About this role
About the Role
As a member of Uber’s Security Review Team, you will proactively identify and reduce risk across Uber’s most critical services and emerging technologies. You will conduct hands-on penetration testing to identify and validate real-world attack paths, perform security design reviews and threat modeling for critical services and AI agents, and partner with engineering teams to drive effective remediation.
You will also help transform how offensive security operates at scale by building AI-powered automation and security tooling that makes assessments faster, more continuous, and more comprehensive. This role combines deep technical security expertise with an automation-first engineering mindset, evolving traditional point-in-time testing toward continuous, scalable adversarial security testing across Uber’s technology ecosystem.
This position focuses on security and privacy design reviews, threat modeling, and hands-on testing of third-party AI agents. The ideal candidate is comfortable analyzing technical designs, evaluating how systems handle sensitive data, identifying potential attack paths, and translating findings into practical recommendations. You’ll work closely with engineering, security, privacy, and third-party partners to address risks while using AI-assisted workflows and automation to improve assessment quality and scale.
What You’ll Do
-
Conduct security and privacy design reviews for services, applications, APIs, and AI integrations. Evaluate architecture, data flows, access controls, and proposed safeguards to identify risks early in development.
-
Perform threat modeling for critical services and AI agents, identifying attack surfaces, trust boundaries, potential attack paths, and appropriate mitigations.
-
Test third-party AI agents through hands-on adversarial assessments, evaluating risks across models, data access, permissions, tools, external integrations, and runtime behavior. Validate whether identified weaknesses can lead to unauthorized actions or sensitive-data exposure.
-
Evaluate sensitive-data handling across services and AI integrations, assessing how data is collected, accessed, stored, shared, retained, and deleted. Partner with privacy stakeholders to identify gaps and recommend appropriate safeguards.
-
Document actionable findings with clear descriptions, supporting evidence, reproducible test steps where applicable, risk assessments, and practical remediation guidance.
-
Partner with engineering teams and third-party vendors to address assessment findings, clarify security and privacy requirements, and verify that implemented mitigations resolve the identified risks.
-
Build and improve AI-powered automation for design reviews, threat modeling, agent testing, and vulnerability validation, reducing repetitive work and increasing assessment consistency, depth, and throughput.
-
Develop reusable assessment materials such as review checklists, threat models, test cases, and reporting templates to support repeatable, high-quality assessments across the team.
-
Basic Qualifications
-
3+ years of experience in security engineering, application security, product security, offensive security, or related technical security roles.
-
Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
-
Experience reviewing technical designs and identifying security risks in applications, APIs, cloud services, or distributed systems.
-
Experience performing threat modeling, analyzing attack paths, and recommending mitigations based on technical risk and potential impact.
-
Understanding of security and privacy principles, including authentication, authorization, least privilege, data protection, and secure handling of sensitive information.
-
Hands-on experience with security testing, vulnerability investigation, or validating the effectiveness of security controls.
-
Experience writing code or automation using languages such as Python, Go, Bash, or similar, and familiarity with AI-assisted development workflows.
-
Ability to communicate technical findings clearly to technical and non-technical audiences, document actionable recommendations, and collaborate across teams with evolving priorities.
-
Preferred Qualifications
-
Experience conducting security assessments or adversarial testing of third-party AI agents, large language model applications, or systems that interact with external tools and data sources.
-
Experience performing privacy design reviews and evaluating data flows, access patterns, retention practices, and safeguards for sensitive data.
-
Experience assessing AI-specific risks involving prompt injection, unintended data disclosure, excessive permissions, or unsafe tool use.
-
Experience building internal security tooling or using AI to automate design analysis, threat modeling, test execution, or assessment reporting.
-
Experience assessing security across interconnected cloud services, enterprise SaaS platforms, and third-party integrations.
-
Experience coordinating multiple assessments, working directly with engineering teams and vendors, and driving findings through remediation and validation.
-
For Seattle, WA-based roles: The base salary range for this role is USD $153,000 per year - USD $170,000 per year.
-
You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
-
Ready to Ride?
-
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
-
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
-
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
-
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.