Uber Logo

Uber

Sr Security Technologist - Incident Commander

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
180K-200K Annually
Senior level
Remote
Hiring Remotely in United States
180K-200K Annually
Senior level
Lead Uber’s highest-severity security incidents from escalation through containment, recovery, and remediation. Command response teams, make high-consequence decisions, investigate logs and system data, brief executives, conduct post-incident analysis, mentor responders, and improve incident response through simulations, threat modeling, automation, and AI-assisted tooling.
The summary above was generated by AI

About the Role

 

 

As a Senior Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation. This role will sit in either our Seattle, San Fransisco, or Sunnyvale office.
 

You operate at the intersection of Fire Captain, NTSB Investigator, and hands-on technical practitioner. In the moment, you take command - setting strategy, assigning resources, and making high-consequence decisions under pressure. After the smoke clears, you drive deep technical investigation and post-incident analysis to ensure we understand not just what happened, but why it happened, and that meaningful, durable fixes are made.

This is not a passive coordination role. You are expected to be technically credible, decisive in ambiguity, and comfortable owning outcomes when there is no playbook. You will shape how Uber responds to security incidents at scale - raising the technical bar, building and modernizing tooling and workflows, and influencing teams beyond Engineering Security.
 


What the Candidate Will Need / Bonus Points

 

---- What the Candidate Will Do ----
 

  1. Command the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.
  2. Participate in an on-call rotation where you are expected to make real-time decisions with incomplete information, balancing speed, risk, and impact.
  3. Act as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus.
  4. Transition seamlessly between executive-level incident leadership and hands-on technical investigation, including log analysis, system interrogation, and root cause validation.
  5. Serve as the primary interface to senior leadership during critical incidents, translating evolving technical realities into clear risk, impact, and decision frameworks.
  6. Build and maintain strong working relationships with global engineering, infrastructure, legal, privacy, and operations teams to enable fast, coordinated response.
  7. Conduct rigorous post-incident analysis in the spirit of an NTSB investigation - focused on systemic causes, contributing factors, and concrete prevention.
  8. Mentor and develop other responders and incident leaders, raising the organization’s ability to handle complex, time-critical security events.
  9. Lead and materially contribute to initiatives that mature Uber’s incident response program, including:
  10. High-fidelity incident simulations and technical tabletop exercises
  11. Threat-informed response planning and scenario development
  12. ‘Left of boom’ threat modeling to prevent incidents before they occur
  13. Improvements to detection, containment, and response automation
  14. Adoption of new investigative techniques and tooling, including AI-assisted workflows

 

 

---- Basic Qualifications ----
 

  1. 5+ years in security operations, detection, or incident response roles at scale, with demonstrated ownership of ambiguous, large, complex, high-impact incidents. 
  2. Deep familiarity with modern attacker TTPs and how they manifest across logs, systems, networks, endpoints, and applications.
  3. Strong technical investigation skills - comfortable working directly with logs, telemetry, and raw system data to validate hypotheses and determine root cause.
  4. Experience briefing executives during active incidents, with the ability to clearly explain tradeoffs, risks, and recommended actions.
  5. Experience designing or running technical incident simulations (tabletops, purple team exercises, or similar) that stress real-world response capabilities.
  6. Experience building or leveraging AI-driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support.


---- Preferred Qualifications ----
 

  1. Demonstrated experience leading other responders through direct command during incidents and longer-term technical mentorship.
  2. Strong bias for action and continuous improvement - uncomfortable with leaving with a shrug if things aren’t right.
  3. Experience responding to incidents in highly distributed, cloud-scale environments where blast radius and coordination complexity are significant.
  4. Broad security domain knowledge (infrastructure, endpoint, product, identity, data) and the ability to reason across them during incidents.
  5. Ability to script or code (Python, Go, or similar) to automate response tasks, prototype tooling, or close operational gaps.

 

Responsibilities

For San Francisco, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.


For Seattle, WA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.


For Sunnyvale, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year

About Us

Ready to Ride?

This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.

You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.

Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.

Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

Uber Seattle, Washington, USA Office

Uber's a hybrid work environment and employees target spending 50% of their time in the office.

Similar Jobs

55 Seconds Ago
In-Office or Remote
172K-270K Annually
Senior level
172K-270K Annually
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead post-sales technical implementations for enterprise customers, including onboarding, integrations, system architecture, workflow configuration, and deployment strategy. Design custom solutions using APIs and complex client environments, advise customers on developer experience analytics and engineering practices, lead technical workshops, and translate architecture into business value. Partner with Customer Success, Product, and Engineering teams while synthesizing customer feedback to influence the product roadmap.
Top Skills: APIsCi/Cd PipelinesGitGithub CliPostgresPythonRestful ServicesRuby/RailsSQL
55 Seconds Ago
In-Office or Remote
196K-309K Annually
Expert/Leader
196K-309K Annually
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Principal Machine Learning Engineer responsible for setting technical direction and building production-grade AI systems for Confluence. The role spans model evaluation, retrieval, ranking, prompt and workflow design, experimentation, reliability, and customer-facing AI product development. Responsibilities include making architectural decisions, partnering across engineering and product teams, mentoring engineers, identifying model and product failure modes, and delivering scalable AI experiences across content creation, editing, discovery, recommendations, and multimodal interaction.
Top Skills: Ai Systems InfrastructureArtificial IntelligenceAutomated EvaluationExperimentationMachine LearningMultimodal AiPrompt EngineeringRankingRetrieval
55 Seconds Ago
In-Office or Remote
158K-248K Annually
Senior level
158K-248K Annually
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Prospect, qualify, and close net-new enterprise SaaS opportunities across defined U.S. territories. Own the full sales cycle, conduct demos and proof-of-concept engagements, develop business cases, forecast accurately, and guide buyers through complex evaluations. Build trusted relationships with technical and executive stakeholders, provide customer and market feedback, and help establish strategic sales processes for the U.S. region.
Top Skills: SaaS

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account