About the Role
Our mission is to protect, defend, and secure the company's products, infrastructure, and data by building highly available, scalable, and extensible security solutions and services. We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk-Based Vulnerability Management (RBVM) systems, transforming how we identify, prioritize, and remediate exposure across a massive digital footprint.
You will drive technical excellence across our vulnerability management landscape, from on-prem, cloud, container security to corporate endpoint hygiene. As a Staff Engineer, you will be a technical visionary and mentor, leading the transition toward Continuous Threat Exposure Management and AI-driven remediation workflows that operate at enterprise scale.
What You Will Do
- RBVM Platform Architecture: Design and scale Security Posture Management tools and platforms to provide a unified, risk-scored view of vulnerabilities across on-prem, cloud, containers, VMs, and endpoints.
- Automation & Orchestration: Build automated remediation workflows and systems that will reduce median response times for emerging threats and scale across decentralized teams.
- Technical Strategy: Lead "Shift-Left" initiatives by integrating vulnerability scanning into development workflows, CI/CD pipelines, and infrastructure provisioning to enforce security policies consistently across all asset types, including cloud resources, endpoints, and applications.
- AI/ML Innovation: Leverage LLMs and AI agents for automated triage, impact analysis, and generating context-aware remediation instructions for service owners across the infrastructure.
- Vulnerability Governance: Partner with Compliance and IT to mature vulnerability standards, SLAs, and risk exception processes across the global digital estate.
- Vulnerability Analysis: Provide deep security subject matter expertise to analyze complex vulnerabilities, assess true risk, and drive informed decisions on remediation verdicts, false positives, and risk acceptance.
- Cross-Functional Collaboration: Partner with IT, product, and operations teams to integrate security posture improvements across the entire environment.
Basic Qualifications
- 7+ years of industry experience in software development, with a focus on large-scale security or infrastructure engineering.
- Expertise in building distributed systems and high-availability security platforms using Golang, Java, or Python.
- Proven track record of designing and operating vulnerability management tools at scale.
- Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines.
- Experience leading cross-functional security initiatives and mentoring senior engineering staff.
Preferred Qualifications
- Hands-on experience developing Risk-Based Vulnerability Management (RBVM) frameworks and automated prioritization logic.
- Knowledge of AI/ML applications in security, specifically for vulnerability triage or large-scale data analysis.
- Experience with External Attack Surface Management (EASM) and tracking internet-facing asset exposure.
- Familiarity with Software Supply Chain Security (SSCS), including SBOM and internal package registries.
For New York City, NY-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For Seattle, WA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For Sunnyvale, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
About UsReady to Ride?
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.
Skills Required
- 7+ years of industry experience in software development, focused on large-scale security or infrastructure engineering
- Expertise building distributed systems and high-availability security platforms using Golang, Java, or Python
- Proven experience designing and operating vulnerability management tools at scale
- Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines
- Experience leading cross-functional security initiatives and mentoring senior engineering staff
- Hands-on experience developing Risk-Based Vulnerability Management frameworks and automated prioritization logic
- Knowledge of AI/ML applications in security, vulnerability triage, or large-scale data analysis
- Experience with External Attack Surface Management and tracking internet-facing asset exposure
- Familiarity with Software Supply Chain Security, SBOMs, and internal package registries
Uber Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Uber and has not been reviewed or approved by Uber.
-
Parental & Family Support — Policies provide a minimum of fully paid parental leave for all parents and financial support for fertility, adoption, and surrogacy, with added credits to ease the transition. Programs extend to family medical leave and parenting support resources, indicating depth beyond baseline offerings.
-
Healthcare Strength — Healthcare coverage is described as comprehensive across many countries, with medical, dental, vision, life, disability, and mental health benefits, plus allowances where direct plans are not available. Wellness programs and reimbursements further reinforce access to care.
-
Wellbeing & Lifestyle Benefits — Monthly ride and meal credits, free office meals/snacks, fitness stipends, onsite gyms, and wellbeing reimbursements create meaningful everyday value. Home‑office stipends, travel medical coverage, and counseling support round out lifestyle-oriented perks.
Uber Insights
What We Do
We are Uber. The go-getters. The kind of people who are relentless about our mission to help people go anywhere and get anything. Movement is what we do. It’s our lifeblood. It runs through our veins. It’s what gets us out of bed each morning. It pushes us to constantly reimagine how we can move better. For you. For all the places you want to go. For all the things you want to get. For all the ways you want to earn. Across the entire world. In real-time. At the incredible speed of now.
Why Work With Us
We welcome people from all backgrounds who seek the opportunity to help build a future where everyone and everything can move independently. If you have the curiosity, passion, and collaborative spirit, work with us, and let’s move the world forward, together.
Gallery









