1,450,551open jobs
86,146companies
223,842added this week
Browse all
Salary
$211k – $234k per year
Location
In office (San Francisco)
Seniority
Staff · 8+ years exp

Confirmed on the employer's own hiring board on Oct 10, 2026. First seen by Alion on Oct 7, 2026. Uber scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Uber is an American mobility and delivery company founded in San Francisco in 2009 that connects independent drivers and couriers with riders and customers through its apps. It operates ride hailing in thousands of cities, a food and grocery delivery business built on the same courier network, a freight brokerage matching shippers with carriers, and an advertising business that sells placement inside those apps. Listed on the New York Stock Exchange since 2019, the company reached sustained profitability in the mid 2020s and now partners with autonomous vehicle developers rather than building self-driving technology itself.

About the Role

As a Staff Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation - and owning the operational and technical effectiveness of the incident-command function. This role will sit in either our Seattle, San Francisco, or Sunnyvale office.

You operate at the intersection of Fire Captain, NTSB Investigator, and hands-on technical practitioner. In the moment, you take command - setting strategy, assigning resources, and making high-consequence decisions under pressure. After the smoke clears, you drive deep technical investigation and post-incident analysis to ensure we understand not just what happened, but why it happened, and that meaningful, durable fixes are made.

This is not a passive coordination role. You are expected to be technically credible, decisive in ambiguity, and comfortable owning outcomes when there is no playbook. As a technical domain and cultural leader, you drive the priorities, goals, and delivery of a significant incident response program spanning multiple high-complexity projects. You align Security Technologists and partner teams across Engineering Security and adjacent functions - raising the technical bar, establishing reusable frameworks and best practices, and modernizing tooling and workflows to reduce risk across Uber.

What the Candidate Will Do

  • Command the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.
  • Participate in an on-call rotation where you are expected to make real-time decisions with incomplete information, balancing speed, risk, and impact, and model decisive, responsible action that keeps responders and stakeholders moving.
  • Act as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus while providing technical oversight to engineers and Security Technologists working across parallel response and remediation efforts.
  • Transition seamlessly between executive-level incident leadership and hands-on technical investigation, including log analysis, system interrogation, and root cause validation across complex systems and security domains.
  • Serve as the primary interface to senior leadership during critical incidents, translating evolving technical realities into concise, audience-aware updates with clear knowns, unknowns, risks, tradeoffs, and decisions needed. Align stakeholders and seek guidance from senior leaders as appropriate.
  • Build and maintain strong working relationships with global engineering, infrastructure, legal, privacy, and operations teams to enable fast, coordinated response, aligning competing goals and translating business needs, risks, and threats into actionable response requirements.
  • Conduct rigorous post-incident analysis in the spirit of an NTSB investigation - focused on systemic causes, contributing factors, and concrete prevention. Drive cross-team remediation with accountable owners, timelines, and validation of durable risk reduction.
  • Serve as a cultural and technical leader, actively mentoring responders, incident leaders, and promising engineers and architects. Share domain expertise and coach effective communication, sound decisions under uncertainty, and greater cross-organizational impact.
  • Own the priorities, goals, and delivery of a significant incident response program with multiple high-complexity projects, in partnership with Senior Manager and Director+ stakeholders. Align Security Technologists across related and adjacent efforts, provide technical and architectural direction, and proactively deliver improvements, including:
  • High-fidelity incident simulations and technical tabletop exercises that develop responders, expose readiness gaps, and turn incident learnings into validated improvements
  • Threat-informed response planning and scenario development, supported by reusable frameworks, playbooks, documentation, and tutorials that enable other teams to leverage your work independently
  • ‘Left of boom’ threat modeling and pre-mortems to prevent incidents before they occur, translating attack paths and business risk into preventive controls and measurable risk reduction
  • Improvements to detection, containment, and response automation that solve classes of recurring problems and create broadly reusable solutions adopted by multiple teams
  • Adoption of new investigative techniques and tooling, including AI-assisted workflows, with source validation, data protection, and human decision gates. Establish and promote response best practices across the group

Basic Qualifications

  • 8+ years in security operations, detection, or incident response roles at scale, with demonstrated ownership of ambiguous, large, complex, high-impact incidents and significant, high-complexity, multi-team programs.
  • Recognized technical domain expertise in incident response, with deep familiarity with modern attacker TTPs and how they manifest across logs, systems, networks, endpoints, and applications. Ability to translate business problems, risk, and threats into security requirements and effective response solutions.
  • Strong technical investigation skills - comfortable working directly with logs, telemetry, and raw system data to validate hypotheses and determine root cause, with the technical depth and breadth to resolve undefined, high-risk problems with little existing structure.
  • Experience briefing executives during active incidents and aligning technical and non-technical stakeholders at all levels, with concise, informative, audience-appropriate communication of tradeoffs, risks, decisions, and recommended actions.
  • Experience designing or running technical incident simulations (tabletops, purple team exercises, or similar) that stress real-world response capabilities and turn findings into implemented, validated improvements across multiple teams.
  • Experience building or leveraging AI-driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support, with safeguards for data sensitivity, source verification, and human accountability.

