Staff Security Engineer
$232kUber Technologies Inc
Job Description About the role and team: As a member of Uber's Offensive Security team, you will work across multiple security disciplines to proactively identify and reduce risk in Uber's most critical services and emerging technologies. You will perform security design reviews and threat modeling for critical services and AI agents, conduct hands-on penetration testing to validate real-world attack paths, and help build AI-powered automation that transforms how these security assessments are performed at scale. This role combines deep technical security expertise with an automation-first mindset, helping evolve traditional point-in-time assessments toward continuous, scalable security testing across Uber's technology ecosystem. This isn't a "set and forget" role. Our environment is fast-moving and the threats are constantly evolving. You will navigate the "messy" reality of hybrid cloud and distributed systems, conducting technical security design reviews as part of our secure software development lifecycle. We are looking for a technically curious engineer who thrives in ambiguity, takes extreme ownership of their work, and has the grit to stay ahead of sophisticated adversaries. If you are motivated by high-stakes challenges and want to build a more secure future for movement - this is where you'll grow. What you'll do
- Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths.
- Conduct security design reviews and threat modeling for AI agents and agentic systems, evaluating risks across models, tools, data, permissions, external integrations, and runtime behavior.
- Design and build AI-powered automation for security design reviews, threat modeling, penetration testing, and vulnerability validation, increasing the scale, frequency, and depth of Offensive Security assessments.
- Partner with engineering and security teams to translate offensive security findings into systemic improvements, helping eliminate vulnerability classes and strengthen security controls across Uber's technology ecosystem.
- Perform multi-disciplinary security design reviews of engineering proposals, analyzing cloud, infrastructure, application, and data-layer security.
- Navigate complex design trade-offs to provide corrective guidance that improves the overall security posture of Uber's products and services.
- Collaborate with engineering teams across the company to analyze design documents and identify potential flaws before they reach production.
- Translate technical security findings into actionable guidance for both engineering and non-technical stakeholders to ensure alignment and impact.
- Conduct comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.
- Champion engineering best practices and serve as a security ambassador, helping teams move fast while building with integrity and care.
- 7+ years of professional experience in security engineering, threat detection, or client platform engineering.
- Demonstrated ability to independently analyze complex, large-scale system designs, identify security risks and attack paths, and drive technical solutions across multiple services, systems, and dependencies.
- Deep knowledge of threat modeling, vulnerability discovery and classification, security risk assessment, and offensive security methodologies, with experience applying them to complex production environments.
- Extensive experience assessing the security of cloud-native services, microservices, distributed systems, APIs, or other large-scale production environments.
- Proven ability to lead complex security assessments and influence engineering teams to implement security improvements across organizational and technical boundaries.
- Experience applying AI/LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or other security engineering workflows.
- Hands-on experience conducting penetration testing of complex applications, services, APIs, and infrastructure, including identifying, validating, and demonstrating exploitable vulnerabilities and attack paths.
- Master's degree or PhD in a technical field and 10+ years of experience in a cybersecurity leadership or staff-level role.
- Deep knowledge of Cybersecurity, Compliance, and Privacy, with experience chaining vulnerabilities and quantifying risks.
- Experience collaborating with EMs, TPMs, and PMs on prioritization, headcount planning, and technical evaluation of team members.
- Advanced expertise in leveraging AI/ML for security use cases and building device attestation or trust tooling at a global scale.
- Strategic relationship builder: Proven ability to leverage collaborative relationships with legal, product, and engineering stakeholders to build trust and accomplish work.
Vacancy posted 6 hours ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer in San Francisco, CA vacancy
$232k - $290k
...impact and unlock incredible career growth opportunities, join us, and build real world value. THE WORK: As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security practitioners, operating at the intersection of application...SuggestedFull timeWork at officeLocal area$175k - $235k
Staff Security Engineer Primer exists to make the world a safer place. We do this by providing trusted decision-ready AI to the world's most critical organizations. Our software enables leaders, operators, and analysts to better understand the changing world around us in...SuggestedContract workRemote workFlexible hours- ...iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft. About the role: We're hiring a Senior/Staff Product Security Engineer to build the security-critical systems at the heart of Collective's member platform. This is a software engineering...SuggestedSelf employmentFreelanceWork at officeRemote workFlexible hours
$226k - $283k
...workflows inside some of the country's most security-sensitive health systems. Security can't be bolted on-it must be engineered into the product. This is a senior technical... ...and secure paved paths. Who You Are: Staff-level product security judgment. You have the...SuggestedWork at officeImmediate startRemote workFlexible hours3 days per week- Envoy is seeking a Staff Security Engineer to own and evolve our security operations and threat-detection capabilities from our San Francisco HQ. You will define detection strategies across cloud, applications, and endpoints, enhance our SIEM, and drive automated controls...Suggested
$220k - $330k
...future of professional services is being written today — and we're just getting started. Role Overview As a Staff Software Engineer on the Product Security team at Harvey, you'll play a critical role in shaping how security is built into our AI platform from the...Work experience placement- ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on... ...and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform...Full timeLocal areaRemote workWorldwideFlexible hours
$267k
...Description About the Role Our mission is to protect, defend, and secure Uber's products, infrastructure, and data by building... ...threats. We are seeking a talented and experienced Senior Staff Software Engineer - (Agentic Systems) to lead our Enterprise Security Team in...Full timeWork experience placementWork at officeRemote work$180k - $247k
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building... ...'re building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen...Local areaRemote workWorldwideFlexible hours$235k - $275k
Code Red is partnered with a unicorn FinTech in SF to bring on a Staff Product Security Engineer . This will be a foundational hire within a small, high‑impact security org that supports a global organization in hypergrowth mode. Base Pay Range $235,000.00/yr - $275,00...Full time- Parallel seeks a senior security engineer to build and operate the security systems enabling fast shipping with minimal risk. You will cover application security, secure defaults, and AI-assisted tooling, addressing the unique attack surface of agentic systems that consume...
