Security Technologist I - Technical Security
About the role and team
Engineering at Uber means building for real-world impact under real-world constraints. The problems are complex, the systems are massive, and the pace is fast. You’ll need to make smart decisions with imperfect information — and own them. If you think in systems, stay calm under pressure, and care about building things that actually work — this is where you’ll grow.
As a Security Analyst within Incident Response, you are at the front lines of protecting Uber, our customers, and our partners. This is a technical, investigative role that requires you to stay steady during high-stakes security incidents and move with urgency to mitigate threats. You won’t just be monitoring dashboards; you’ll be solving complex security puzzles, conducting digital forensics, and building automated solutions to scale our global defenses in a high-pressure environment that demands both grit and adaptability.
What you’ll do
- Act as a first responder to security alerts, triaging and containing cyber threats across Uber’s global platform in a high-velocity, high-stakes environment.
- Conduct in-depth forensic investigations by analyzing logs, network traffic, and host telemetry to determine the root cause, scope, and impact of sophisticated attacks.
- Develop and deploy automated scripts and SOAR playbooks to streamline incident response workflows and increase team efficiency.
- Proactively hunt for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
- Collaborate across engineering and product teams to share threat intelligence, resolve blockers, and lead incident investigations through to remediation.
- Communicate investigative findings and technical root cause analysis clearly to help shape long-term security strategy and influence senior leadership.
Basic Qualifications
- Bachelor's degree in Computer Engineering, Information Security, or a related technical field (or equivalent professional experience).
- Minimum 2 years of professional experience in a security-focused role such as Incident Response, Security Operations (SOC), or Digital Forensics.
- Experience with technical security solutions including SIEM, EDR, and network monitoring tools.
- Proven track record of managing incident response and handling in a professional, enterprise environment.
- Exceptional communication skills with the ability to independently communicate technical topics concisely and contribute to technical documentation like runbooks or wikis.
Preferred Qualifications
- 2 + years of professional experience in Incident Response or Digital Forensics within a large-scale technology platform.
- Proficiency in a programming language such as Python or Go for incident response automation and data analysis.
- Hands-on experience with SOAR platforms (e.g., Splunk Phantom, Cortex XSOAR) and developing automated response playbooks.
- Experience with using GenAI or vision-language models to assist in investigations and incident response.
- Strong understanding of network protocols, system security, and common threat vectors/TTPs.
For San Francisco, CA-based roles: The base salary range for this role is USD $133,000 per year - USD $140,000 per year.
For Seattle, WA-based roles: The base salary range for this role is USD $133,000 per year - USD $140,000 per year.
For Sunnyvale, CA-based roles: The base salary range for this role is USD $133,000 per year - USD $140,000 per year.
For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.