Staff Security Engineer, Vulnerability Management

Uber

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Seattle, WANew York, NYSunnyvale, CASan Francisco, CA
Posted
70 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $184k
$128k most similar roles pay here $235k

This listing doesn't post a salary. Most similar roles pay $151,475–$215,759.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 56 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Staff Security Engineer, Vulnerability Management

Staff Security Engineer - Vulnerability Management will join the security team to lead the evolution of the Risk-Based Vulnerability Management platform. This role involves architecting next-generation systems to identify, prioritize, and remediate exposure across a massive digital footprint including on-prem, cloud, containers, and corporate endpoints. The engineer will build automated remediation workflows, integrate vulnerability scanning into CI/CD pipelines for shift-left initiatives, and leverage LLMs and AI agents for triage and impact analysis. Key responsibilities include developing security posture management tools, managing vulnerability governance with compliance teams, and performing deep technical analysis of complex vulnerabilities. Required skills include expertise in Golang, Java, or Python to build distributed systems, along with experience in container security, cloud-native infrastructure, and software supply chain security. The role focuses on solving the challenge of large-scale threat exposure management.

What does a Security Engineer earn in New York?

Median $192000 from 30 postings across 11 companies.

See salary data

What you'll do

  • Architect and scale Risk-Based Vulnerability Management (RBVM) platforms across on-prem, cloud, container, and endpoint environments.
  • Build automated remediation workflows to reduce response times for emerging threats across decentralized teams.
  • Integrate vulnerability scanning into CI/CD pipelines and development workflows to enforce "Shift-Left" security policies.
  • Leverage LLMs and AI agents for automated triage, impact analysis, and generating context-aware remediation instructions.
  • Mature vulnerability standards, SLAs, and risk exception processes in partnership with Compliance and IT teams.
  • Analyze complex vulnerabilities to determine true risk, identify false positives, and drive informed remediation decisions.
  • Develop infrastructure for tracking external attack surface management and software supply chain security.

What we're looking for

  • 7+ years of industry experience in software development focused on large-scale security or infrastructure engineering.
  • Expertise in building distributed systems and high-availability security platforms using Golang, Java, or Python.
  • Proven track record of designing and operating vulnerability management tools at scale.
  • Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines.
  • Experience leading cross-functional security initiatives and mentoring senior engineering staff.
  • Hands-on experience developing Risk-Based Vulnerability Management (RBVM) frameworks and automated prioritization logic (preferred).
  • Knowledge of AI/ML applications in security for vulnerability triage or large-scale data analysis (preferred).
  • Experience with External Attack Surface Management (EASM) and Software Supply Chain Security (SSCS) (preferred).

More like this

Similar roles

Staff Security Engineer, Vulnerability Management

GEICO

Seattle, WA +3 109 days ago $110,000–$230,000
Vulnerability Management Security Engineering Python Go Java SQL CI/CD DevSecOps SIEM SOAR Containers Distributed Systems Threat Modeling Offensive Security PCI NYDFS
8+ yrs exp Hybrid

Security Engineer (Vulnerability Management)

SpaceX

Starbase, TX +1 10 days ago
Python Go C# C/C++ Rust Bash PowerShell Bugcrowd HackerOne Web Application Security Threat Intelligence CVSS AWS Azure GCP infrastructure-as-code TCP/IP DNS HTTP/S Linux Windows macOS OT Security

Vulnerability Management Engineer

SoFi

San Francisco, CA 31 days ago $99,200–$186,000
Vulnerability Management AppSec SAST DAST AWS Python Go Bash Java CI/CD OWASP CVE CVSS Agile

Senior Vulnerability Management Engineer

SoFi

Seattle, WA +1 31 days ago $124,800–$234,000
Vulnerability Management Kubernetes Python Go Java Bash SCA SAST DAST CI/CD Qualys Helm Maven Gradle Webhooks OWASP CVE CVSS CWE
4+ yrs exp

Senior Vulnerability Management Engineer

LPL Financial

Fort Mill, NC +4 24 days ago $100,631–$167,787
Vulnerability Management Qualys InsightVM Rapid7 Wiz Nessus AWS Azure Cloud Platform Cloud Security Posture Management Linux UNIX VM Ware ESX Citrix Oracle SQL Server DB2 IMS Microsoft Platform Containers Serverless
5+ yrs exp Hybrid