Security Technologist II, Privacy Design Review

Uber

Confirmed live today High trust

Quick summary

Work type
On-site
Location
San Francisco, CASeattle, WASunnyvale, CA
Posted
2 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $183k
$132k most similar roles pay here $240k

This listing doesn't post a salary. Most similar roles pay $149,315–$216,262.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 53 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Security Technologist II, Privacy Design Review

Security Technologist II - Privacy Design Review joins the Security Review Team to proactively identify and reduce risks across critical services and emerging technologies. This role involves conducting hands-on penetration testing, performing security design reviews, and executing threat modeling for infrastructure, APIs, and AI agents. The position focuses on analyzing data flows, trust boundaries, and sensitive data handling while building AI-powered automation and security tooling to scale assessment workflows. Key responsibilities include evaluating third-party AI systems for risks like prompt injection and unauthorized actions, as well as performing code-assisted reviews to validate architectural assumptions. Candidates must possess expertise in Python or Go, along with deep knowledge of authentication, authorization, and privacy principles. The role addresses the challenge of transitioning point-in-time testing toward continuous, automated adversarial security testing across a complex technology ecosystem involving distributed systems and cloud services.

What you'll do

  • Conduct security and privacy design reviews for Uber’s services, infrastructure, and AI systems to identify systemic risks early in development.
  • Perform threat modeling for high-risk systems to identify attack surfaces, trust boundaries, and complex chained attack paths.
  • Execute hands-on adversarial assessments of third-party AI agents and agentic systems to validate security controls and data protection.
  • Conduct code-assisted security reviews and penetration testing to validate architectural assumptions and authorization boundaries.
  • Analyze sensitive data handling across complex systems to ensure compliance with privacy standards and safety requirements.
  • Develop AI-powered automation and tools to scale security design reviews, threat modeling, and vulnerability validation.
  • Create new assessment methodologies, security patterns, and reusable frameworks for the broader security team.
  • Partner with engineering teams and stakeholders to drive findings through remediation and influence architectural decisions.

What we're looking for

  • 5+ years of professional experience in security engineering, application security, product security, offensive security, or related technical roles.
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field (or equivalent practical experience).
  • Demonstrated ability to independently review complex technical designs and architectures across applications, APIs, cloud services, and infrastructure.
  • Advanced experience performing threat modeling and attack-path analysis for complex systems including trust boundaries and security assumptions.
  • Significant hands-on experience with security testing, vulnerability research, penetration testing, or adversarial testing.
  • Proficiency developing security tooling and automation using languages such as Python, Go, or similar to improve assessment workflows.
  • Strong communication skills to explain complex risks to engineering and non-technical stakeholders while driving remediation.
  • Advanced experience conducting adversarial assessments of AI agents and LLM applications (preferred).

More like this

Similar roles

Security Researcher II

Microsoft

Redmond, WA 53 days ago $102,100–$202,200
Digital Forensics Threat Hunting Kusto Query Language (KQL) SQL Jupyter Notebooks Azure GitHub Azure DevOps Splunk Humio Kibana Windows Linux macOS Cybersecurity
2+ yrs exp

Analyst, Privacy

Coinbase

Remote 32 days ago $135,320–$159,200
SQL Python MongoDB Airflow Looker Snowflake Generative AI GDPR CCPA PIPEDA ePrivacy DPIAs PIAs ROPA Incident Management Automation Data Analysis
3+ yrs exp Remote

Senior Privacy Engineer

Upstart

Remote (Canada) 89 days ago $164,800–$228,400
Python Go Java Scala C++ Rust Microservices APIs Data Governance Encryption Anonymization Pseudonymization Machine Learning Data Pipelines Audit Logging Threat Modeling Data Lineage Privacy-by-Design
3+ yrs exp Remote

Privacy Engineer, Level IV

Snap Inc.

Bellevue, WA +3 35 days ago $157,000–$235,000
Differential Privacy Cryptography Machine Learning Data Structures Algorithms Threat Modeling Risk Assessment Distributed Systems Data Governance Privacy-Preserving Computation Security Engineering
2+ yrs exp