401,286open jobs
13,975companies
77,769added this week
Browse all
Salary
$180k – $200k per year
Location
In office
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
Uber is an American mobility and delivery company founded in San Francisco in 2009 that connects independent drivers and couriers with riders and customers through its apps. It operates ride hailing in thousands of cities, a food and grocery delivery business built on the same courier network, a freight brokerage matching shippers with carriers, and an advertising business that sells placement inside those apps. Listed on the New York Stock Exchange since 2019, the company reached sustained profitability in the mid 2020s and now partners with autonomous vehicle developers rather than building self-driving technology itself.

About the Role

As a Senior Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation. This role will sit in either our Seattle, San Fransisco, or Sunnyvale office.

You operate at the intersection of Fire Captain, NTSB Investigator, and hands-on technical practitioner. In the moment, you take command - setting strategy, assigning resources, and making high-consequence decisions under pressure. After the smoke clears, you drive deep technical investigation and post-incident analysis to ensure we understand not just what happened, but why it happened, and that meaningful, durable fixes are made.

This is not a passive coordination role. You are expected to be technically credible, decisive in ambiguity, and comfortable owning outcomes when there is no playbook. You will shape how Uber responds to security incidents at scale - raising the technical bar, building and modernizing tooling and workflows, and influencing teams beyond Engineering Security.

What the Candidate Will Need / Bonus Points

---- What the Candidate Will Do ----

  • Command the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.
  • Participate in an on-call rotation where you are expected to make real-time decisions with incomplete information, balancing speed, risk, and impact.
  • Act as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus.
  • Transition seamlessly between executive-level incident leadership and hands-on technical investigation, including log analysis, system interrogation, and root cause validation.
  • Serve as the primary interface to senior leadership during critical incidents, translating evolving technical realities into clear risk, impact, and decision frameworks.
  • Build and maintain strong working relationships with global engineering, infrastructure, legal, privacy, and operations teams to enable fast, coordinated response.
  • Conduct rigorous post-incident analysis in the spirit of an NTSB investigation - focused on systemic causes, contributing factors, and concrete prevention.
  • Mentor and develop other responders and incident leaders, raising the organization’s ability to handle complex, time-critical security events.
  • Lead and materially contribute to initiatives that mature Uber’s incident response program, including:
  • High-fidelity incident simulations and technical tabletop exercises
  • Threat-informed response planning and scenario development
  • ‘Left of boom’ threat modeling to prevent incidents before they occur
  • Improvements to detection, containment, and response automation
  • Adoption of new investigative techniques and tooling, including AI-assisted workflows

---- Basic Qualifications ----

  • 5+ years in security operations, detection, or incident response roles at scale, with demonstrated ownership of ambiguous, large, complex, high-impact incidents.
  • Deep familiarity with modern attacker TTPs and how they manifest across logs, systems, networks, endpoints, and applications.
  • Strong technical investigation skills - comfortable working directly with logs, telemetry, and raw system data to validate hypotheses and determine root cause.
  • Experience briefing executives during active incidents, with the ability to clearly explain tradeoffs, risks, and recommended actions.
  • Experience designing or running technical incident simulations (tabletops, purple team exercises, or similar) that stress real-world response capabilities.
  • Experience building or leveraging AI-driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support.

---- Preferred Qualifications ----

  • Demonstrated experience leading other responders through direct command during incidents and longer-term technical mentorship.
  • Strong bias for action and continuous improvement - uncomfortable with leaving with a shrug if things aren’t right.
  • Experience responding to incidents in highly distributed, cloud-scale environments where blast radius and coordination complexity are significant.
  • Broad security domain knowledge (infrastructure, endpoint, product, identity, data) and the ability to reason across them during incidents.
  • Ability to script or code (Python, Go, or similar) to automate response tasks, prototype tooling, or close operational gaps.

For San Francisco, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For Seattle, WA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For Sunnyvale, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
401,286 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$60k – $90k per year • Equity • Remote • Full-Time • 3+ years exp • Madrid
C++
JavaScript
Node JS
Python
Rust
Databases
PostgreSQL
Frontend
WebAssembly
DevOps
GitHub
KVM
Xen
Marketing
LinkedIn
Apply
$120k – $150k per year • Equity 1–3% • In office • Full-Time • 1+ year exp • San Francisco
JavaScript
Node JS
Python
AI/ML
Edge AI
DevOps
AWS
Azure
GCP
Apply
In office • 2+ years exp • PhD
Python
Apply
In office • 4+ years exp • Master's Degree
Python
AI/ML
Image Segmentation
PyTorch
TensorFlow
DevOps
AWS
Docker
GCP
Apply
$145k – $160k per year • In office • 7+ years exp • Bachelor's Degree
Java
MATLAB
Python
SQL
AI/ML
Hadoop
Spark
Analytics
Tableau
Apply
Equity • In office • 3+ years exp • Chicago
Marketing
Salesforce
Apply
In office • 3+ years exp • Bachelor's Degree • Chihuahua
Marketing
Salesforce
Apply
$190k – $211k per year • Equity • In office • 5+ years exp • Bachelor's Degree • San Francisco
Java
Perl
Python
Ruby
Scala
AI/ML
Spark
Analytics
A/B Testing
Apply
COE Team Lead I 3 days ago
$29k – $65k per year (Estimated) • In office • 1+ year exp • Taguig
Apply
In office • 4+ years exp • Bachelor's Degree
Analytics
A/B Testing
Apply
See all jobs
This is one of many
401,286 more open roles from verified company boards, updated every day.