Skip to content

Open nowPosted 4 days ago

Security Engineer II - Design Review/Threat Modeling

Uber161 open roles

Where
Seattle, WA, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer II - Design Review/Threat ModelingUber · Seattle, WA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Uber's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Uber postings stay open a median of 35 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 33.9%30 days
This job: posted 4 days ago

Uber median: 35 days open

The posting

Job Description

About the role and team:

As a member of Uber’s Security Review Team, you will work across multiple security disciplines to proactively identify and reduce risk in Uber’s most critical services and emerging technologies. You will perform security design reviews and threat modeling for critical services and AI agents, conduct hands-on penetration testing to validate real-world attack paths, and help build AI-powered automation that transforms how these security assessments are performed at scale. This role combines deep technical security expertise with an automation-first mindset, helping evolve traditional point-in-time assessments toward continuous, scalable security testing across Uber’s technology ecosystem.

This isn't a "set and forget" role. Our environment is fast-moving and the threats are constantly evolving. You will navigate the "messy" reality of hybrid cloud and distributed systems, conducting technical security design reviews as part of our secure software development lifecycle. We are looking for a technically curious engineer who thrives in ambiguity, takes extreme ownership of their work, and has the grit to stay ahead of sophisticated adversaries. If you are motivated by high-stakes challenges and want to build a more secure future for movement - this is where you’ll grow.

What you’ll do

  • Conduct security design reviews and threat modeling across Uber’s diverse codebase, evaluating security risks in services, applications, APIs, infrastructure, mobile platforms, AI systems, and other production software.
  • Assess third-party AI agents, including coding and work-focused agents, through adversarial testing to identify security risks in agent behavior, tool use, data access, permissions, prompt injection, and external integrations.
  • Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths
  • Design and build AI-powered automation for security design reviews, threat modeling, penetration testing, increasing the scale, frequency, and depth of Offensive Security assessments.
  • Partner with engineering and security teams to translate offensive security findings into systemic improvements, helping eliminate vulnerability classes and strengthen security controls across Uber’s technology ecosystem.
  • Perform multi-disciplinary security design reviews of engineering proposals, analyzing cloud, infrastructure, application, and data-layer security.
  • Navigate complex design trade-offs to provide corrective guidance that improves the overall security posture of Uber’s products and services.
  • Collaborate with engineering teams across the company to analyze design documents and identify potential flaws before they reach production.
  • Translate technical security findings into actionable guidance for both engineering and non-technical stakeholders to ensure alignment and impact.
  • Conduct comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.
  • Champion engineering best practices and serve as a security ambassador, helping teams move fast while building with integrity and care.

Basic Qualifications

  • 3+ years of professional experience in security engineering, systems architecture, or a related software engineering field.
  • Proven ability to analyze complex system designs and provide technical input to solve security challenges with multiple dependencies.
  • Broad knowledge of threat modeling, vulnerability classification, and risk modeling frameworks.
  • Experience with security designs related to cloud-native services, microservices, or distributed systems.
  • Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.

Preferred Qualifications

  • Hands-on experience performing security design reviews and threat modeling across complex applications, services, APIs, distributed systems, cloud infrastructure, and mobile platforms.
  • Demonstrated ability to identify complex attack paths and systemic security weaknesses by reasoning across application, infrastructure, identity, data, and trust boundaries.
  • Experience conducting code-assisted security reviews, using source code to validate architectural assumptions, security controls, data flows, authorization boundaries, and potential vulnerabilities.
  • Experience reviewing large-scale distributed and cloud-native architectures, including microservices, service-to-service authentication, APIs, messaging systems, data stores, and multi-cloud environments.
  • Advanced proficiency in at least one backend language such as Go, Java, or Python to evaluate code-level security.
  • Hands-on experience with multi-cloud environments (e.g., AWS, GCP) and data store technologies (SQL or NoSQL).
  • Experience applying AI/LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or other security engineering workflows.
  • Strong systems thinking with the ability to simplify complex technical concepts and influence without authority.
  • Experience working within an automated CI/CD environment or a mature Secure Software Development Lifecycle (S-SDLC).

Responsibilities

For Seattle, WA-based roles: The base salary range for this role is USD $171,000 per year - USD $190,000 per year.

You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.

About Us

Ready to Ride?

This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.

You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.

Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.

Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Uber's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Uber's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Uber's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.