Staff Security Technologist - Incident Commander
About the Role
As a Staff Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation - and owning the operational and technical effectiveness of the incident-command function. This role will sit in either our Seattle, San Francisco, or Sunnyvale office.
You operate at the intersection of Fire Captain, NTSB Investigator, and hands-on technical practitioner. In the moment, you take command - setting strategy, assigning resources, and making high-consequence decisions under pressure. After the smoke clears, you drive deep technical investigation and post-incident analysis to ensure we understand not just what happened, but why it happened, and that meaningful, durable fixes are made.
This is not a passive coordination role. You are expected to be technically credible, decisive in ambiguity, and comfortable owning outcomes when there is no playbook. As a technical domain and cultural leader, you drive the priorities, goals, and delivery of a significant incident response program spanning multiple high-complexity projects. You align Security Technologists and partner teams across Engineering Security and adjacent functions - raising the technical bar, establishing reusable frameworks and best practices, and modernizing tooling and workflows to reduce risk across Uber.
What the Candidate Will Do
- Command the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.
- Participate in an on-call rotation where you are expected to make real-time decisions with incomplete information, balancing speed, risk, and impact, and model decisive, responsible action that keeps responders and stakeholders moving.
- Act as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus while providing technical oversight to engineers and Security Technologists working across parallel response and remediation efforts.
- Transition seamlessly between executive-level incident leadership and hands-on technical investigation, including log analysis, system interrogation, and root cause validation across complex systems and security domains.
- Serve as the primary interface to senior leadership during critical incidents, translating evolving technical realities into concise, audience-aware updates with clear knowns, unknowns, risks, tradeoffs, and decisions needed. Align stakeholders and seek guidance from senior leaders as appropriate.
- Build and maintain strong working relationships with global engineering, infrastructure, legal, privacy, and operations teams to enable fast, coordinated response, aligning competing goals and translating business needs, risks, and threats into actionable response requirements.
- Conduct rigorous post-incident analysis in the spirit of an NTSB investigation - focused on systemic causes, contributing factors, and concrete prevention. Drive cross-team remediation with accountable owners, timelines, and validation of durable risk reduction.
- Serve as a cultural and technical leader, actively mentoring responders, incident leaders, and promising engineers and architects. Share domain expertise and coach effective communication, sound decisions under uncertainty, and greater cross-organizational impact.
- Own the priorities, goals, and delivery of a significant incident response program with multiple high-complexity projects, in partnership with Senior Manager and Director+ stakeholders. Align Security Technologists across related and adjacent efforts, provide technical and architectural direction, and proactively deliver improvements, including:
- High-fidelity incident simulations and technical tabletop exercises that develop responders, expose readiness gaps, and turn incident learnings into validated improvements
- Threat-informed response planning and scenario development, supported by reusable frameworks, playbooks, documentation, and tutorials that enable other teams to leverage your work independently
- ‘Left of boom’ threat modeling and pre-mortems to prevent incidents before they occur, translating attack paths and business risk into preventive controls and measurable risk reduction
- Improvements to detection, containment, and response automation that solve classes of recurring problems and create broadly reusable solutions adopted by multiple teams
- Adoption of new investigative techniques and tooling, including AI-assisted workflows, with source validation, data protection, and human decision gates. Establish and promote response best practices across the group
Basic Qualifications
- 8+ years in security operations, detection, or incident response roles at scale, with demonstrated ownership of ambiguous, large, complex, high-impact incidents and significant, high-complexity, multi-team programs.
- Recognized technical domain expertise in incident response, with deep familiarity with modern attacker TTPs and how they manifest across logs, systems, networks, endpoints, and applications. Ability to translate business problems, risk, and threats into security requirements and effective response solutions.
- Strong technical investigation skills - comfortable working directly with logs, telemetry, and raw system data to validate hypotheses and determine root cause, with the technical depth and breadth to resolve undefined, high-risk problems with little existing structure.
- Experience briefing executives during active incidents and aligning technical and non-technical stakeholders at all levels, with concise, informative, audience-appropriate communication of tradeoffs, risks, decisions, and recommended actions.
- Experience designing or running technical incident simulations (tabletops, purple team exercises, or similar) that stress real-world response capabilities and turn findings into implemented, validated improvements across multiple teams.
- Experience building or leveraging AI-driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support, with safeguards for data sensitivity, source verification, and human accountability.
Preferred Qualifications
- Demonstrated experience leading other responders through direct command during incidents and longer-term technical mentorship of responders, engineers, and architects, helping others increase their impact beyond their immediate team.
- Strong bias for action and continuous improvement - proactively identifying and resolving complex operational or organizational gaps, enabling peers and stakeholders to make sound decisions under uncertainty, responding promptly, and following through on commitments.
- Experience responding to incidents in highly distributed, cloud-scale environments where blast radius and coordination complexity are significant, and driving improvements across multiple teams and adjacent functions.
- Broad security domain knowledge (infrastructure, endpoint, product, identity, data) and the ability to reason across them during incidents, developing frameworks, patterns, and methodologies that reduce risk across the company.
- Ability to script or code (Python, Go, or similar) to automate response tasks, prototype broadly reusable tooling, or close investigation and operational gaps.
Responsibilities
For San Francisco, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year.
You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Ready to Ride?
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

