below marketmost similar roles pay hereabove market
This listing doesn't post a salary. Most similar roles pay
$154,450–$215,166.
Based on 240 similar postings.
Employer
About Uber
Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.
As a member of the Security Review Team, the Sr Security Technologist - Security/Privacy Design Reviewer will proactively identify and reduce risk across critical services and emerging technologies. You will conduct hands-on penetration testing, perform security design reviews, and lead threat modeling for applications, APIs, infrastructure, and AI agents. Key responsibilities include analyzing data flows, trust boundaries, and access controls to identify systemic risks and building AI-powered automation to scale security assessments. You will utilize Python, Go, and AI-assisted workflows to transform point-in-time testing into continuous adversarial security testing. The role specifically addresses security and privacy risks in third-party AI agents, evaluating sensitive data handling, prompt injection, and autonomous behavior to ensure robust protection across complex distributed systems and cloud services.
Lead security and privacy design reviews for Uber's services, applications, APIs, infrastructure, and AI systems.
Perform threat modeling to identify attack surfaces, trust boundaries, and complex chained attack paths for high-risk systems.
Conduct hands-on adversarial assessments of third-party AI agents to evaluate risks like prompt injection and data exposure.
Execute code-assisted security reviews and penetration testing to validate architectural assumptions and security controls.
Analyze sensitive-data handling across complex systems to develop safeguards for data collection, storage, and deletion.
Build AI-powered automation and security tooling to scale threat modeling and vulnerability validation workflows.
Develop reusable security methodologies, testing techniques, and frameworks for assessing emerging technologies.
Partner with engineering and privacy teams to drive remediation of identified vulnerabilities and influence architectural decisions.
What we're looking for
5+ years of professional experience in security engineering, application security, product security, offensive security, or related technical security roles.
Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
Demonstrated ability to independently review complex technical designs and architectures to identify systemic security risks across applications, APIs, and cloud services.
Advanced experience performing threat modeling and attack-path analysis across complex systems, including identifying trust boundaries and security assumptions.
Strong knowledge of security and privacy principles, including authentication, authorization, identity, least privilege, and data protection.
Significant hands-on experience with security testing, vulnerability research, penetration testing, or adversarial testing to validate exploitability and security controls.
Proficiency developing security tooling and automation using languages such as Python, Go, or similar, including AI-assisted development.
Advanced experience conducting adversarial security assessments of AI agents, large language model applications, or agentic systems (preferred).
AI Red Teaming
Adversarial Machine Learning
Generative AI
Penetration Testing
Python
C#
C/C++
PowerShell
Kali Linux
Burpsuite
Nmap
Nessus
Vulnerability Research
Anomaly Detection
Threat Analysis
Software Development Lifecycle
Statistics
Predictive Analytics
Azure
AWS
GCP
Python
Go
C#
TypeScript
Terraform
Bicep
CloudFormation
Kubernetes
CI/CD
Active Directory
Entra ID
Okta
Linux
Windows
infrastructure-as-code
Identity Federation
Security Telemetry
Vulnerability Research
Offensive Security
Exploit Development
Reverse Engineering
AI
Threat Analysis
Anomaly Detection
Software Development Lifecycle
Cybersecurity
Capture The Flag (CTF)