JOBSEARCHER

Sr Security Technologist - Risk & Compliance

Job DescriptionAbout the RoleAs a Senior Security Technologist on the team, you will help lead security diligence, integration, and operational security efforts for acquisitions, strategic investments, and subsidiary environments. You will collaborate with subsidiary security personnel to uplift their security operations to Uber minimum standards post-acquisition.This role combines advisory, operational, and hands-on security engineering responsibilities, including automation, incident response, and pragmatic risk management in fast-moving, evolving environments. Successful candidates are excited to build practical solutions, improve security operations, and help teams navigate complex integration challenges.You will write code using approved AI tooling, automate workflows, deploy security tooling to subsidiary environments, integrate systems, improve telemetry visibility, and help operationalize security capabilities across newly acquired target companies and evolving environments. You will also help respond to security incidents involving subsidiaries and acquired companies, partnering closely with internal security teams and business stakeholders to rapidly reduce risk and improve resilience.The ideal candidate is comfortable:building automation and integrations,investigating security incidents,deploying security tooling,leveraging AI-assisted engineering workflows,and communicating technical risk to leadership.You'll be successful in this role if you enjoy solving technical problems, collaborating across teams, and building practical security solutions in evolving environments.Travel may occasionally be required to support acquisition diligence or integration efforts, but is generally infrequent and based on business needs.What You'll DoAssess the cyber security maturity of acquisition targets across infrastructure, on-prem, cloud, identity, endpoint, SaaS, and engineering environmentsIdentify key technical and operational risks, domain specific security gaps, and integration challenges associated with acquired organizationsDesign and implement scalable security integrations for newly acquired companies and subsidiariesBuild automation, tooling, and workflows to accelerate security onboarding and operational visibilityWrite code and scripts to integrate systems, normalize telemetry, automate remediation activities, and improve operational efficiencyUse AI-assisted engineering and automation techniques to improve analysis, integration, and security operations workflowsDeploy and operationalize security services such as:endpoint detection and response (EDR)vulnerability managementlogging and telemetry collectionIncident Response Monitoring for Subsidiariesidentity and access managementdevice managementcloud security monitoringasset inventory and visibility toolingPartner with Engineering Security, Enterprise Security, Cloud Security, Security Response and Investigations, Information Technology (IT) Privacy, Legal, Corporate Development, and business stakeholders during acquisition and integration activitiesRespond to and help coordinate security incidents involving subsidiaries and acquired entitiesSupport containment, remediation, recovery, and long-term hardening efforts during incident response scenariosBasic Qualifications5+ years of experience in security engineering, cloud security, infrastructure security, detection and response, or related technical security rolesBachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experienceHands-on engineering and troubleshooting experience in modern enterprise environmentsExperience applying risk management principles in complex cybersecurity environments, including both cloud and on-premises infrastructure.Experience writing code or automation using languages such as Python, Go, Bash, or similarExperience integrating or deploying security technologies in cloud or enterprise environmentsExperience working with modern cloud infrastructure and SaaS ecosystemsFamiliarity with AI-assisted development workflows and modern automation techniquesExperience supporting or responding to security incidentsUnderstanding of:cloud infrastructure and securityidentity and access managementendpoint securityvulnerability managementlogging and telemetry systemsenterprise SaaS platformsnetworking fundamentalsAbility to communicate complex technical concepts clearly to both technical and non-technical audiencesComfort navigating evolving priorities and collaborating across teams in fast-moving environmentsPreferred Qualifications:Strong information assurance management principles and practicesAssess security risk across interconnected cloud and on-premises environments.Understand how security controls interact, overlap, and compensate for one another.Apply risk-based decision-making to evaluate control effectiveness and overall security posture.Partner with technical and business teams to align security requirements with operational needsExperience building internal security tooling or operational automation platformsExperience integrating acquired environments into centralized security operationsFamiliarity with detection engineering, SIEM platforms, or telemetry pipelinesExperience assessing engineering and software development security practicesExperience with infrastructure-as-code or cloud automation frameworksExperience using LLMs or AI tooling to improve engineering or security workflowsIncident response, investigative, and problem-solving experienceWritten communication and program management experienceAbility to balance pragmatic execution with long-term security strategyResponsibilitiesFor San Francisco, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.For Seattle, WA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.For Sunnyvale, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.About UsReady to Ride?This isn't the kind of place where you follow a playbook - it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves - we'd love to hear from you.You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.