Staff Security Engineer

Posted 3 Days Ago
Be an Early Applicant
3 Locations
In-Office
232K-258K Annually
Senior level
Logistics • Transportation • 3PL: Third Party Logistics
We reimagine the way the world moves for the better.
The Role
Perform penetration testing, threat modeling, security design reviews, and vulnerability validation across applications, APIs, infrastructure, cloud-native systems, and AI agents. Build AI-powered security automation, identify complex attack paths, and partner with engineering teams to improve security controls and eliminate vulnerability classes. Translate technical findings into actionable guidance and lead complex assessments across organizational boundaries.
Summary Generated by Built In

About the role and team: 


As a member of Uber’s Offensive Security team, you will work across multiple security disciplines to proactively identify and reduce risk in Uber’s most critical services and emerging technologies. You will perform security design reviews and threat modeling for critical services and AI agents, conduct hands-on penetration testing to validate real-world attack paths, and help build AI-powered automation that transforms how these security assessments are performed at scale. This role combines deep technical security expertise with an automation-first mindset, helping evolve traditional point-in-time assessments toward continuous, scalable security testing across Uber’s technology ecosystem.


This isn't a "set and forget" role. Our environment is fast-moving and the threats are constantly evolving. You will navigate the "messy" reality of hybrid cloud and distributed systems, conducting technical security design reviews as part of our secure software development lifecycle. We are looking for a technically curious engineer who thrives in ambiguity, takes extreme ownership of their work, and has the grit to stay ahead of sophisticated adversaries. If you are motivated by high-stakes challenges and want to build a more secure future for movement - this is where you’ll grow.


What you’ll do 

  • Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths.

  • Conduct security design reviews and threat modeling for AI agents and agentic systems, evaluating risks across models, tools, data, permissions, external integrations, and runtime behavior.

  • Design and build AI-powered automation for security design reviews, threat modeling, penetration testing, and vulnerability validation, increasing the scale, frequency, and depth of Offensive Security assessments.

  • Partner with engineering and security teams to translate offensive security findings into systemic improvements, helping eliminate vulnerability classes and strengthen security controls across Uber’s technology ecosystem.

  • Perform multi-disciplinary security design reviews of engineering proposals, analyzing cloud, infrastructure, application, and data-layer security.

  • Navigate complex design trade-offs to provide corrective guidance that improves the overall security posture of Uber’s products and services.

  • Collaborate with engineering teams across the company to analyze design documents and identify potential flaws before they reach production.

  • Translate technical security findings into actionable guidance for both engineering and non-technical stakeholders to ensure alignment and impact.

  • Conduct comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.

  • Champion engineering best practices and serve as a security ambassador, helping teams move fast while building with integrity and care.


Basic Qualifications 

  • 7+ years of professional experience in security engineering, threat detection, or client platform engineering.
  • Demonstrated ability to independently analyze complex, large-scale system designs, identify security risks and attack paths, and drive technical solutions across multiple services, systems, and dependencies.
  • Deep knowledge of threat modeling, vulnerability discovery and classification, security risk assessment, and offensive security methodologies, with experience applying them to complex production environments.
  • Extensive experience assessing the security of cloud-native services, microservices, distributed systems, APIs, or other large-scale production environments.
  • Proven ability to lead complex security assessments and influence engineering teams to implement security improvements across organizational and technical boundaries.
  • Experience applying AI/LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or other security engineering workflows.
  • Hands-on experience conducting penetration testing of complex applications, services, APIs, and infrastructure, including identifying, validating, and demonstrating exploitable vulnerabilities and attack paths.

Preferred Qualifications 

  • Master’s degree or PhD in a technical field and 10+ years of experience in a cybersecurity leadership or staff-level role.
  • Deep knowledge of Cybersecurity, Compliance, and Privacy, with experience chaining vulnerabilities and quantifying risks.
  • Experience collaborating with EMs, TPMs, and PMs on prioritization, headcount planning, and technical evaluation of team members.
  • Advanced expertise in leveraging AI/ML for security use cases and building device attestation or trust tooling at a global scale.
  • Strategic relationship builder: Proven ability to leverage collaborative relationships with legal, product, and engineering stakeholders to build trust and accomplish work.
Responsibilities

For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.


For Seattle, WA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.


For Sunnyvale, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.


For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.

About Us

Ready to Ride?

This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.

You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.

Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.

Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

Skills Required

  • 7+ years of professional experience in security engineering, threat detection, or client platform engineering
  • Ability to independently analyze complex, large-scale system designs, identify security risks and attack paths, and drive technical solutions across multiple services and dependencies
  • Deep knowledge of threat modeling, vulnerability discovery and classification, security risk assessment, and offensive security methodologies
  • Experience assessing cloud-native services, microservices, distributed systems, APIs, or other large-scale production environments
  • Ability to lead complex security assessments and influence engineering teams to implement security improvements
  • Experience applying AI, LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or security engineering workflows
  • Hands-on penetration testing experience across complex applications, services, APIs, and infrastructure
  • Master's degree or PhD in a technical field
  • 10+ years of experience in a cybersecurity leadership or staff-level role
  • Deep knowledge of cybersecurity, compliance, and privacy, including vulnerability chaining and risk quantification
  • Experience collaborating with engineering managers, technical program managers, and product managers on prioritization, headcount planning, and technical evaluations
  • Advanced expertise leveraging AI/ML for security use cases and building device attestation or trust tooling at global scale
  • Ability to build collaborative relationships with legal, product, and engineering stakeholders

Uber Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Uber and has not been reviewed or approved by Uber.

  • Parental & Family Support — Policies provide a minimum of fully paid parental leave for all parents and financial support for fertility, adoption, and surrogacy, with added credits to ease the transition. Programs extend to family medical leave and parenting support resources, indicating depth beyond baseline offerings.
  • Healthcare Strength — Healthcare coverage is described as comprehensive across many countries, with medical, dental, vision, life, disability, and mental health benefits, plus allowances where direct plans are not available. Wellness programs and reimbursements further reinforce access to care.
  • Wellbeing & Lifestyle Benefits — Monthly ride and meal credits, free office meals/snacks, fitness stipends, onsite gyms, and wellbeing reimbursements create meaningful everyday value. Home‑office stipends, travel medical coverage, and counseling support round out lifestyle-oriented perks.

Uber Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
21,000 Employees
Year Founded: 2009

What We Do

We are Uber. The go-getters. The kind of people who are relentless about our mission to help people go anywhere and get anything. Movement is what we do. It’s our lifeblood. It runs through our veins. It’s what gets us out of bed each morning. It pushes us to constantly reimagine how we can move better. For you. For all the places you want to go. For all the things you want to get. For all the ways you want to earn. Across the entire world. In real-time. At the incredible speed of now.

Why Work With Us

We welcome people from all backgrounds who seek the opportunity to help build a future where everyone and everything can move independently. If you have the curiosity, passion, and collaborative spirit, work with us, and let’s move the world forward, together.

Gallery

Gallery

Similar Jobs

Samsara Logo Samsara

Application Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Seattle, WA, USA
4000 Employees
165K-295K Annually

Writer Logo Writer

Security Engineer

Artificial Intelligence • Software • Generative AI
Hybrid
3 Locations
350 Employees
183K-240K Annually

Grow Therapy Logo Grow Therapy

Staff Engineer

Healthtech • Social Impact • Software
Remote or Hybrid
4 Locations
650 Employees
182K-288K Annually

Uber Logo Uber

Security Engineer

Logistics • Transportation • 3PL: Third Party Logistics
In-Office
4 Locations
21000 Employees
267K-297K Annually

Similar Companies Hiring

Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account