Sr Security Technologist - Incident Commander

Sway

Northern (KY)

Hybrid

USD 180,000 - 200,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Uber is seeking a Senior Security Technologist, Incident Command, to lead its most critical security incidents end-to-end from detection through containment and remediation. You will command high-stakes incidents, drive post-incident analyses, and shape tooling, workflows, and cross-team coordination at scale.

You will mentor other responders, participate in simulations, and influence security practices across engineering, privacy, legal and operations to raise the organization’s incident

Qualifications

  • 5+ years in security operations, detection, or incident response at scale.
  • Deep familiarity with modern attacker TTPs across logs, systems, networks, endpoints, and applications.
  • Strong investigation skills with logs, telemetry, and raw system data.
  • Experience briefing executives during active incidents with clear risk explanations.
  • Experience designing or running technical incident simulations (tabletops, purple team).
  • Experience building or leveraging AI-driven tooling to improve response.

Responsibilities

  • Command the highest severity and most complex incidents as the single accountable leader.
  • Participate in on-call rotations making real-time decisions with incomplete information.
  • Act as incident authority, form hypotheses, set strategy, and direct investigations.
  • Transition between executive leadership and hands-on analysis including log review and root cause validation.
  • Interface with senior leadership to translate technical risks into clear decisions.
  • Build strong relationships with global teams to enable fast, coordinated response.
  • Conduct post-incident analyses focusing on systemic causes and prevention.
  • Mentor and develop other responders and incident leaders for future incidents.
  • Lead initiatives maturing Uber’s IR program, including simulations, threat modeling, and automation.
  • Adopt new investigative tooling and AI-assisted workflows to improve response posture.

Skills

Security operations
Incident response
Log analysis
Executive briefing
Tabletop exercises
AI tooling
Leadership
Scripting (Python/Go)

Job description

About the Role

As a Senior Security Technologist, Incident Command, you are accountable for leading Uber’s most critical, complex, and high-impact security incidents end-to-end - from escalation to containment, recovery, and systemic remediation. This role will sit in either our Seattle, San Fransisco, or Sunnyvale office.

You operate at the intersection of Fire Captain, NTSB Investigator, and hands‑on technical practitioner. In the moment, you take command - setting strategy, assigning resources, and making high‑consequence decisions under pressure. After the smoke clears, you drive deep technical investigation and post‑incident analysis to ensure we understand not just what happened, but why it happened, and that meaningful, durable fixes are made.

This is not a passive coordination role. You are expected to be technically credible, decisive in ambiguity, and comfortable owning outcomes when there is no playbook. You will shape how Uber responds to security incidents at scale - raising the technical bar, building and modernizing tooling and workflows, and influencing teams beyond Engineering Security.

