Senior Security Engineer, Application Security

Uber

Quick summary

Work type
On-site
Location
Seattle, WANew York, NYSan Francisco, CASunnyvale, CA
Posted
25 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $183k
$133k most similar roles pay here $230k

This listing doesn't post a salary. Most similar roles pay $149,687–$216,000.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 45 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Senior Security Engineer, Application Security

Uber seeks a Senior Security Engineer to join its Application Security team in New York, Seattle, or San Francisco. This senior-level position involves designing and deploying next-generation security automation, including AI-driven vulnerability scanning and intelligent asset indexing, to enhance Uber’s application ecosystem. Day-to-day responsibilities include building large-scale automation for discovering and remediating vulnerabilities, developing end-to-end systems for secret discovery and code scanning, and collaborating with cross-functional teams to integrate security capabilities into the platform. The ideal candidate has 5+ years of software engineering experience, strong programming skills in Go, Java, C, or Python, and a solid understanding of service-oriented architectures. Additional preferred qualifications include expertise in distributed system design, real-time data pipelines, and threat modeling. This role offers significant impact on Uber’s security posture and opportunities for mentorship and professional growth.

What you'll do

  • Design and deploy large-scale automation to discover and remediate security vulnerabilities.
  • Develop end-to-end systems for application security platforms including secret discovery and code scanning.
  • Identify coverage gaps in security-sensitive functionality and automate solutions to address them.
  • Research novel attack techniques and automate their detection using innovative tools.
  • Build distributed backend systems for real-time analytics and data-driven security insights.
  • Mentor junior team members and provide guidance on remediation of identified security issues.

What we're looking for

  • 5+ years of professional experience in software engineering.
  • Strong programming skills in Go, Java, C, or Python.
  • Experience identifying and remediating common security vulnerabilities (OWASP Top 10).
  • Solid understanding of service-oriented and distributed system architectures.
  • Expertise in designing and implementing REST APIs and datastores.
  • Familiarity with distributed messaging systems like Kafka.
  • Experience integrating open-source security scanners and tools.

More like this

Similar roles

Senior Application Security Engineer

Hippo

San Jose, CA +1 68 days ago $151,000$226,250
OAuth2 OIDC SAML JWT MFA CI/CD Kubernetes SAST DAST SCA Python PostgreSQL AWS Azure GitHub Swagger RESTful APIs JSON Web Tokens OWASP Top 10 DevSecOps
Hybrid

Senior Application Security Engineer

Hippo

Austin, TX +1 68 days ago
Python Java OAuth2 OIDC SAML JWT MFA Kubernetes Terraform AWS CI/CD Docker PostgreSQL SAST DAST SCA Prometheus Grafana
Hybrid

Staff Software Engineer

Uber

Seattle, WA +1 40 days ago
Python Golang SQL Kubernetes Docker Terraform AWS CI/CD Prometheus Grafana PostgreSQL Redis Flask FastAPI GraphQL RESTful_APIs OAuth2 JWT OpenID_Connect Git Jenkins Ansible Zap OWASP_Top_10 Django Celery RabbitMQ Kafka Elasticsearch Logstash Kibana Splunk MLflow TensorFlow PyTorch Scikit-learn Pandas NumPy Jupyter_Notebook

Senior Application Security Engineer

Datadog

3 days ago $187,000$240,000
Go Python API security authentication authorization infrastructure security mTLS service identity API gateways CI/CD observability telemetry zero trust architectures policy-based systems large-scale access control models sandboxing agent-based systems
Hybrid