Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Strategist GRC

$211k

Uber

About The Team Uber's Engineering Security team works to ensure the security of information for our full set of users - riders, eaters, drivers and partners. Our ultimate goal is to ensure that every experience with Uber is simple, secure, and safe. We are seeking a talented Staff Security Strategist, GRC to join our Tech Risk and Assurance team within Engineering Security. About The Team Uber's Engineering Security team works to ensure the security of information for our full set of users - riders, eaters, drivers and partners. Our ultimate goal is to ensure that every experience with Uber is simple, secure, and safe. We are seeking a talented Staff Security Strategist, GRC to join our Tech Risk and Assurance team within Engineering Security. About The Role The Staff Security Strategist, GRC partners with engineering, security, and cross-functional risk stakeholders to strengthen Uber's cybersecurity posture through scalable cyber risk management, risk governance, and control design programs. This role is responsible for driving and implementing security, compliance, and risk management programs on the ServiceNow eGRC platform at Uber, working with the engineering team to develop and enable technical solutions that satisfy a variety of risk and compliance processes. This role operates at the intersection of technical security, process design, and risk governance. The successful candidate will translate control gaps, threat and business context, and compliance requirements into practical risk treatment plans that engineering teams can execute, while driving consistent risk analysis, decision-making, and follow-through. The role must be able to deliver work products required by Agile development methodologies for software development delivery as defined. What You Will Do Own cyber risk intake, triage, and prioritization, ensuring clear accountability, well-formed risk statements, and timely treatment decisions. Develop product strategy and lead project execution for multiple major components of Uber's Risk and Compliance technology solutions. Manage different solutions on Uber's internal eGRC platform (ServiceNow) and collaborate with stakeholders to implement their program improvements. Partner with engineering teams to define risk treatment plans, identify sustainable fixes, and drive mitigation or remediation to the last mile rather than stopping at documentation. Gather business and functional requirements from partner teams and deliver a product/release that meets the needs presented. Develop technical specifications documentation. Lead or materially contribute to control design reviews, risk assessments, and risk decisions that require judgment, stakeholder alignment, and tradeoff management. Drive and evangelize vision for overall GRC strategy across engineering and security organizations. Analyze and fully understand user stories and internal procedures in order to improve system capabilities, automate process workflows, and address scheduling limitations throughout the development and delivery of the eGRC platform. Work with developers to implement workflows from customer requirements including workflows, UI actions, client scripts, business rules, etc. Load, manipulate, and maintain data between the eGRC platform and other systems as needed. Build and maintain risk reporting for leaders and partner teams, including KRIs, exposure trends, risk acceptance aging, decision status, and escalation triggers. Design and develop dashboards, home pages, performance analytics data collectors, and reports as needed to support program requirements. Improve the efficiency of risk workflows through automation, better tooling, clearer operating models, and reusable knowledge assets. Perform system and integration testing with sample and live data. Review product performance and provide a continuous improvement path through leveraging industry standard tools and capabilities as well as building new ones. Serve as a bridge between cybersecurity, engineering, audit, privacy, and compliance stakeholders so that security risk becomes practical engineering action. Mentor analysts and junior security partners on risk analysis, risk statement quality, treatment planning, stakeholder communication, and operational rigor. Basic Qualifications Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, Risk Management, or related field, or equivalent practical experience. 10+ years of experience in security, cyber risk, GRC, assurance, security operations, or related technical risk roles. Security certifications e.g. CISA, CISSP, CISM, or other relevant certifications. Demonstrated success managing security risk programs, treatment decisions, and cross-functional execution end to end. Strong understanding of security controls, risk treatment, and how to work with engineering on implementation details. Experience operating across multiple stakeholders, handling ambiguity, and driving accountability. Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision. Excellent written and verbal communication skills, including the ability to present risk, status, and decision points to leadership and technical audiences. Preferred Qualifications CRISC, ISO 27001 Lead Auditor, or comparable additional certifications. Hands-on experience with ServiceNow eGRC platform, including configuration, workflow development, and integration. Experience with other GRC/ERM tooling such as AuditBoard, Archer, OpenPages, or SAP GRC. Big 4 accounting firm and/or internet/technology industry experience. Process management experience, including process redesign and optimization. Proven track record in driving security risk treatment to closure across multiple engineering teams. Ability to leverage AI, data analytics, and workflow automation to improve risk program performance and reporting. Experience with risk quantification methodologies and risk lifecycle tooling. Strong knowledge of control frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, NIST RMF, SOC 2, and CIS. Proficiency in Python, SQL, dashboards, or similar tools for data analysis and reporting. Ability to thrive in environments of uncertainty. For San Francisco, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year. For Sunnyvale, CA-based roles: The base salary range for this role is USD $211,000 per year - USD $234,000 per year. For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits. Ready to Ride? This isn't the kind of place where you follow a playbook - it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves - we'd love to hear from you. You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits. Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements. Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form. #J-18808-Ljbffr Uber

