Security Engineer II - Design Review / Threat Modelling
Job Description
Work on security at scale from Uber’s Security Review Team. This onsite role in Sunnyvale, CA combines hands-on security testing with threat modeling and AI-powered automation to increase the scale, frequency, and depth of Offensive Security assessments across critical services and AI agents. You will partner closely with engineering and security teams to turn findings into systemic improvements.
Compensation and benefits include eligibility for Uber’s bonus program, possible equity awards and other types of compensation, and access to a 401(k) plan for full-time employees, along with various benefits.
Salary range: USD 171,000 - 190,000 per year.
Responsibilities
- Conduct security design reviews and threat modeling across Uber’s diverse codebase, evaluating security risks in services, applications, APIs, infrastructure, mobile platforms, AI systems, and other production software.
- Assess third-party AI agents (coding and work-focused agents) using adversarial testing to identify security risks in agent behavior, tool use, data access, permissions, prompt injection, and external integrations.
- Perform hands-on penetration testing of critical Uber services, applications, APIs, infrastructure, and AI agents to identify exploitable vulnerabilities and complex attack paths.
- Design and build AI-powered automation for security design reviews, threat modeling, and penetration testing, expanding the reach of Offensive Security assessments.
- Partner with engineering and security teams to translate offensive security findings into systemic improvements, helping eliminate vulnerability classes and strengthen security controls.
- Lead multi-disciplinary security design reviews of engineering proposals across cloud, infrastructure, application, and data-layer security.
- Provide corrective guidance based on complex design trade-offs to improve the overall security posture of Uber products and services.
- Collaborate with engineering teams to analyze design documents and surface potential flaws before they reach production.
- Translate technical security findings into actionable guidance for engineering and non-technical stakeholders to ensure alignment and impact.
- Conduct comprehensive security assessments, including threat modeling for web and mobile applications, to identify and mitigate risks at scale.
- Champion engineering best practices and act as a security ambassador, supporting teams as they move fast with security, integrity, and care.
Requirements
- 3+ years of professional experience in security engineering, systems architecture, or a related software engineering field.
- Proven ability to analyze complex system designs and provide technical input to solve security challenges with multiple dependencies.
- Broad knowledge of threat modeling, vulnerability classification, and risk modeling frameworks.
- Experience with security designs related to cloud-native services, microservices, or distributed systems.
- Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
Technologies
Go, Java, Python, AWS, GCP, SQL, NoSQL, AI/LLMs, CI/CD, microservices, cloud-native services, distributed systems, multi-cloud environments
Preferred Qualifications
- Hands-on experience performing security design reviews and threat modeling across complex applications, services, APIs, distributed systems, cloud infrastructure, and mobile platforms.
- Demonstrated ability to identify complex attack paths and systemic security weaknesses across application, infrastructure, identity, data, and trust boundaries.
- Experience conducting code-assisted security reviews using source code to validate architectural assumptions, security controls, data flows, authorization boundaries, and potential vulnerabilities.
- Experience reviewing large-scale distributed and cloud-native architectures, including microservices, service-to-service authentication, APIs, messaging systems, data stores, and multi-cloud environments.
- Advanced proficiency in at least one backend language such as Go, Java, or Python to evaluate code-level security.
- Hands-on experience with multi-cloud environments (e.g., AWS, GCP) and data store technologies (SQL or NoSQL).
- Experience applying AI/LLMs, agents, or automation frameworks to security testing, vulnerability discovery, threat modeling, or other security engineering workflows.
- Strong systems thinking with the ability to simplify complex technical concepts and influence without authority.
- Experience working within an automated CI/CD environment or a mature Secure Software Development Lifecycle (S-SDLC).
Office Location / Remote Work Requirements
- Unless approved for full remote work, employees must spend at least 50% of their time in-office.
- Some roles, like those at greenlight hubs, require full-time in-office presence.