Security Engineer II, Design Review / Threat Modelling

Uber

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Seattle, WASunnyvale, CA
Posted
7 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $177k
$122k $227k
below market most similar roles pay here above market

This listing doesn't post a salary. Most similar roles pay $145,000–$208,800.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 66 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Security Engineer II, Design Review / Threat Modelling

As a Security Engineer II - Design Review / Threat Modelling, you will join the Security Review Team to proactively identify and reduce risk across critical services and emerging technologies. You will perform security design reviews and threat modeling for services, APIs, infrastructure, and AI agents while conducting hands-on penetration testing to validate real-world attack paths. Your daily work involves building AI-powered automation to scale security assessments and translating offensive findings into systemic improvements. You will utilize skills in threat modeling, vulnerability classification, and risk modeling within cloud-native, microservices, and distributed systems. Technical requirements include proficiency in backend languages like Go, Java, or Python, along with experience in multi-cloud environments like AWS or GCP, SQL, NoSQL, and applying LLMs to security engineering workflows.

What does a Security Engineer earn in California?

Median $203125 from 45 postings across 16 companies.

See salary data

What you'll do

  • Conduct security design reviews and threat modeling for services, APIs, infrastructure, and AI systems.
  • Perform hands-on penetration testing to identify exploitable vulnerabilities and complex attack paths.
  • Assess third-party AI agents through adversarial testing to identify risks in behavior and data access.
  • Build AI-powered automation to scale security design reviews and penetration testing efforts.
  • Translate offensive security findings into systemic improvements and actionable guidance for engineering teams.
  • Analyze engineering proposals to identify flaws in cloud, infrastructure, and data-layer security.
  • Provide corrective guidance on complex design trade-offs to improve the overall security posture.

What we're looking for

  • 3+ years of professional experience in security engineering, systems architecture, or a related software engineering field.
  • Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
  • Proven ability to analyze complex system designs and provide technical input to solve security challenges with multiple dependencies.
  • Broad knowledge of threat modeling, vulnerability classification, and risk modeling frameworks.
  • Experience with security designs related to cloud-native services, microservices, or distributed systems.
  • Hands-on experience performing security design reviews and threat modeling across complex applications, services, APIs, and cloud infrastructure (preferred).
  • Advanced proficiency in at least one backend language such as Go, Java, or Python to evaluate code-level security (preferred).
  • Experience applying AI/LLMs, agents, or automation frameworks to security testing or vulnerability discovery (preferred).

More like this

Similar roles

Staff Security Engineer

Uber

San Francisco, CA +2 16 days ago
Offensive Security Penetration Testing Threat Modeling AI LLMs Microservices APIs Distributed Systems Security Design Review Automation Secure Software Development Lifecycle Device Attestation
7+ yrs exp Hybrid

Senior Lead Security Engineer, Threat Modelling

JPMorgan Chase

Wilmington, DE +3 16 days ago
Python Go Java C/C# AWS GCP Azure Kubernetes Terraform Ansible CI/CD Jenkins GitHub Actions Git BitBucket Jira DevSecOps Infrastructure as Code Zero Trust STRIDE DREAD PASTA MITRE ATT&CK NIST CIS GDPR CCPA
5+ yrs exp

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 101 days ago $90,000–$154,000
Incident Response Python Sentinel Defender Azure Kubernetes Mitre Att&ck EOP
4+ yrs exp Hybrid

Security Engineer II

F5 Inc

Reston, VA 5 days ago $104,700–$157,100
SIEM EDR AWS Azure Kubernetes Python Go Shell Grafana Splunk DataDog Sumo Logic CrowdStrike CI/CD DevSecOps NGINX WAF FedRAMP MITRE ATT&CK
3+ yrs exp Hybrid

Security Engineer II

Microsoft

Remote 30 days ago $102,100–$202,200
C C++ Penetration Testing Vulnerability Research Code Review OS Security Windows Architecture Security Engineering Network Protocols Security Mitigations
2+ yrs exp Remote