824,589open jobs
53,146companies
135,057added this week
Browse all
Salary
$232k – $258k per year
Location
In office (San Francisco)
Seniority
Staff · 10+ years exp

Confirmed on the employer's own hiring board on Sep 27, 2026. First seen by Alion on Sep 24, 2026. Uber scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Uber is an American mobility and delivery company founded in San Francisco in 2009 that connects independent drivers and couriers with riders and customers through its apps. It operates ride hailing in thousands of cities, a food and grocery delivery business built on the same courier network, a freight brokerage matching shippers with carriers, and an advertising business that sells placement inside those apps. Listed on the New York Stock Exchange since 2019, the company reached sustained profitability in the mid 2020s and now partners with autonomous vehicle developers rather than building self-driving technology itself.

About the role and team:

As a member of Uber’s Offensive Security team, you will work across multiple security disciplines to proactively identify and reduce risk in Uber’s most critical services and emerging technologies. You will perform security design reviews and threat modeling for critical services and AI agents, conduct hands-on penetration testing to validate real-world attack paths, and help build AI-powered automation that transforms how these security assessments are performed at scale. This role combines deep technical security expertise with an automation-first mindset, helping evolve traditional point-in-time assessments toward continuous, scalable security testing across Uber’s technology ecosystem.

This isn't a "set and forget" role. Our environment is fast-moving and the threats are constantly evolving. You will navigate the "messy" reality of hybrid cloud and distributed systems, conducting technical security design reviews as part of our secure software development lifecycle. We are looking for a technically curious engineer who thrives in ambiguity, takes extreme ownership of their work, and has the grit to stay ahead of sophisticated adversaries. If you are motivated by high-stakes challenges and want to build a more secure future for movement - this is where you’ll grow.

What you’ll do

  • Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths.

  • Conduct security design reviews and threat modeling for AI agents and agentic systems, evaluating risks across models, tools, data, permissions, external integrations, and runtime behavior.

  • Design and build AI-powered automation for security design reviews, threat modeling, penetration testing, and vulnerability validation, increasing the scale, frequency, and depth of Offensive Security assessments.

  • Partner with engineering and security teams to translate offensive security findings into systemic improvements, helping eliminate vulnerability classes and strengthen security controls across Uber’s technology ecosystem.

  • Perform multi-disciplinary security design reviews of engineering proposals, analyzing cloud, infrastructure, application, and data-layer security.

  • Navigate complex design trade-offs to provide corrective guidance that improves the overall security posture of Uber’s products and services.

  • Collaborate with engineering teams across the company to analyze design documents and identify potential flaws before they reach production.

  • Translate technical security findings into actionable guidance for both engineering and non-technical stakeholders to ensure alignment and impact.

  • Conduct comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.

  • Champion engineering best practices and serve as a security ambassador, helping teams move fast while building with integrity and care.

Basic Qualifications

  • 7+ years of professional experience in security engineering, threat detection, or client platform engineering.
  • Demonstrated ability to independently analyze complex, large-scale system designs, identify security risks and attack paths, and drive technical solutions across multiple services, systems, and dependencies.
  • Deep knowledge of threat modeling, vulnerability discovery and classification, security risk assessment, and offensive security methodologies, with experience applying them to complex production environments.
  • Extensive experience assessing the security of cloud-native services, microservices, distributed systems, APIs, or other large-scale production environments.
  • Proven ability to lead complex security assessments and influence engineering teams to implement security improvements across organizational and technical boundaries.
  • Experience applying AI/LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or other security engineering workflows.
  • Hands-on experience conducting penetration testing of complex applications, services, APIs, and infrastructure, including identifying, validating, and demonstrating exploitable vulnerabilities and attack paths.

Preferred Qualifications

  • Master’s degree or PhD in a technical field and 10+ years of experience in a cybersecurity leadership or staff-level role.
  • Deep knowledge of Cybersecurity, Compliance, and Privacy, with experience chaining vulnerabilities and quantifying risks.
  • Experience collaborating with EMs, TPMs, and PMs on prioritization, headcount planning, and technical evaluation of team members.
  • Advanced expertise in leveraging AI/ML for security use cases and building device attestation or trust tooling at a global scale.
  • Strategic relationship builder: Proven ability to leverage collaborative relationships with legal, product, and engineering stakeholders to build trust and accomplish work.

