{"id":2060692,"url":"https://alion.io/job/uber-staff-security-technologist-incident-commander","title":"Staff Security Technologist - Incident Commander","company":{"id":230,"name":"Uber","domain":"uber.com","url":"https://alion.io/company/uber","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"A","score":94,"open_postings":129,"ghost_share":0,"stale_share":0.419,"repost_share":0.031,"time_to_fill_p50_days":6,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["San Francisco, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":211000,"max":234000,"currency":"USD","period":"year","gross":null,"usd_annual":234000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"Threat Modeling","optional":false},{"name":"Python","optional":true}],"status":"live","first_seen_at":"2026-10-07T17:50:01Z","employer_posted_date":"2026-10-07","last_verified_at":"2026-10-11T21:48:32Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"About the Role\nAs a Staff Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation - and owning the operational and technical effectiveness of the incident-command function. This role will sit in either our Seattle, San Francisco, or Sunnyvale office.\nYou operate at the intersection of Fire Captain, NTSB Investigator, and hands-on technical practitioner. In the moment, you take command - setting strategy, assigning resources, and making high-consequence decisions under pressure. After the smoke clears, you drive deep technical investigation and post-incident analysis to ensure we understand not just what happened, but why it happened, and that meaningful, durable fixes are made.\nThis is not a passive coordination role. You are expected to be technically credible, decisive in ambiguity, and comfortable owning outcomes when there is no playbook. As a technical domain and cultural leader, you drive the priorities, goals, and delivery of a significant incident response program spanning multiple high-complexity projects. You align Security Technologists and partner teams across Engineering Security and adjacent functions - raising the technical bar, establishing reusable frameworks and best practices, and modernizing tooling and workflows to reduce risk across Uber.\nWhat the Candidate Will Do\nCommand the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.\nParticipate in an on-call rotation where you are expected to make real-time decisions with incomplete information, balancing speed, risk, and impact, and model decisive, responsible action that keeps responders and stakeholders moving.\nAct as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus while providing technical oversight to engineers and Security Technologists working across parallel response and remediation efforts.\nTransition seamlessly between executive-level incident leadership and hands-on technical investigation, including log analysis, system interrogation, and root cause validation across complex systems and security domains.\nServe as the primary interface to senior leadership during critical incidents, translating evolving technical realities into concise, audience-aware updates with clear knowns, unknowns, risks, tradeoffs, and decisions needed. Align stakeholders and seek guidance from senior leaders as appropriate.\nBuild and maintain strong working relationships with global engineering, infrastructure, legal, privacy, and operations teams to enable fast, coordinated response, aligning competing goals and translating business needs, risks, and threats into actionable response requirements.\nConduct rigorous post-incident analysis in the spirit of an NTSB investigation - focused on systemic causes, contributing factors, and concrete prevention. Drive cross-team remediation with accountable owners, timelines, and validation of durable risk reduction.\nServe as a cultural and technical leader, actively mentoring responders, incident leaders, and promising engineers and architects. Share domain expertise and coach effective communication, sound decisions under uncertainty, and greater cross-organizational impact.\nOwn the priorities, goals, and delivery of a significant incident response program with multiple high-complexity projects, in partnership with Senior Manager and Director+ stakeholders. Align Security Technologists across related and adjacent efforts, provide technical and architectural direction, and proactively deliver improvements, including:\nHigh-fidelity incident simulations and technical tabletop exercises that develop responders, expose readiness gaps, and turn incident learnings into validated improvements\nThreat-informed response planning and scenario development, supported by reusable frameworks, playbooks, documentation, and tutorials that enable other teams to leverage your work independently\n‘Left of boom’ threat modeling and pre-mortems to prevent incidents before they occur, translating attack paths and business risk into preventive controls and measurable risk reduction\nImprovements to detection, containment, and response automation that solve classes of recurring problems and create broadly reusable solutions adopted by multiple teams\nAdoption of new investigative techniques and tooling, including AI-assisted workflows, with source validation, data protection, and human decision gates. Establish and promote response best practices across the group\nBasic Qualifications\n8+ years in security operations, detection, or incident response roles at scale, with demonstrated ownership of ambiguous, large, complex, high-impact incidents and significant, high-complexity, multi-team programs.\nRecognized technical domain expertise in incident response, with deep familiarity with modern attacker TTPs and how they manifest across logs, systems, networks, endpoints, and applications. Ability to translate business problems, risk, and threats into security requirements and effective response solutions.\nStrong technical investigation skills - comfortable working directly with logs, telemetry, and raw system data to validate hypotheses and determine root cause, with the technical depth and breadth to resolve undefined, high-risk problems with little existing structure.\nExperience briefing executives during active incidents and aligning technical and non-technical stakeholders at all levels, with concise, informative, audience-appropriate communication of tradeoffs, risks, decisions, and recommended actions.\nExperience designing or running technical incident simulations (tabletops, purple team exercises, or similar) that stress real-world response capabilities and turn findings into implemented, validated improvements across multiple teams.\nExperience building or leveraging AI-driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support, with safeguards for data sensitivity, source verification, and human accountability.\nPreferred Qualifications\nDemonstrated experience leading other responders through direct command during incidents and longer-term technical mentorship of responders, engineers, and architects, helping others increase their impact beyond their immediate team.\nStrong bias for action and continuous improvement - proactively identifying and resolving complex operational or organizational gaps, enabling peers and stakeholders to make sound decisions under uncertainty, responding promptly, and following through on commitments.\nExperience responding to incidents in highly distributed, cloud-scale environments where blast radius and coordination complexity are significant, and driving improvements across multiple teams and adjacent functions.\nBroad security domain knowledge (infrastructure, endpoint, product, identity, data) and the ability to reason across them during incidents, developing frameworks, patterns, and methodologies that reduce risk across the company.\nAbility to script or code (Python, Go, or similar) to automate response tasks, prototype broadly reusable tooling, or close investigation and operational gaps.\nFor San Francisco, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year.\nYou will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.","description_format":"text","description_chars":7814,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Transportation & Logistics","Ride Hailing"],"lifecycle":[{"event":"open","at":"2026-10-08T01:50:54Z"}],"visa":[],"liveness":{"score":75,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.831,"p_room":0.9,"age_days":2,"expected_fill_days":6,"reasons":["conf:2","velocity","win:mid","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":{"stated_usd_annual":234000,"is_top_pay":true},"html_url":"https://alion.io/job/uber-staff-security-technologist-incident-commander","json_url":"https://alion.io/job/uber-staff-security-technologist-incident-commander.json","meta":{"generated_at":"2026-10-11T22:22:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":12164,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":230},"rest":"https://alion.io/mcp/rest/get_company?id=230"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fuber-staff-security-technologist-incident-commander"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fuber-staff-security-technologist-incident-commander"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fuber-staff-security-technologist-incident-commander"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/uber-staff-security-technologist-incident-commander\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fuber-staff-security-technologist-incident-commander"}]}