About the role and team:
As a member of Uber’s Offensive Security team, you will work across multiple security disciplines to proactively identify and reduce risk in Uber’s most critical services and emerging technologies. You will perform security design reviews and threat modeling for critical services and AI agents, conduct hands-on penetration testing to validate real-world attack paths, and help build AI-powered automation that transforms how these security assessments are performed at scale. This role combines deep technical security expertise with an automation-first mindset, helping evolve traditional point-in-time assessments toward continuous, scalable security testing across Uber’s technology ecosystem.
This isn't a "set and forget" role. Our environment is fast-moving and the threats are constantly evolving. You will navigate the "messy" reality of hybrid cloud and distributed systems, conducting technical security design reviews as part of our secure software development lifecycle. We are looking for a technically curious engineer who thrives in ambiguity, takes extreme ownership of their work, and has the grit to stay ahead of sophisticated adversaries. If you are motivated by high-stakes challenges and want to build a more secure future for movement - this is where you’ll grow.
What you’ll do
Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths.
Conduct security design reviews and threat modeling for AI agents and agentic systems, evaluating risks across models, tools, data, permissions, external integrations, and runtime behavior.
Design and build AI-powered automation for security design reviews, threat modeling, penetration testing, and vulnerability validation, increasing the scale, frequency, and depth of Offensive Security assessments.
Partner with engineering and security teams to translate offensive security findings into systemic improvements, helping eliminate vulnerability classes and strengthen security controls across Uber’s technology ecosystem.
Perform multi-disciplinary security design reviews of engineering proposals, analyzing cloud, infrastructure, application, and data-layer security.
Navigate complex design trade-offs to provide corrective guidance that improves the overall security posture of Uber’s products and services.
Collaborate with engineering teams across the company to analyze design documents and identify potential flaws before they reach production.
Translate technical security findings into actionable guidance for both engineering and non-technical stakeholders to ensure alignment and impact.
Conduct comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.
Champion engineering best practices and serve as a security ambassador, helping teams move fast while building with integrity and care.
Basic Qualifications
Preferred Qualifications
For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For Seattle, WA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For Sunnyvale, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.