Staff Security Engineer - Vulnerability Management
USD 232k-258k / year + Equity
About the Role
Our mission is to protect, defend, and secure the company's products, infrastructure, and data by building highly available, scalable, and extensible security solutions and services. We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk-Based Vulnerability Management (RBVM) systems, transforming how we identify, prioritize, and remediate exposure across a massive digital footprint.
You will drive technical excellence across our vulnerability management landscape, from on-prem, cloud, container security to corporate endpoint hygiene. As a Staff Engineer, you will be a technical visionary and mentor, leading the transition toward Continuous Threat Exposure Management and AI-driven remediation workflows that operate at enterprise scale.
What You Will Do
- RBVM Platform Architecture: Design and scale Security Posture Management tools and platforms to provide a unified, risk-scored view of vulnerabilities across on-prem, cloud, containers, VMs, and endpoints.
- Automation & Orchestration: Build automated remediation workflows and systems that will reduce median response times for emerging threats and scale across decentralized teams.
- Technical Strategy: Lead "Shift-Left" initiatives by integrating vulnerability scanning into development workflows, CI/CD pipelines, and infrastructure provisioning to enforce security policies consistently across all asset types, including cloud resources, endpoints, and applications.
- AI/ML Innovation: Leverage LLMs and AI agents for automated triage, impact analysis, and generating context-aware remediation instructions for service owners across the infrastructure.
- Vulnerability Governance: Partner with Compliance and IT to mature vulnerability standards, SLAs, and risk exception processes across the global digital estate.
- Vulnerability Analysis: Provide deep security subject matter expertise to analyze complex vulnerabilities, assess true risk, and drive informed decisions on remediation verdicts, false positives, and risk acceptance.
- Cross-Functional Collaboration: Partner with IT, product, and operations teams to integrate security posture improvements across the entire environment.
Basic Qualifications
- 7+ years of industry experience in software development, with a focus on large-scale security or infrastructure engineering.
- Expertise in building distributed systems and high-availability security platforms using Golang, Java, or Python.
- Proven track record of designing and operating vulnerability management tools at scale.
- Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines.
- Experience leading cross-functional security initiatives and mentoring senior engineering staff.
Preferred Qualifications
- Hands-on experience developing Risk-Based Vulnerability Management (RBVM) frameworks and automated prioritization logic.
- Knowledge of AI/ML applications in security, specifically for vulnerability triage or large-scale data analysis.
- Experience with External Attack Surface Management (EASM) and tracking internet-facing asset exposure.
- Familiarity with Software Supply Chain Security (SSCS), including SBOM and internal package registries.
Ready to Ride?
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.
For New York City, NY-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For San Francisco, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For Seattle, WA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For Sunnyvale, CA-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year.
For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.