Preferred Qualifications

  • Demonstrated experience leading other responders through direct command during incidents and longer-term technical mentorship of responders, engineers, and architects, helping others increase their impact beyond their immediate team.
  • Strong bias for action and continuous improvement - proactively identifying and resolving complex operational or organizational gaps, enabling peers and stakeholders to make sound decisions under uncertainty, responding promptly, and following through on commitments.
  • Experience responding to incidents in highly distributed, cloud-scale environments where blast radius and coordination complexity are significant, and driving improvements across multiple teams and adjacent functions.
  • Broad security domain knowledge (infrastructure, endpoint, product, identity, data) and the ability to reason across them during incidents, developing frameworks, patterns, and methodologies that reduce risk across the company.
  • Ability to script or code (Python, Go, or similar) to automate response tasks, prototype broadly reusable tooling, or close investigation and operational gaps.

For San Francisco, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year.

You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,450,551 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
San Francisco
$180k – $250k per year • Remote (United States) • Full-Time • United States
DevOps
Kubernetes
Apply
$141k – $176k per year • Equity • In office • 7+ years exp • Bachelor's Degree • Atlanta
DevOps
AWS
Cybersecurity
ISO 27001
Apply
$179k – $224k per year • Equity • In office • 8+ years exp • Atlanta
DevOps
Platform Engineering
Cybersecurity
GDPR
Threat Modeling
PKI
Apply
≈ $89k – $173k per year (Estimated) • In office • 5+ years exp • Louisville
DevOps
Azure
Cybersecurity
Microsoft Defender
GDPR
SIEM
Apply
$210k – $234k per year • In office • Full-Time • 7+ years exp • New York
Python
AI/ML
Model Context Protocol
Prompt Engineering
Function Calling
AI Agents
LLM
RAG
Red Teaming
LLM Guardrails
NIST AI RMF
Tool Use
DevOps
GCP
AWS
Kubernetes
IAM
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
≈ $116k – $226k per year (Estimated) • Hybrid • Full-Time • Newark
Python
Rust
TypeScript
DevOps
AWS
Linux
Cybersecurity
HIPAA
Threat Modeling
Apply
≈ $60k – $145k per year (Estimated) • Remote (Argentina) • Full-Time • 12+ years exp
Python
Go
TypeScript
AI/ML
AutoGen
LlamaIndex
Model Context Protocol
Fine-tuning
Embeddings
AI Agents
Semantic Kernel
CrewAI
LLM
RAG
Hallucination
Hybrid Search
Human-in-the-Loop
Multi-Agent Systems
Machine Learning
DevOps
GCP
Azure
CI/CD
AWS
Docker
Cybersecurity
Threat Modeling
Apply
≈ $69k – $162k per year (Estimated) • Hybrid • Contractor • London
Python
Databases
Snowflake
Databricks
DevOps
Terraform
Helm
CloudFormation
Azure
CI/CD
GitOps
AWS
Docker
Kubernetes
GitHub
Cybersecurity
MITRE ATT&CK
STRIDE
Threat Modeling
OWASP
Management
Jira
Agile
QA
Pytest
Apply
≈ $77k – $178k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Tokyo
DevOps
GCP
Azure
CI/CD
AWS
IAM
Cybersecurity
Threat Modeling
Apply
≈ $229k – $458k per year (Estimated) • In office • 15+ years exp • Bachelor's Degree • Cupertino
Java
Java
Spring Boot
Netty
Databases
Redis
Apache Kafka
AI/ML
Feature Store
DevOps
gRPC
GCP
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
Threat Modeling
Analytics
A/B Testing
Management
Agile
Apply
$171k – $190k per year • Equity • In office • 3+ years exp • Bachelor's Degree • San Francisco
Python
Go
Java
SQL
AI/ML
Function Calling
AI Agents
Tool Use
DevOps
GCP
CI/CD
AWS
Cybersecurity
Threat Modeling
Apply
$171k – $190k per year • Equity • In office • 3+ years exp • Bachelor's Degree • Seattle
Python
Go
Java
SQL
AI/ML
Function Calling
AI Agents
Tool Use
DevOps
GCP
CI/CD
AWS
Cybersecurity
Threat Modeling
Apply
$232k – $258k per year • Equity • In office • 10+ years exp • Master's Degree • San Francisco
AI/ML
AI Agents
DevOps
Platform Engineering
Cybersecurity
Threat Modeling
Apply
$232k – $258k per year • Equity • In office • 10+ years exp • Bachelor's Degree • San Francisco
Python
Go
Ruby
DevOps
Platform Engineering
Incident Management
Cybersecurity
Threat Modeling
Apply
$267k – $297k per year • Equity • In office • 10+ years exp • Bachelor's Degree • San Francisco
Python
Go
Java
DevOps
GCP
Azure
AWS
Incident Management
IAM
Cybersecurity
Threat Modeling
SIEM
Apply
≈ $249k – $448k per year (Estimated) • Equity • In office • 8+ years exp • San Francisco
Cybersecurity
HIPAA
Apply
≈ $249k – $448k per year (Estimated) • Equity • In office • 8+ years exp • San Francisco
Cybersecurity
HIPAA
Apply
≈ $249k – $448k per year (Estimated) • Equity • In office • 8+ years exp • San Francisco
Cybersecurity
HIPAA
Apply
$205k – $250k per year • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • San Francisco
Python
AI/ML
Red Teaming
DevOps
Terraform
Ansible
GitHub Actions
CI/CD
AWS
AWS Lambda
IAM
Amazon ECS
Linux
DNS
DHCP
Cybersecurity
pfSense
PKI
Apply
$132k – $170k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Washington • San Francisco
Apply
See all jobs
This is one of many
1,450,551 more open roles from verified company boards, updated every day.