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Staff Security Strategist GRC in San Francisco, CA vacancy
  • Uber seeks a Staff Security Strategist, GRC to strengthen cyber risk governance within the Engineering Security team. The role focuses on scalable risk management, control design, and governance using ServiceNow eGRC, partnering with engineering to translate risk into... 
    Suggested

    Uber

    San Francisco, CA
    4 days ago
  •  .../CCPA/CPRA readiness, and design scalable audit processes to support growth. You will also build a GRC platform and drive cross-functional collaboration with IT, Security and Engineering. The successful candidate will have 6+ years in audit and compliance, demonstrated... 
    Suggested

    B Capital

    San Francisco, CA
    3 days ago
  • Intuit seeks two Staff Customer Experience Strategists to elevate the Workforce Solutions and ASO experiences across SMB and mid-market. You will own end-to-end CX design, partnering with Product, Engineering, CS, Risk, and Finance to align AI-powered and human expertise... 
    Suggested

    Intuit

    San Francisco, CA
    4 days ago
  • $168k - $227k

    Overview We are seeking two exceptional Staff Customer Experience Strategists to elevate the experience for Intuit's expanding Workforce Solutions portfolio, including Advanced Payroll, HR & Worker Management, and our new Administrative Services Organization (ASO). These... 
    Suggested
    Fixed term contract

    Intuit

    San Francisco, CA
    4 days ago
  • $150k - $250k

     ...production capability for leading robotics companies and national-security-critical hardware. Basically, we're building robots that build...  ..., and competitive again. The Role We are hiring a Deployment Strategist to open, own, and grow our most important defense... 
    Suggested
    Full time
    Contract work
    Work at office

    Garuda Ventures

    San Francisco, CA
    4 days ago
  •  ...and reason about any physical activity captured on camera, from security incidents (e.g. perimeter intrusion, theft, LPR), to safety...  ...Tesla, Uber, and the U.S. Special Forces. The Role Deployment Strategists are accountable for delivering value to Specter customers. They... 
    Shift work

    Socket.dev

    San Francisco, CA
    4 days ago
  •  ...contribute where everything begins with data.” Staff Software Engineer (Data Platform) “Every...  ...agencies around the world. Deployment Strategist, Public Sector (Law Enforcement) Location...  ...on TRM to make the world safer and more secure. TRM Labs is building AI-powered... 
    Full time
    For contractors
    Worldwide
    Rotating shift
    Weekday work

    TRM Labs Inc.

    San Francisco, CA
    1 day ago
  •  ...SOC 2. You will work closely with various stakeholders to identify gaps and develop actionable plans to improve the organization's security posture. If you are passionate about cybersecurity and looking to make a significant impact in a dynamic environment, this... 
    Remote job

    Request Technology

    San Francisco, CA
    2 days ago
  • $139.6k - $225.78k

     ...precision that drives great outcomes.Job SummaryJob SummaryWe are seeking a passionate and self-driven Sr. Staff Researcher to join our Cloud-Delivered Security Services team. In this role, you will be pivotal in developing and refining the security content that powers... 
    Full time
    Work experience placement
    Work at office
    Visa sponsorship
    Work visa

    Palo Alto Networks

    San Francisco, CA
    6 days ago
  • Zipline is seeking a Staff Compensation Manager in South San Francisco to drive compensation strategies and support its rapid growth. In this key role, you will lead compensation strategies, conduct market analyses, and partner with leaders across multiple functions to... 

    Namely

    South San Francisco, CA
    5 days ago
  • Pinterest is seeking a Staff Technical Program Manager for Security in the US. You will lead high-impact security programs spanning multiple teams, shaping strategy, roadmaps, and governance while partnering with Platforms, Trust & Safety, Growth, and Engineering to deliver... 

    Socket.dev

    San Francisco, CA
    2 days ago
  •  ...architecture connects every application, data source, and process to power real-time orchestration at scale. With enterprise-grade security and continuous innovation at its core, Workato provides the trusted foundation for organizations to automate with confidence and... 
    Remote work
    Flexible hours

    Workato

    San Francisco, CA
    6 days ago
  • $293k - $385k

     ...the TeamSecurity is foundational to OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.The Security organization protects OpenAI’s technology, people, and products by building and operating deeply technical systems that must work... 
    Work at office
    Local area
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    6 days ago
  • Fastly in San Francisco, CA is seeking a Staff Product Marketing Manager for its Security portfolio. You will own go-to-market strategy, messaging, and packaging for Next-Gen WAF, DDoS protection, Bot Management, and TLS/compliance adjacent security capabilities. You will... 

    Fastly

    San Francisco, CA
    4 days ago
  • Aurora is seeking a Staff Technical Product & Program Manager, Security to embed security across software, hardware and services. You will bridge Security and Product teams, driving strategy, roadmaps, governance, and risk management for complex, cross-functional programs... 

