Staff Security Engineer - Engineer
About the role and team
Engineering at Uber means building for real-world impact under real-world constraints. The problems are complex, the systems are massive, and the pace is fast. You’ll need to make smart decisions with imperfect information — and own them. If you think in systems, stay calm under pressure, and care about building things that actually work — this is where you’ll grow.
As a Staff Security Engineer, you will safeguard user-facing products by leveraging AI and ML to identify evolving threats. You will architect and scale industry-leading solutions while navigating the "messy" reality of heterogeneous data and shifting adversary behaviors. This role is for a technical leader who can stay steady during high-stakes incident investigations and move with urgency to build proactive security frameworks.
What you’ll do
- Architect and scale sophisticated security services and frameworks designed to neutralize evolving threats across Uber's global ecosystem.
- Navigate high-stakes incident investigations by performing in-depth threat analysis and driving root cause analysis across complex, hybrid-cloud environments.
- Innovate and write high-quality, modular code to automate detection logic and scale response capabilities using Python, Go, or Ruby.
- Champion engineering excellence by establishing standards for detection rules, query optimization, and technical documentation within the organization.
- Collaborate across disciplines—including Network Ops, Incident Response, and Product—to influence security posture without direct authority.
- Own the transition from research to production by experimenting with new AI/ML techniques to continuously enhance our cyber defense capabilities.
Basic Qualifications
- 8+ years of professional experience in security engineering, threat detection, or client platform engineering.
- Demonstrated expertise in designing, building, and tuning detection systems (rules, anomaly models, correlation logic) across log, network, and endpoint telemetry, with a track record of improving detection coverage and signal fidelity while reducing false-positive burden on responders.
- Proven ability to solve strategically important problems by providing concrete technical input into code and systems across multiple teams.
- Demonstrated experience leading cross-functional security and privacy projects through all stages: inception, requirement gathering, threat modeling, and global operations.
- Expertise in defining standards for security/privacy, testing, monitoring, and alerting systems, while leading teams to execute against them.
- Ability to direct incident management as a high-level escalation point for other engineers, identifying and adopting best practices in incident response across teams.
- Demonstrated skill in making complex engineering and risk tradeoffs (e.g., Security/Privacy vs. Velocity, Buy vs. Build) with an understanding of short and long-term implications.
- Proven track record of technical writing and review, including ERDs, developer documentation, and post-mortems that meet business and compliance goals.
- Education: Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field.
Preferred Qualifications
- Master’s degree or PhD in a technical field and 10+ years of experience in a cybersecurity leadership or staff-level role.
- Deep knowledge of Cybersecurity, Compliance, and Privacy, with experience chaining vulnerabilities and quantifying risks.
- Experience collaborating with EMs, TPMs, and PMs on prioritization, headcount planning, and technical evaluation of team members.
- Advanced expertise in leveraging AI/ML for security use cases and building device attestation or trust tooling at a global scale.
- Strategic relationship builder: Proven ability to leverage collaborative relationships with legal, product, and engineering stakeholders to build trust and accomplish work.
Responsibilities
For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Ready to Ride?
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

