{"id":132119,"url":"https://alion.io/job/uber-staff-security-strategist-grc","title":"Staff Security Strategist GRC","company":{"id":230,"name":"Uber","domain":"uber.com","url":"https://alion.io/company/uber","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"A","score":92,"open_postings":100,"ghost_share":0,"stale_share":0.53,"repost_share":0,"time_to_fill_p50_days":4,"computed_at":"2026-09-26T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["San Francisco, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":211000,"max":234000,"currency":"USD","period":"year","gross":null,"usd_annual":234000},"salary_estimate":null,"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"Agile","optional":false},{"name":"ServiceNow","optional":false},{"name":"ISO 27001","optional":true},{"name":"NIST 800-53","optional":true},{"name":"NIST CSF","optional":true},{"name":"Python","optional":true},{"name":"SOC 2","optional":true},{"name":"SQL","optional":true}],"status":"live","first_seen_at":"2026-06-19T00:00:00Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-27T00:44:14Z","board_verified":true,"closed_at":null,"days_open":100,"trust":{"level":"stale","repost_count":1,"flags":["stale"],"days_open":100},"description":"About the Team\nUber's Engineering Security team works to ensure the security of information for our full set of users - riders, eaters, drivers and partners. Our ultimate goal is to ensure that every experience with Uber is simple, secure, and safe. We are seeking a talented Staff Security Strategist, GRC to join our Tech Risk and Assurance team within Engineering Security.\nAbout the Role\nThe Staff Security Strategist, GRC partners with engineering, security, and cross-functional risk stakeholders to strengthen Uber's cybersecurity posture through scalable cyber risk management, risk governance, and control design programs. This role is responsible for driving and implementing security, compliance, and risk management programs on the ServiceNow eGRC platform at Uber, working with the engineering team to develop and enable technical solutions that satisfy a variety of risk and compliance processes.\nThis role operates at the intersection of technical security, process design, and risk governance. The successful candidate will translate control gaps, threat and business context, and compliance requirements into practical risk treatment plans that engineering teams can execute, while driving consistent risk analysis, decision-making, and follow-through. The role must be able to deliver work products required by Agile development methodologies for software development delivery as defined.\nWhat you will do\nOwn cyber risk intake, triage, and prioritization, ensuring clear accountability, well-formed risk statements, and timely treatment decisions.\nDevelop product strategy and lead project execution for multiple major components of Uber's Risk and Compliance technology solutions.\nManage different solutions on Uber's internal eGRC platform (ServiceNow) and collaborate with stakeholders to implement their program improvements.\nPartner with engineering teams to define risk treatment plans, identify sustainable fixes, and drive mitigation or remediation to the last mile rather than stopping at documentation.\nGather business and functional requirements from partner teams and deliver a product/release that meets the needs presented. Develop technical specifications documentation.\nLead or materially contribute to control design reviews, risk assessments, and risk decisions that require judgment, stakeholder alignment, and tradeoff management.\nDrive and evangelize vision for overall GRC strategy across engineering and security organizations.\nAnalyze and fully understand user stories and internal procedures in order to improve system capabilities, automate process workflows, and address scheduling limitations throughout the development and delivery of the eGRC platform.\nWork with developers to implement workflows from customer requirements including workflows, UI actions, client scripts, business rules, etc.\nLoad, manipulate, and maintain data between the eGRC platform and other systems as needed.\nBuild and maintain risk reporting for leaders and partner teams, including KRIs, exposure trends, risk acceptance aging, decision status, and escalation triggers.\nDesign and develop dashboards, home pages, performance analytics data collectors, and reports as needed to support program requirements.\nImprove the efficiency of risk workflows through automation, better tooling, clearer operating models, and reusable knowledge assets.\nPerform system and integration testing with sample and live data.\nReview product performance and provide a continuous improvement path through leveraging industry standard tools and capabilities as well as building new ones.\nServe as a bridge between cybersecurity, engineering, audit, privacy, and compliance stakeholders so that security risk becomes practical engineering action.\nMentor analysts and junior security partners on risk analysis, risk statement quality, treatment planning, stakeholder communication, and operational rigor.\nBasic Qualifications:\nBachelor's or Master's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, Risk Management, or related field, or equivalent practical experience.\n10+ years of experience in security, cyber risk, GRC, assurance, security operations, or related technical risk roles.\nSecurity certifications e.g. CISA, CISSP, CISM, or other relevant certifications.\nDemonstrated success managing security risk programs, treatment decisions, and cross-functional execution end to end.\nStrong understanding of security controls, risk treatment, and how to work with engineering on implementation details.\nExperience operating across multiple stakeholders, handling ambiguity, and driving accountability.\nAbility to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision.\nExcellent written and verbal communication skills, including the ability to present risk, status, and decision points to leadership and technical audiences.\nPreferred Qualifications:\nCRISC, ISO 27001 Lead Auditor, or comparable additional certifications.\nHands-on experience with ServiceNow eGRC platform, including configuration, workflow development, and integration.\nExperience with other GRC/ERM tooling such as AuditBoard, Archer, OpenPages, or SAP GRC.\nBig 4 accounting firm and/or internet/technology industry experience.\nProcess management experience, including process redesign and optimization.\nProven track record in driving security risk treatment to closure across multiple engineering teams.\nAbility to leverage AI, data analytics, and workflow automation to improve risk program performance and reporting.\nExperience with risk quantification methodologies and risk lifecycle tooling.\nStrong knowledge of control frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, NIST RMF, SOC 2, and CIS.\nProficiency in Python, SQL, dashboards, or similar tools for data analysis and reporting.\nAbility to thrive in environments of uncertainty.\n~~ ~~\n For San Francisco, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year.\nFor Sunnyvale, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year.\nFor all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.","description_format":"text","description_chars":6450,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Transportation & Logistics","Security Compliance","Ride Hailing"],"lifecycle":[{"event":"open","at":"2026-06-19T00:00:00Z"},{"event":"close","at":"2026-08-31T17:11:42Z"},{"event":"reopen","at":"2026-09-23T06:59:07Z"}],"liveness":{"score":9,"band":"cold","label":"Long shot","p_open":1,"p_active":0.317,"p_room":0.28,"age_days":99,"expected_fill_days":4,"reasons":["conf:6","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-26T05:45:00Z"},"pay":{"stated_usd_annual":234000,"is_top_pay":true},"html_url":"https://alion.io/job/uber-staff-security-strategist-grc","json_url":"https://alion.io/job/uber-staff-security-strategist-grc.json","meta":{"generated_at":"2026-09-27T05:35:20Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4935,"day_limit":5000,"remaining_today":65,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}