For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For Seattle, WA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For Sunnyvale, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
824,589 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
San Francisco
≈ $110k – $239k per year (Estimated) • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Chicago
DevOps
GCP
Azure
CI/CD
AWS
IAM
Linux
Windows
Cybersecurity
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Least Privilege
Microsoft Defender for Cloud
Microsoft Entra ID
Ping Identity
Active Directory
SIEM
DLP
OWASP
Apply
≈ $86k – $172k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Jacksonville
Management
Microsoft Office
Apply
$200k – $210k per year • In office • TS/SCI • Full-Time • 5+ years exp • Linthicum Heights
Cybersecurity
ISO 27001
Apply
$190k – $270k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Alameda
Python
PowerShell
AI/ML
AI Agents
LLM Guardrails
DevOps
CI/CD
AWS
IAM
Cybersecurity
Zero Trust
Management
Agile
Apply
$219k – $311k per year • In office • Full-Time • 9+ years exp • Bachelor's Degree • Alameda
DevOps
Azure
CI/CD
AWS
GitHub
IAM
Cybersecurity
GDPR
Zero Trust
Management
Agile
Apply
≈ $32k – $77k per year (Estimated) • In office • 5+ years exp • Moscow
Python
Databases
PostgreSQL
Redis
OpenSearch
AI/ML
Model Context Protocol
AI Agents
LLM
RAG
DevOps
Docker
Kubernetes
Apply
$158k – $293k per year • Equity • Remote (United States) • Full-Time • 8+ years exp • San Francisco • New York
AI/ML
AI Agents
Transformers
Human-in-the-Loop
Agentic Workflows
Machine Learning
Apply
$160k – $240k per year • In office • United States
Python
Java
Rust
TypeScript
C++
AI/ML
Model Context Protocol
Reinforcement Learning
AI Agents
Apply
$160k – $240k per year • In office • Seattle
Python
Java
Rust
TypeScript
C++
AI/ML
Model Context Protocol
Reinforcement Learning
AI Agents
Apply
$160k – $240k per year • In office • Calgary
Python
Java
Rust
TypeScript
C++
AI/ML
Model Context Protocol
Reinforcement Learning
AI Agents
Apply
$232k – $258k per year • Equity • In office • 10+ years exp • Bachelor's Degree • San Francisco
Python
Go
Ruby
DevOps
Platform Engineering
Incident Management
Cybersecurity
Threat Modeling
Apply
$267k – $297k per year • Equity • In office • 10+ years exp • Bachelor's Degree • San Francisco
Python
Go
Java
DevOps
GCP
Azure
AWS
Incident Management
IAM
Cybersecurity
Threat Modeling
SIEM
Apply
$202k – $224k per year • Equity • In office • 5+ years exp • Bachelor's Degree • Seattle
Go
Java
Databases
Apache Kafka
AI/ML
Flink
Machine Learning
DevOps
Terraform
GCP
AWS
Docker
Kubernetes
TCP/IP
DNS
Cybersecurity
Zscaler
Apply
$153k – $170k per year • Equity • In office • 5+ years exp • Bachelor's Degree • Seattle
Python
PowerShell
DevOps
GCP
Azure
AWS
IAM
Cybersecurity
Okta
CyberArk
ISO 27001
GDPR
HIPAA
Zero Trust
Least Privilege
Microsoft Entra ID
Active Directory
LDAP
Apply
$232k – $258k per year • Equity • In office • 8+ years exp • Bachelor's Degree • Seattle
Go
Java
Databases
Apache Kafka
AI/ML
Flink
Feature Store
DevOps
GCP
AWS
Docker
Kubernetes
Platform Engineering
Apply
$130k – $175k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • San Francisco
Apply
≈ $105k – $207k per year (Estimated) • In office • Full-Time • 5+ years exp • San Francisco
Apply
$140k – $295k per year • In office • 5+ years exp • San Francisco
Apply
$100k – $125k per year • In office • 2+ years exp • San Francisco
Python
Apply
$145k – $235k per year • In office • 3+ years exp • San Francisco
Apply
See all jobs
This is one of many
824,589 more open roles from verified company boards, updated every day.