Security Engineer II - Design Review/Threat Modeling
Job Description
Uber’s Security Review Team is looking for a Security Engineer II to help strengthen the security of production systems across services, platforms, and AI agents. In this role, you will run security design reviews and threat modeling, then apply hands-on offensive testing and AI-powered automation to scale those assessments.
Based in Seattle, the position is onsite, with at least 50% time in-office unless full remote work is approved.
What you’ll do
- Lead security design reviews and threat modeling across Uber’s codebase, evaluating security risks across services, applications, APIs, infrastructure, mobile platforms, AI systems, and other production software.
- Adversarially test third-party AI agents, including coding and work-focused agents, to uncover risks related to agent behavior, tool use, data access, permissions, prompt injection, and external integrations.
- Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths.
- Design and build AI-powered automation for offensive security workflows, expanding the scale, frequency, and depth of security design reviews, threat modeling, and penetration testing.
- Partner with engineering and security teams to turn offensive findings into systemic improvements, helping reduce vulnerability classes and strengthen security controls across Uber’s ecosystem.
- Conduct multidisciplinary security design reviews of engineering proposals, analyzing cloud, infrastructure, application, and data-layer security.
- Navigate security design trade-offs and provide corrective guidance that improves the security posture of Uber products and services.
- Collaborate with engineering teams to analyze design documents and identify potential flaws before they reach production.
- Translate technical findings into actionable guidance for engineering and non-technical stakeholders to drive alignment and impact.
- Run comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.
- Serve as a security ambassador by championing engineering best practices and supporting teams as they move quickly with integrity and care.
Requirements
- 3+ years of professional experience in security engineering, systems architecture, or a related software engineering field.
- Proven ability to analyze complex system designs and provide technical input to solve security challenges with multiple dependencies.
- Broad knowledge of threat modeling, vulnerability classification, and risk modeling frameworks.
- Experience with security designs for cloud-native services, microservices, or distributed systems.
- Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
Technologies you may work with
- Go, Java, Python
- AWS, GCP
- SQL, NoSQL
- AI/LLMs, CI/CD
- Mobile platforms, microservices, distributed systems
- Cloud-native services, multi-cloud environments
Benefits
- Eligibility to participate in Uber’s bonus program
- May be offered an equity award and other forms of compensation
- All full-time employees are eligible to participate in a 401(k) plan
- Various benefits
- You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits
Preferred qualifications
- Hands-on experience performing security design reviews and threat modeling across complex applications, services, APIs, distributed systems, cloud infrastructure, and mobile platforms.
- Demonstrated ability to identify complex attack paths and systemic security weaknesses across application, infrastructure, identity, data, and trust boundaries.
- Experience conducting code-assisted security reviews using source code to validate architectural assumptions, security controls, data flows, authorization boundaries, and potential vulnerabilities.
- Experience reviewing large-scale distributed and cloud-native architectures, including microservices, service-to-service authentication, APIs, messaging systems, data stores, and multi-cloud environments.
- Advanced proficiency in at least one backend language such as Go, Java, or Python to evaluate code-level security.
- Hands-on experience with multi-cloud environments (e.g., AWS, GCP) and data store technologies (SQL or NoSQL).
- Experience applying AI/LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or other security engineering workflows.
- Strong systems thinking with the ability to simplify complex technical concepts and influence without authority.
- Experience working within an automated CI/CD environment or a mature Secure Software Development Lifecycle (S-SDLC).
Location and compensation
- Location: Seattle, WA (onsite)
- Salary range: USD 171,000 - 190,000 per year
Work model
- Unless approved for full remote work, employees must spend at least 50% of their time in-office.
- Some roles (including those at greenlight hubs) require full-time in-office presence.