    Aurora

    San Francisco, CA
    4 days ago
  • Ripple in San Francisco, CA seeks a Senior Staff Technical Program Manager for Information Security to lead the Post-Quantum Cryptography (PQC) migration program. You will work with InfoSec, XRPL Core, Payments, Custody, Stablecoin, Platform, Compliance, and Legal to ensure... 

    Ripple

    San Francisco, CA
    5 days ago
  • Ripple is seeking a Senior Staff Technical Program Manager to lead its Post-Quantum Cryptography migration program, coordinating with InfoSec, XRPL Core, Payments, Custody, Stablecoin, Platform, Compliance and Legal to ensure a company-wide cryptographic upgrade by the... 

    Ripple

    San Francisco, CA
    14 hours ago
  •  ...Identify and report preventative or other maintenance issues in public areas or guest rooms. Follow all company and safety and security policies and procedures; report any maintenance problems, safety hazards, accidents, or injuries; complete safety training and certifications... 
    Work experience placement
    Local area
    Shift work

    Marriott International Inc

    San Francisco, CA
    5 days ago
  •  ...procedures. Monitor dining rooms for seating availability, service, safety, and well being of guests. Follow all company and safety and security policies and procedures; report accidents, injuries, and unsafe work conditions to manager; and complete safety training and... 
    Work experience placement
    Local area

    Marriott International

    San Francisco, CA
    1 day ago
  •  ...include, but are not limited to: drug procurement, storage, and security; safe, accurate and timely preparation and distribution of...  ...Program may be part of pharmacist responsibilities as applicable. Staff are expected to participate in department initiatives to improve... 
    Work experience placement
    Shift work

    University of California - San Francisco

    San Francisco, CA
    2 days ago
  • A nonprofit advocacy organization in San Francisco is seeking a Staff Attorney to oversee disability rights issues, represent clients in federal court, and produce advocacy reports. Candidates must be licensed California attorneys with a minimum of 1-2 years of relevant... 
    Full time
    Part time

    People With Disabilities Foundation

    San Francisco, CA
    3 days ago
  • $215k - $250k

     ...back into the product so it compounds across customers.As an AI Strategist on our Applied AI team focused on the legal vertical, you are...  ..., including outside-counsel guidelines, privilege, and security reviewFounder or early-startup operating experienceStrong network... 
    Contract work
    Local area

    Perplexity AI

    San Francisco, CA
    3 days ago
  • $98k - $110k

    Who You’ll Work WithSlalom is seeking a Corporate Strategist to join our Strategy team. Our Strategy team helps organizations of all kinds redefine what’s possible, give shape to the future—and get there. We focus on high-impact projects, meeting our clients where they... 
    Temporary work
    Local area

    Slalom

    San Francisco, CA
    5 days ago
  •  ...accelerate transformation outcomes.We are seeking a Migration Strategist to serve as one of our foremost migration experts—helping clients...  ...architects, data engineering teams, application teams, security, and integration specialists to deliver best-fit migration solutions... 
    Temporary work
    Local area

    Slalom

    San Francisco, CA
    2 days ago
  • $88k - $125k

     ...and is responsible for a substantial portion of Google’s advertising business growth across the globe.As a New Business Account Strategist, you will be a critical member of our Onboarding team, managing the onboarding of new advertising customers for Google throughout... 

    Google

    San Francisco, CA
    6 days ago
  • $144k - $216k

    Who we areAbout StripeStripe, LLC. is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities...
    Remote work

    Stripe

    San Francisco, CA
    4 days ago
  •  ...have raised $60M in Series C funding from Wellington Management, CRV, Next47 and Y Combinator.The roleWe're hiring a Deployment Strategist to own the successful deployment and adoption of Encord across a portfolio of customers. This is a high-impact, post-sales role that... 

    Encord

    San Francisco, CA
    6 days ago
  • $88k - $124k

    Build and manage relationships with clients virtually or face to face by meeting with multiple clients on a daily basis and develop an understanding of their business issues, marketing objectives, and success metrics.Work proactively and cooperatively with internal and ...

    Google

    San Francisco, CA
    2 days ago
  • $88k - $124k

    Build trusted relationships with key client decision-makers to understand their business objectives and marketing needs.Analyze customer objectives, financials, and the landscape to develop high-quality agreements and align on ambitious growth goals.Develop Google Ads knowledge...

    Google

    San Francisco, CA
    3 days ago
  • $102k - $147k

    Who You’ll Work WithWe are growing our global supply chain strategy team who is delivering transformational solutions for our clients focused on: planning, logistics and fulfillment, and procurement. What You’ll Do· This role will play a critical part in growing and supporting...
    Contract work
    Temporary work
    Local area

    Slalom

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Strategist GRC. Be the first to apply!