Staff Security Strategist GRC

Uber

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
San Francisco, CASunnyvale, CA
Posted
11 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $184k
$130k most similar roles pay here $231k

This listing doesn't post a salary. Most similar roles pay $152,112–$215,925.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 53 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Staff Security Strategist GRC

Staff Security Strategist GRC joins the Tech Risk and Assurance team within Engineering Security to strengthen cybersecurity posture through scalable risk management, governance, and control design. This role sits at the intersection of technical security and process design, where the individual will translate complex threat contexts and compliance requirements into actionable treatment plans for engineering teams. Key responsibilities include managing the ServiceNow eGRC platform, overseeing cyber risk intake and prioritization, developing product strategies for risk tools, and automating workflows to improve efficiency. The candidate will utilize skills in risk quantification, control framework knowledge such as NIST and ISO 27001, and technical proficiency in Python, SQL, and data analytics. This role solves the challenge of transforming high-level security risks into practical engineering actions while ensuring consistent risk analysis across various internal systems.

What you'll do

  • Own cyber risk intake, triage, and prioritization to ensure clear accountability and timely treatment decisions.
  • Manage and improve risk and compliance programs on the ServiceNow eGRC platform.
  • Partner with engineering teams to define and execute practical risk treatment plans for technical vulnerabilities.
  • Gather functional requirements from stakeholders to develop technical specifications and product releases.
  • Lead control design reviews, risk assessments, and high-level decision-making involving stakeholder alignment.
  • Automate risk workflows and improve operational efficiency through better tooling and reusable knowledge assets.
  • Build and maintain risk reporting dashboards, including KRIs and exposure trends for leadership.
  • Mentor junior security partners on risk analysis, treatment planning, and communication.

What we're looking for

  • Bachelor's or Master's degree in Computer Science, Engineering, Information Systems, Cybersecurity, Risk Management, or a related field, or equivalent practical experience.
  • 10+ years of experience in security, cyber risk, GRC, assurance, security operations, or related technical risk roles.
  • Security certifications such as CISA, CISSP, CISM, or other relevant certifications.
  • Demonstrated success managing security risk programs, treatment decisions, and cross-functional execution end to end.
  • Strong understanding of security controls, risk treatment, and engineering implementation details.
  • Excellent written and verbal communication skills for presenting to leadership and technical audiences.
  • Experience with ServiceNow eGRC platform, other GRC/ERM tools, or risk quantification methodologies (preferred).
  • Knowledge of control frameworks like NIST CSF, NIST 800-53, ISO 27001, NIST RMF, SOC 2, or CIS (preferred).

More like this

Similar roles

Staff Security Strategist GRC

Uber

San Francisco, CA +1 11 days ago
ServiceNow eGRC Python SQL NIST CSF NIST 800-53 ISO 27001 NIST RMF SOC 2 CIS Agile Data Analytics Workflow Automation Risk Quantification AuditBoard Archer OpenPages SAP GRC
10+ yrs exp

Security Engineer, GRC

Plaid

San Francisco, CA +2 80 days ago $156,000–$213,600
Python SQL AWS Terraform CI/CD OPA Rego Sentinel Policy-as-Code OpenAI Claude SOC 2 ISO 27001 NIST CSF FedRAMP Mode GitHub API

Staff Security Engineer

Uber

San Francisco, CA +2 10 days ago
Penetration Testing Threat Modeling AI LLMs Microservices Distributed Systems Cybersecurity
7+ yrs exp

Principal GRC Cyber Risk Management

Northern Trust

Tempe, AZ 86 days ago
NIST CSF FAIR MITRE ATT&CK ISO 27001 Cyber Risk Management Cyber Threat Intelligence Data Analytics Automation Artificial Intelligence Risk Reporting KRIs KCIs CISSP CISM CRISC
10+ yrs exp

Senior Security GRC Analyst

Salesforce

Remote (Herndon, VA) 33 days ago $117,200–$176,700
Information Security Cybersecurity FedRAMP DoD SRG AWS Azure GCP SaaS IaaS PaaS Compliance Engineering AI Scripting Incident Response Security Operations Agile
4+ yrs exp Remote