Security Technologist II - Privacy Design Review
- Location
- San Francisco, California / Seattle, Washington / Sunnyvale, California
- Team
- Engineer
- Subteam
- Information Security
- Posted on
- Oct 2, 2026
About the Role
As a member of Uber’s Security Review Team, you will proactively identify and reduce risk across Uber’s most critical services and emerging technologies. You will conduct hands-on penetration testing to identify and validate real-world attack paths, perform security design reviews and threat modeling for critical services and AI agents, and partner with engineering teams to drive effective remediation.
You will also help transform how offensive security operates at scale by building AI-powered automation and security tooling that makes assessments faster, more continuous, and more comprehensive. This role combines deep technical security expertise with an automation-first engineering mindset, evolving traditional point-in-time testing toward continuous, scalable adversarial security testing across Uber’s technology ecosystem.
This position focuses on security and privacy design reviews, threat modeling, and hands-on testing of third-party AI agents. The ideal candidate is comfortable analyzing technical designs, evaluating how systems handle sensitive data, identifying potential attack paths, and translating findings into practical recommendations. You’ll work closely with engineering, security, privacy, and third-party partners to address risks while using AI-assisted workflows and automation to improve assessment quality and scale.
What You'll Do
- Lead complex security and privacy design reviews across Uber services, applications, APIs, infrastructure, and AI systems, independently analyzing architecture, data flows, trust boundaries, access controls, and security assumptions to identify systemic risks early in development.
- Lead threat modeling for critical and high-risk systems, identifying attack surfaces, trust boundaries, abuse cases, complex and chained attack paths, and architectural weaknesses while partnering with engineering teams to design effective mitigations.
- Conduct advanced hands-on adversarial assessments of third-party AI agents and agentic systems, evaluating security risks across models, sensitive data, permissions, tools, external integrations, and runtime behavior, and validating whether weaknesses can result in unauthorized actions, data exposure, or broader system compromise.
- Perform code-assisted security reviews and targeted penetration testing to validate architectural assumptions, security controls, authorization boundaries, and potential attack paths identified during design reviews and threat modeling.
- Lead security and privacy analysis of sensitive-data handling across complex systems and AI integrations, evaluating how data is collected, accessed, processed, stored, shared, retained, and deleted, and partnering with privacy stakeholders to develop appropriate safeguards.
- Own complex security assessments end-to-end, from scoping and technical analysis through risk determination, remediation guidance, stakeholder alignment, and validation of implemented controls.
- Partner directly with engineering teams, security and privacy stakeholders, and third-party vendors to resolve complex security issues, influence architectural decisions, and drive findings through remediation and validation.
- Design and advance AI-powered automation for security design reviews, threat modeling, adversarial testing, and vulnerability validation, transforming expert security analysis into scalable and repeatable workflows that increase assessment depth, consistency, and throughput.
- Develop new assessment methodologies, threat models, testing techniques, security patterns, and reusable frameworks that enable the broader team to consistently assess emerging technologies and evolving attack surfaces.
- Identify recurring vulnerabilities and systemic security weaknesses across assessments and partner with engineering and security teams to develop durable controls that eliminate or reduce entire classes of security risk.
- Serve as a technical security resource for complex assessments, providing guidance and review to other security practitioners, sharing expertise, and helping improve the technical quality and consistency of security assessments across the team.
Basic Qualifications
- 5+ years of professional experience in security engineering, application security, product security, offensive security, or related technical security roles, with demonstrated experience independently leading complex security assessments.
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
- Demonstrated ability to independently review complex technical designs and architectures, identify systemic security risks, and provide security guidance across applications, APIs, cloud services, distributed systems, infrastructure, and third-party integrations.
- Advanced experience performing threat modeling and attack-path analysis across complex systems, including identifying attack surfaces, trust boundaries, security assumptions, chained attack paths, and appropriate mitigations.
- Strong knowledge of security and privacy principles, including authentication, authorization, identity, least privilege, data protection, isolation, trust boundaries, and secure handling of sensitive information.
- Significant hands-on experience with security testing, vulnerability research and investigation, penetration testing, or adversarial testing, including validating exploitability and the effectiveness of security controls.
- Ability to analyze source code, system architecture, APIs, and runtime behavior to validate security assumptions and identify vulnerabilities that may not be apparent through design documentation alone.
- Proficiency developing security tooling and automation using languages such as Python, Go, or similar, with demonstrated ability to use AI-assisted development and automation to improve security assessment workflows.
- Demonstrated ability to independently own complex security assessments from initial scoping and technical analysis through findings, remediation guidance, stakeholder alignment, and validation.
- Strong written and verbal communication skills, with demonstrated ability to explain complex security risks to engineering and non-technical stakeholders, influence technical decisions, and drive remediation across organizational boundaries.
Preferred Qualifications
- Advanced experience conducting adversarial security assessments of AI agents, large language model applications, agentic systems, or systems that interact with external tools, sensitive data, and third-party services.
- Deep understanding of AI-specific attack surfaces and vulnerabilities, including prompt injection, indirect prompt injection, sensitive-data disclosure, excessive agency and permissions, tool misuse, insecure integrations, and unintended autonomous behavior.
- Experience performing complex privacy design reviews and analyzing end-to-end data lifecycles, including data collection, access, processing, storage, sharing, retention, deletion, and enforcement of privacy controls.
- Demonstrated experience identifying complex and chained attack paths across application, identity, infrastructure, cloud, data, and third-party trust boundaries.
- Experience performing code-assisted security reviews and using source code, configuration, APIs, and runtime behavior to validate architectural assumptions, security controls, authorization boundaries, and potential vulnerabilities.
- Advanced experience applying AI/LLMs and agentic workflows to automate or augment security design reviews, threat modeling, vulnerability discovery, adversarial testing, and security control validation.
- Experience designing AI-powered security workflows that autonomously gather technical context, reason across multiple sources, invoke security tools, generate attack hypotheses, validate findings, and produce evidence-backed security assessments.
- Experience building or integrating security knowledge systems that leverage security standards, historical findings, architectural patterns, threat intelligence, and previous assessments to improve AI-assisted security analysis.
- Experience evaluating AI-generated security analysis through benchmarking, regression testing, expert comparison, coverage measurement, false-positive analysis, and other methods for establishing the accuracy and reliability of automated assessments.
- Experience assessing complex security architectures spanning interconnected cloud services, distributed systems, enterprise SaaS platforms, APIs, identity systems, data platforms, and third-party integrations.
- Demonstrated ability to develop reusable security methodologies, threat models, assessment frameworks, testing approaches, and automation that improve the quality, consistency, and scalability of security reviews across a broader organization.
- Experience serving as a technical security resource for other engineers, providing guidance on complex assessments, reviewing security analysis, sharing expertise, and helping raise the technical capabilities of the broader team.
- Demonstrated experience managing multiple complex assessments simultaneously and working directly with engineering teams, security and privacy stakeholders, and third-party vendors to drive findings from discovery through remediation and validation.
For San Francisco, CA-based roles: The base salary range for this role is USD $153,000 per year - USD $170,000 per year.
For Seattle, WA-based roles: The base salary range for this role is USD $153,000 per year - USD $170,000 per year.
For Sunnyvale, CA-based roles: The base salary range for this role is USD $153,000 per year - USD $170,000 per year.
For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Ready to Ride?
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.




