Staff Security Engineer - Vulnerability Management

Uber

United States

On-site

USD 232,000 - 258,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus program
Equity
401(k) plan
Benefits

Job summary

Uber is seeking a Staff Security Engineer, Vulnerability Management to architect and scale our Risk-Based Vulnerability Management (RBVM) systems across on-prem, cloud, containers, VMs, and endpoints. You will lead the transition toward Continuous Threat Exposure Management and AI-driven remediation workflows at enterprise scale.

You will mentor engineers, drive security posture improvements, and collaborate across IT, security, product, and operations to mature governance, standards, and

Qualifications

  • 7+ years of industry experience in software development with a focus on large-scale security or infrastructure engineering.
  • Expertise in building distributed systems and high-availability security platforms.
  • Proven track record of designing and operating vulnerability management tools at scale.
  • Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines.
  • Experience leading cross-functional security initiatives and mentoring senior engineering staff.

Responsibilities

  • RBVM Platform Architecture: Design and scale Security Posture Management tools and platforms to provide a unified, risk-scored view of vulnerabilities across on-prem, cloud, containers, VMs, and endpoints.
  • Automation & Orchestration: Build automated remediation workflows and systems that will reduce median response times for emerging threats and scale across decentralized teams.
  • Technical Strategy: Lead Shift-Left initiatives by integrating vulnerability scanning into development workflows, CI/CD pipelines, and infrastructure provisioning to enforce security policies.
  • AI/ML Innovation: Leverage LLMs and AI agents for automated triage, impact analysis, and remediation instructions for service owners.
  • Vulnerability Governance: Partner with Compliance and IT to mature vulnerability standards, SLAs, and risk exception processes across the global estate.
  • Vulnerability Analysis: Provide deep security SME to analyze complex vulnerabilities and drive remediation decisions.

Skills

Golang
Java
Python
Security design
Vulnerability management
CI/CD pipelines

Job description

About the Role

Our mission is to protect, defend, and secure the company's products, infrastructure, and data by building highly available, scalable, and extensible security solutions and services. We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk-Based Vulnerability Management (RBVM) systems, transforming how we identify, prioritize, and remediate exposure across a massive digital footprint.

You will drive technical excellence across our vulnerability management landscape, from on-prem, cloud, container security to corporate endpoint hygiene. As a Staff Engineer, you will be a technical visionary and mentor, leading the transition toward Continuous Threat Exposure Management and AI-driven remediation workflows that operate at enterprise scale.

What You Will Do
  • RBVM Platform Architecture: Design and scale Security Posture Management tools and platforms to provide a unified, risk-scored view of vulnerabilities across on-prem, cloud, containers, VMs, and endpoints.
  • Automation & Orchestration: Build automated remediation workflows and systems that will reduce median response times for emerging threats and scale across decentralized teams.
  • Technical Strategy: Lead \"Shift-Left\" initiatives by integrating vulnerability scanning into development workflows, CI/CD pipelines, and infrastructure provisioning to enforce security policies consistently across all asset types, including cloud resources, endpoints, and applications.
  • AI/ML Innovation: Leverage LLMs and AI agents for automated triage, impact analysis, and generating context-aware remediation instructions for service owners across the infrastructure.
  • Vulnerability Governance: Partner with Compliance and IT to mature vulnerability standards, SLAs, and risk exception processes across the global digital estate.
  • Vulnerability Analysis: Provide deep security subject matter expertise to analyze complex vulnerabilities, assess true risk, and drive informed decisions on remediation verdicts, false positives, and risk acceptance.
  • Cross-Functional Collaboration: Partner with IT, product, and operations teams to integrate security posture improvements across the entire environment.
Basic Qualifications
  • 7+ years of industry experience in software development, with a focus on large-scale security or infrastructure engineering.
  • Expertise in building distributed systems and high-availability security platforms using Golang, Java, or Python.
  • Proven track record of designing and operating vulnerability management tools at scale.
  • Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines.
  • Experience leading cross-functional security initiatives and mentoring senior engineering staff.
Preferred Qualifications
  • Hands-on experience developing Risk-Based Vulnerability Management (RBVM) frameworks and automated prioritization logic.
  • Knowledge of AI/ML applications in security, specifically for vulnerability triage or large-scale data analysis.
  • Experience with External Attack Surface Management (EASM) and tracking internet-facing asset exposure.
  • Familiarity with Software Supply Chain Security (SSCS), including SBOM and internal package registries.
Ready to Ride?

This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.

You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.

Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.

Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.

For New York City, NY-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For Seattle, WA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For Sunnyvale, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.

For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer – Vulnerability Management
Staff Security Engineer – Vulnerability Management

Uber • San Francisco (CA)

On-site
USD 232,000 - 258,000
Bonus program
Equity award
401(k) plan
+1
Staff Security Engineer - Vulnerability Management
Staff Security Engineer - Vulnerability Management

Uber • New York (NY)

On-site
USD 232,000 - 258,000
Bonus program
Equity
401(k) plan
+1
Senior Staff Security Engineer - (Agentic Systems)
Senior Staff Security Engineer - (Agentic Systems)

Uber • United States

Hybrid
USD 267,000 - 297,000
Bonus program
Equity awards
401(k) plan
+1
Senior Staff Security Engineer - (Agentic Systems)
Senior Staff Security Engineer - (Agentic Systems)

Uber • Seattle (WA)

On-site
USD 267,000 - 297,000
401(k) plan
Bonus program
Equity awards
+1
Staff Security Engineer - Detection & Response (AI-Driven Threat Hunting & Incident Response)
Staff Security Engineer - Detection & Response (AI-Driven Threat Hunting & Incident Response)

Uber • United States

On-site
USD 232,000 - 258,000
Bonuses
Equity
401(k) plan
+1
Sr Staff Engineer - Core Infrastructure
Sr Staff Engineer - Core Infrastructure

Uber • United States

On-site
USD 267,000 - 297,000
Bonuses
Equity
401(k) plan
Senior Staff Security Engineer – (Agentic Systems)
Senior Staff Security Engineer – (Agentic Systems)

Uber • Seattle (WA)

On-site
USD 267,000 - 297,000
Bonus program
Equity award
401(k) plan
+1
Staff Technical Program Manager
Staff Technical Program Manager

Uber • United States

Hybrid
USD 241,000 - 257,000
Bonus program
Benefits
Senior Security Incident Commander
Senior Security Incident Commander

Uber • United States

Hybrid
USD 180,000 - 200,000
Staff Security Strategist GRC
Staff Security Strategist GRC

Uber • United States

On-site
USD 211,000 - 234,000
401(k) plan
Bonus program
Equity eligibility
+1