Security Engineer II, Design Review & Threat Modelling

Uber

Confirmed live today High trust

Quick summary

Work type
On-site
Location
San Francisco, CASeattle, WASunnyvale, CA
Posted
2 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $176k
$120k most similar roles pay here $224k

This listing doesn't post a salary. Most similar roles pay $146,150–$206,546.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 56 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Security Engineer II, Design Review & Threat Modelling

As a member of the Security Review Team, the Security Engineer II - Design Review / Threat Modelling will proactively identify and reduce risk across critical services and emerging technologies. The role involves performing security design reviews, threat modeling for AI agents, and hands-on penetration testing to validate real-world attack paths. You will build AI-powered automation to scale security assessments while navigating hybrid cloud and distributed systems within a secure software development lifecycle. Key responsibilities include evaluating infrastructure, APIs, mobile platforms, and data layers to eliminate vulnerability classes. Required skills include expertise in threat modeling, risk modeling frameworks, and experience with cloud-native services or microservices. Preferred qualifications include proficiency in Go, Java, or Python, familiarity with AWS or GCP environments, and experience applying LLMs or automation frameworks to security testing and vulnerability discovery across complex distributed architectures.

What does a Security Engineer earn in California?

Median $203125 from 45 postings across 19 companies.

See salary data

What you'll do

  • Perform security design reviews and threat modeling for services, infrastructure, and AI systems.
  • Conduct hands-on penetration testing to identify exploitable vulnerabilities across applications, APIs, and mobile platforms.
  • Execute adversarial testing on third-party AI agents to identify risks in behavior and data access.
  • Build AI-powered automation to scale security design reviews and offensive security assessments.
  • Translate technical security findings into actionable guidance for both engineering and non-technical stakeholders.
  • Partner with engineering teams to implement systemic improvements that eliminate entire classes of vulnerabilities.
  • Analyze complex system designs to provide corrective guidance on cloud, infrastructure, and data-layer security.

What we're looking for

  • 3+ years of professional experience in security engineering, systems architecture, or a related software engineering field.
  • Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
  • Proven ability to analyze complex system designs and provide technical input to solve security challenges with multiple dependencies.
  • Broad knowledge of threat modeling, vulnerability classification, and risk modeling frameworks.
  • Experience with security designs related to cloud-native services, microservices, or distributed systems.
  • Hands-on experience performing security design reviews and threat modeling across complex applications, APIs, infrastructure, and mobile platforms (preferred).
  • Advanced proficiency in at least one backend language such as Go, Java, or Python (preferred).
  • Experience applying AI/LLMs, agents, or automation frameworks to security testing or engineering workflows (preferred).

More like this

Similar roles

Security Technologist II, Design Review

Uber

Seattle, WA 3 days ago
Penetration Testing Threat Modeling Python Go Bash Application Security Offensive Security Automation Prompt Injection Distributed Systems
3+ yrs exp

Senior Lead Security Engineer, Threat Modelling

JPMorgan Chase

Wilmington, DE +3 11 days ago
AWS GCP Azure Python Go Java C# Kubernetes Terraform Ansible CI/CD Git Jenkins GitHub Actions Jira Zero Trust DevSecOps Infrastructure as Code STRIDE DREAD PASTA MITRE ATT&CK NIST CIS
5+ yrs exp

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 96 days ago $90,000–$154,000
Incident Response Sentinel Defender Azure Kubernetes Python Mitre Att&ck Automation Detection Engineering
4+ yrs exp

Security Engineer II

F5 Inc

Remote (Reston, VA) 27 days ago $104,700–$157,100
SIEM EDR AWS GuardDuty Sumo Logic Grafana CrowdStrike DataDog Splunk Thycotic AWS Microsoft Azure Google Cloud Platform Python Shell Go Kubernetes OpenStack CI/CD DevSecOps NGINX WAF
3+ yrs exp Remote

Security Engineer II

Microsoft

Remote 26 days ago $102,100–$202,200
C C++ Windows Penetration Testing Code Review Vulnerability Research Offensive Security Security Engineering Network Protocols Operating Systems
2+ yrs exp Remote

Security Engineer II

F5 Inc

Remote (Reston, VA) 27 days ago $104,700–$157,100
SIEM EDR AWS GuardDuty Sumo Logic Grafana CrowdStrike DataDog Splunk Thycotic AWS Microsoft Azure Google Cloud Platform IaC Kubernetes OpenStack NGINX WAF Cyber Kill Chain
3+ yrs exp Remote