Security Technologist I - Technical Security
About the role and team
Engineering at Uber means building for real-world impact under real-world constraints. The problems are complex, the systems are massive, and the pace is fast. You’ll need to make smart decisions with imperfect information — and own them. If you think in systems, stay calm under pressure, and care about building things that actually work — this is where you’ll grow.
As a Security Analyst within our vSOC (Virtual Security Operations Center) and CIRT (CyberSecurity Incident Response Team), you are at the front lines of protecting Uber, our customers, and our partners. This is a technical, investigative role that requires you to stay steady during high-stakes security incidents and move with urgency to mitigate threats. You won’t just be monitoring dashboards; you’ll be solving complex security puzzles, conducting digital forensics, and building automated solutions to scale our global defenses.
What you’ll do
- Act as a first responder to security alerts, triaging and containing cyber threats across Uber’s global platform in a high-velocity environment.
- Conduct in-depth forensic investigations by analyzing logs, network traffic, and host telemetry to determine the root cause, scope, and impact of sophisticated attacks.
- Develop and deploy automated scripts and SOAR playbooks to streamline incident response workflows and increase team efficiency.
- Proactively hunt for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
- Coordinate end-to-end incident handling and bug bounty cases, partnering closely with engineering leads and stakeholders to strengthen our security posture.
- Communicate investigative findings clearly and concisely to help shape long-term security strategy and influence senior leadership.
Basic Qualifications
- Minimum 3 years of professional experience in a security-focused role, such as Incident Response or Security Operations (SOC).
- Proven track record of ownership within a service scope, prioritizing key areas of improvement and delivering on tasks that support standards of excellence.
- Basic working knowledge of security design, architecture, and platforms, with the ability to troubleshoot issues and analyze technical details within a specific domain.
- Demonstrated bias for action as a self-starter who simplifies decision-making processes and uses data to inform deadlines and action-oriented results.
- Exceptional communication skills with the ability to independently communicate low-complexity topics concisely and contribute to technical documentation (runbooks, wikis, ERDs).
- Proficiency in delivering results by effectively managing time, breaking large tasks into smaller components, and proactively communicating progress to stakeholders.
- Experience with technical security solutions including SIEM, EDR, and network monitoring tools.
- Bachelor's degree in Computer Science, Information Security, or a related technical field (or equivalent professional experience).
Preferred Qualifications
- Experience working in a 24/7 global operations model and handling crisis events for large-scale technology platforms.
- Proficiency in a programming language (e.g., Python, Go) for incident response automation and data analysis.
- Hands-on experience across multiple domains such as cloud security, host forensics, and vision-language or GenAI-assisted investigations.
- Strong understanding of network protocols (TCP/IP stack), system security, and common threat vectors/TTPs.
- Professional security certifications (e.g., GIAC, OSCP) are a plus.