Staff Security Strategist GRC

Uber

Confirmed live today High trust

Quick summary

Work type
On-site
Location
San Francisco, CASunnyvale, CA
Posted
11 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $184k
$130k most similar roles pay here $231k

This listing doesn't post a salary. Most similar roles pay $152,112–$215,925.

Based on 240 similar postings.

Employer

About Uber

Uber Technologies, Inc. is the world’s largest, San Francisco-based mobile technology platform facilitating on-demand ride-hailing, food delivery (Uber Eats), and freight transportation across approximately 70 countries.

Uber currently has 53 open roles on FindRole.

Most-posted roles

View all roles at Uber

At a glance

TL;DR · Staff Security Strategist GRC

Staff Security Strategist GRC joins the Tech Risk and Assurance team within Engineering Security to strengthen cybersecurity posture through scalable risk management, governance, and control design. This role operates at the intersection of technical security and process design, where the individual translates complex threat contexts and compliance requirements into actionable treatment plans for engineering teams. Key responsibilities include managing the ServiceNow eGRC platform, developing product strategies for risk tools, automating workflows, and building performance dashboards to track key risk indicators. The candidate will collaborate with developers to implement UI actions and scripts while ensuring security risks become practical engineering actions. Required skills include expertise in GRC frameworks like NIST CSF or ISO 27001, along with proficiency in Python, SQL, and data analysis to improve reporting and automate risk management processes across the organization.

What you'll do

  • Manage cyber risk intake, triage, and prioritization to ensure clear accountability and timely treatment decisions.
  • Develop product strategy and lead execution for Risk and Compliance technology solutions on the ServiceNow eGRC platform.
  • Partner with engineering teams to define risk treatment plans and drive technical remediations to completion.
  • Gather functional requirements from stakeholders to develop technical specifications and deliver high-quality software products.
  • Lead control design reviews, risk assessments, and complex decision-making involving stakeholder alignment and trade-offs.
  • Automate risk workflows and improve system capabilities by analyzing user stories and internal procedures.
  • Build and maintain risk reporting dashboards, including Key Risk Indicators (KRIs) and exposure trends for leadership.
  • Mentor junior security partners on risk analysis, treatment planning, and operational rigor.

What we're looking for

  • Bachelor's or Master's degree in Computer Science, Engineering, Information Systems, Cybersecurity, Risk Management, or a related field, or equivalent practical experience.
  • 10+ years of experience in security, cyber risk, GRC, assurance, security operations, or related technical risk roles.
  • Security certifications such as CISA, CISSP, CISM, or other relevant certifications.
  • Demonstrated success managing security risk programs, treatment decisions, and cross-functional execution end to end.
  • Strong understanding of security controls, risk treatment, and engineering implementation details.
  • Excellent written and verbal communication skills for presenting to leadership and technical audiences.
  • Experience with ServiceNow eGRC platform, other GRC/ERM tools, or Big 4 accounting firm experience (preferred).
  • Proficiency in Python, SQL, data analytics, automation, or knowledge of frameworks like NIST, ISO, and SOC 2 (preferred).

More like this

Similar roles

Staff Security Strategist GRC

Uber

San Francisco, CA +1 11 days ago
ServiceNow eGRC Python SQL Agile NIST CSF NIST 800-53 ISO 27001 NIST RMF SOC 2 CIS Data Analytics Workflow Automation Risk Quantification AuditBoard Archer OpenPages SAP GRC
10+ yrs exp

Security Engineer, GRC

Plaid

San Francisco, CA +2 80 days ago $156,000–$213,600
Python SQL AWS Terraform CI/CD OPA Rego Sentinel Policy-as-Code OpenAI Claude SOC 2 ISO 27001 NIST CSF FedRAMP Mode GitHub API

Staff Security Engineer

Uber

San Francisco, CA +2 10 days ago
Penetration Testing Threat Modeling AI LLMs Microservices Distributed Systems Cybersecurity
7+ yrs exp

Principal GRC Cyber Risk Management

Northern Trust

Tempe, AZ 86 days ago
NIST CSF FAIR MITRE ATT&CK ISO 27001 Cyber Risk Management Cyber Threat Intelligence Data Analytics Automation Artificial Intelligence Risk Reporting KRIs KCIs CISSP CISM CRISC
10+ yrs exp

Senior Security GRC Analyst

Salesforce

Remote (Herndon, VA) 33 days ago $117,200–$176,700
Information Security Cybersecurity FedRAMP DoD SRG AWS Azure GCP SaaS IaaS PaaS Compliance Engineering AI Scripting Incident Response Security Operations Agile
4+ yrs exp Remote