$405k
...growing group of committed researchers, engineers, policy experts, and business leaders working... ...AI systems. About the role The Security Risk team is responsible for how... ...hybrid policy: Currently, we expect all staff to be in one of our offices at least 25%...Full timeWork at officeVisa sponsorshipFlexible hours$189k - $303k
...Staff Application Security Engineer Aurora's mission is to deliver the benefits of self-driving technology safely, quickly, and broadly. The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible...Work at officeLocal area3 days per week$251k - $325k
...00 people across hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come from OpenAI, Tesla, SpaceX... ...launches from our [Liftoff]( event. About the Team The Security team at Tools for Humanity operates at a level far beyond a...Casual workWorldwideFlexible hours- ...the AI transformation of this space is still largely uncharted. Engineers here are building agentic solutions to problems that haven't... ...company events._ Ironclad is seeking an experienced Application Security Engineer with a passion for securing modern software...Full timeContract workWork at office
$190k - $230k
Staff Security Engineer, Data Science Engineering Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables...Flexible hours- ...at record breaking speeds. About You and The Role Product security at Zipline protects systems that directly affect safety, regulatory... ..., autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a...Local area
$232k - $290k
...see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence and...Full timeWork at officeLocal area$204k - $240k
...to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a staff security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems...Full timeWork at officeLocal area$210k - $255k
...with us at Crusoe.About This RoleCrusoe is building the world’s favorite AI-first cloud infrastructure. We are seeking a Staff Corporate Security Engineer to act as the principal architect for our corporate security posture.In this role, you will move beyond tactical tool...Temporary work$175k - $270k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...how we operate, not treated as a blocker.Your roleAs a Staff Corporate Security Engineer, you will be a critical part...Temporary workLocal areaWorldwide- ...thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud... ...and firmware running on IoT hardware in the field. As a Staff Application Security Engineer, you’ll drive the overarching technical direction for...Full timeRemote work
- ...: 4+ years Key Responsibilities: - Own the end-to-end security posture across application, cloud, network, infrastructure, and... ...to communicate security risks and trade-offs clearly to both engineering teams and executive stakeholders - High level of autonomy and...Full timeH1bVisa sponsorshipMonday to Friday
- ...every step of the way. Join us to invest in yourself, your career, and the financial world.The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning-driven detection and anomaly detection program. You will own the detection...Remote work
$212k - $265k
...ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Staff Security Engineer within the Secure Digital Asset Operations (SDAO) function, you will collaborate with leadership and cross-functional...Full timeWork at officeLocal area$200k - $300k
...Job Description Job Description Senior/Staff Security Engineer Company: Init Intelligence Location: San Francisco, CA - in person, Monday to Friday Compensation: $200,000 - $300,000 base + 1-2% equity Employment Type: Full-time Visa Sponsorship: Available...Full timeH1bWork at officeVisa sponsorshipMonday to Friday$221k - $299k
...does happen. You'll join a team that includes an AppSec-focused engineer and an infrastructure-focused engineer, and you'll guide... ...broader process or control change. Partner with our Product Security Engineer on golden paths when a weakness points to a systemic gap...Full timeContract workWork at officeImmediate startRemote workFlexible hours3 days per week$250k - $285k
...high-performing team that believes in each other, come build with us at Crusoe. About This Role We’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications, infrastructure, and...Temporary work$200k - $280k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...operate, not treated as a blocker.What you'll doAs a Staff Product Security Engineer at Airwallex, you will be a...Temporary workLocal areaWorldwide- ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security...Work at officeRelocation3 days per week1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer. Be the first to apply!
Related searches
- staff data engineer San Francisco, CA
- project engineer assistant project manager San Francisco, CA
- senior staff engineer San Francisco, CA
- senior staff systems engineer San Francisco, CA
- assistant chief engineer San Francisco, CA
- engineering aide San Francisco, CA
- software engineer staff San Francisco, CA
- staff design engineer San Francisco, CA
- assistant engineering manager San Francisco, CA
- assistant engineer San Francisco, CA

