may clarify whether this Director role sits alongside or above his team.
- Gowri Rao Krishnamurthy's launch demo: Her Rubrik AI stage demo post describes IT admins realizing "the routine is covered" so they can focus on higher-value work, which is the clearest public articulation of how Rubrik frames the human-agent trust shift to customers.
- Amplitude's parallel mandate: The Head of Product Design posting asks for a leader to define human-agent workflows across an AI-native analytics platform, which is the same Decision Gate problem in a different domain and worth preparing as a comparison point if Rubrik asks how the framework applies beyond cyber.

