Security Technologist II, Design Review

Uber

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Seattle, WA
Posted
3 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $181k
$129k most similar roles pay here $225k

This listing doesn't post a salary. Most similar roles pay $151,106–$211,400.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 56 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Security Technologist II, Design Review

As a member of the Security Review Team, the Security Technologist II - Design Review will proactively identify and reduce risk across critical services and emerging technologies. The role involves conducting security and privacy design reviews for applications, APIs, and AI integrations while performing threat modeling to identify attack surfaces and trust boundaries. You will perform hands-on adversarial testing on third-party AI agents to evaluate risks like prompt injection and unauthorized data exposure. To scale these efforts, you will build AI-powered automation and security tooling using Python, Go, or Bash. Key responsibilities include evaluating sensitive data handling, documenting actionable findings for engineering teams, and developing reusable assessment materials. The role addresses the challenge of moving from point-in-time testing toward continuous, scalable adversarial security testing across a complex technology ecosystem involving cloud services and distributed systems.

What you'll do

  • Conduct security and privacy design reviews for services, applications, APIs, and AI integrations.
  • Perform threat modeling to identify attack surfaces and potential paths for critical services and AI agents.
  • Execute hands-on adversarial testing on third-party AI agents to evaluate risks like prompt injection and data exposure.
  • Evaluate sensitive-data handling practices across systems to ensure compliance with privacy requirements.
  • Document actionable findings with clear risk assessments and practical remediation guidance for engineering teams.
  • Build AI-powered automation and security tooling to scale assessment processes and reduce repetitive tasks.
  • Develop reusable assessment materials, including checklists and test cases, to standardize team workflows.

What we're looking for

  • 3+ years of experience in security engineering, application security, product security, offensive security, or related technical roles.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
  • Experience reviewing technical designs and identifying risks in applications, APIs, cloud services, or distributed systems.
  • Experience performing threat modeling, analyzing attack paths, and recommending mitigations based on risk and impact.
  • Understanding of security and privacy principles including authentication, authorization, least privilege, and sensitive data protection.
  • Hands-on experience with security testing, vulnerability investigation, or validating the effectiveness of security controls.
  • Experience writing code or automation in Python, Go, Bash, or similar, and familiarity with AI-assisted development workflows.
  • Ability to communicate technical findings clearly to both technical and non-technical audiences.
  • Experience conducting assessments of third-party AI agents, LLM applications, or systems interacting with external tools (preferred).
  • Experience performing privacy design reviews and evaluating data flows for sensitive information (preferred).
  • Experience assessing AI-specific risks like prompt injection or unintended data disclosure (preferred).
  • Experience building internal security tooling or using AI to automate design analysis and threat modeling (preferred).
  • Experience assessing security across interconnected cloud services, enterprise SaaS platforms, and third-party integrations (preferred).
  • Experience coordinating multiple assessments and driving findings through remediation with engineering teams and vendors (preferred).

More like this

Similar roles

Security Researcher II

Microsoft

Redmond, WA 55 days ago $102,100–$202,200
Digital Forensics Threat Hunting Kusto Query Language (KQL) SQL Jupyter Notebooks Azure GitHub Azure DevOps Splunk Humio Kibana Windows Linux macOS Cybersecurity
2+ yrs exp

IT Security Engineer II

Endeavor Health

Skokie, IL +2 27 days ago
SIEM EDR XDR SOAR IDS IPS DLP CSPM CNAPP HIPAA PCI NIST Vulnerability Management System Hardening Identity Security Cloud Security Incident Response
3+ yrs exp Hybrid

IT Security Specialist II

University of Miami

Miami, FL 119 days ago
Vulnerability Management Threat Intelligence Incident Response PCI-DSS Qualys Tenable Rapid7 Malware Analysis Threat Hunting Digital Forensics CISA Advisories ISACs Security Assessment Risk Management
5+ yrs exp Hybrid