What the Candidate Will Need / Bonus Points
What the Candidate Will Do
  1. Command the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.
  2. Participate in an on‑call rotation where you are expected to make real‑time decisions with incomplete information, balancing speed, risk, and impact.
  3. Act as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus.
  4. Transition seamlessly between executive‑level incident leadership and hands‑on technical investigation, including log analysis, system interrogation, and root cause validation.
  5. Serve as the primary interface to senior leadership during critical incidents, translating evolving technical realities into clear risk, impact, and decision frameworks.
  6. Build and maintain strong working relationships with global engineering, infrastructure, legal, privacy, and operations teams to enable fast, coordinated response.
  7. Conduct rigorous post‑incident analysis in the spirit of an NTSB investigation - focused on systemic causes, contributing factors, and concrete prevention.
  8. Mentor and develop other responders and incident leaders, raising the organization’s ability to handle complex, time‑critical security events.
  9. Lead and materially contribute to initiatives that mature Uber’s incident response program, including:
  10. High‑fidelity incident simulations and technical tabletop exercises
  11. Threat‑informed response planning and scenario development
  12. ‘Left of boom’ threat modeling to prevent incidents before they occur
  13. Improvements to detection, containment, and response automation
  14. Adoption of new investigative techniques and tooling, including AI‑assisted workflows
Basic Qualifications
  1. 5+ years in security operations, detection, or incident response roles at scale, with demonstrated ownership of ambiguous, large, complex, high‑impact incidents.
  2. Deep familiarity with modern attacker TTPs and how they manifest across logs, systems, networks, endpoints, and applications.
  3. Strong technical investigation skills - comfortable working directly with logs, telemetry, and raw system data to validate hypotheses and determine root cause.
  4. Experience briefing executives during active incidents, with the ability to clearly explain tradeoffs, risks, and recommended actions.
  5. Experience designing or running technical incident simulations (tabletops, purple team exercises, or similar) that stress real‑world response capabilities.
  6. Experience building or leveraging AI‑driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support.
Preferred Qualifications
  1. Demonstrated experience leading other responders through direct command during incidents and longer‑term technical mentorship.
  2. Strong bias for action and continuous improvement - uncomfortable with leaving with a shrug if things aren’t right.
  3. Experience responding to incidents in highly distributed, cloud‑scale environments where blast radius and coordination complexity are significant.
  4. Broad security domain knowledge (infrastructure, endpoint, product, identity, data) and the ability to reason across them during incidents.
  5. Ability to script or code (Python, Go, or similar) to automate response tasks, prototype tooling, or close operational gaps.

You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits.

Offices remain key to collaboration and Uber’s culture. Unless approved for full remote work, employees must spend at least 50% of their time in office. Some roles, like those at greenlight hubs, require full‑time in‑office presence.

Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

For San Francisco, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For Seattle, WA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For Sunnyvale, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Technologist II - Technical Security
Security Technologist II - Technical Security

Uber • United States

On-site
USD 153,000 - 170,000
Bonuses
Equity
Benefits
+1
Security Technologist II - Technical Security
Security Technologist II - Technical Security

Uber • San Francisco (CA)

On-site
USD 153,000 - 170,000
Bonus program
Equity award
401(k) plan
+1
Staff Security Engineer - Detection & Response (AI-Driven Threat Hunting & Incident Response)
Staff Security Engineer - Detection & Response (AI-Driven Threat Hunting & Incident Response)

Uber • United States

On-site
USD 232,000 - 258,000
Bonuses
Equity
401(k) plan
+1
Senior Staff Security Engineer - (Agentic Systems)
Senior Staff Security Engineer - (Agentic Systems)

Uber • United States

Hybrid
USD 267,000 - 297,000
Bonus program
Equity awards
401(k) plan
+1
Staff Security Engineer – Detection & Response (AI-Driven Threat Hunting & Incident Response)
Staff Security Engineer – Detection & Response (AI-Driven Threat Hunting & Incident Response)

Uber • Seattle (WA)

On-site
USD 232,000 - 258,000
Bonus program
Equity grant
401(k) plan
+1
Senior Staff Security Engineer - (Agentic Systems)
Senior Staff Security Engineer - (Agentic Systems)

Uber • San Francisco (CA)

On-site
USD 267,000 - 297,000
Bonus program
Equity award
401(k) plan
+1
Senior Staff Security Engineer – (Agentic Systems)
Senior Staff Security Engineer – (Agentic Systems)

Uber • Seattle (WA)

On-site
USD 267,000 - 297,000
Bonus program
Equity award
401(k) plan
+1
Staff Security Strategist GRC
Staff Security Strategist GRC

Uber • United States

On-site
USD 211,000 - 234,000
401(k) plan
Bonus program
Equity eligibility
+1
Staff Security Engineer - Vulnerability Management
Staff Security Engineer - Vulnerability Management

Uber • New York (NY)

On-site
USD 232,000 - 258,000
Bonus program
Equity
401(k) plan
+1
Staff Security Engineer - Vulnerability Management
Staff Security Engineer - Vulnerability Management

Uber • United States

On-site
USD 232,000 - 258,000
Bonus program
Equity
401(k) plan
+1