SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Technologist II - Design Review

Uber - Seattle, WA, United States - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 153,000 - 170,000 / annual

As a Security Technologist II on Uber's Security Review Team, you will proactively identify and reduce risk across Uber's most critical services and emerging technologies. This role combines deep technical security expertise with an automation-first engineering mindset, evolving traditional point-in-time testing toward continuous, scalable adversarial security testing. Key responsibilities include: • Conduct security and privacy design reviews for services, applications, APIs, and AI integrations, evaluating architecture, data flows, access controls, and proposed safeguards to identify risks early in development. • Perform threat modeling for critical services and AI agents, identifying attack surfaces, trust boundaries, potential attack paths, and appropriate mitigations. • Test third-party AI agents through hands-on adversarial assessments, evaluating risks across models, data access, permissions, tools, external integrations, and runtime behavior. Validate whether identified weaknesses can lead to unauthorized actions or sensitive-data exposure. • Evaluate sensitive-data handling across services and AI integrations, assessing how data is collected, accessed, stored, shared, retained, and deleted. Partner with privacy stakeholders to identify gaps and recommend safeguards. • Document actionable findings with clear descriptions, supporting evidence, reproducible test steps, risk assessments, and practical remediation guidance. • Partner with engineering teams and third-party vendors to address assessment findings, clarify security and privacy requirements, and verify that implemented mitigations resolve identified risks. • Build and improve AI-powered automation for design reviews, threat modeling, agent testing, and vulnerability validation, reducing repetitive work and increasing assessment consistency, depth, and throughput. • Develop reusable assessment materials such as review checklists, threat models, test cases, and reporting templates to support repeatable, high-quality assessments across the team. REQUIREMENTS: Basic Qualifications: • 3+ years of experience in security engineering, application security, product security, offensive security, or related technical security roles. • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience. • Experience reviewing technical designs and identifying security risks in applications, APIs, cloud services, or distributed systems. • Experience performing threat modeling, analyzing attack paths, and recommending mitigations based on technical risk and potential impact. • Understanding of security and privacy principles, including authentication, authorization, least privilege, data protection, and secure handling of sensitive information. • Hands-on experience with security testing, vulnerability investigation, or validating the effectiveness of security controls. • Experience writing code or automation using languages such as Python, Go, Bash, or similar, and familiarity with AI-assisted development workflows. • Ability to communicate technical findings clearly to technical and non-technical audiences, document actionable recommendations, and collaborate across teams with evolving priorities. Preferred Qualifications: • Experience conducting security assessments or adversarial testing of third-party AI agents, large language model applications, or systems that interact with external tools and data sources. • Experience performing privacy design reviews and evaluating data flows, access patterns, retention practices, and safeguards for sensitive data. • Experience assessing AI-specific risks involving prompt injection, unintended data disclosure, excessive permissions, or unsafe tool use. • Experience building internal security tooling or using AI to automate design analysis, threat modeling, test execution, or assessment reporting. • Experience assessing security across interconnected cloud services, enterprise SaaS platforms, and third-party integrations. • Experience coordinating multiple assessments, working directly with engineering teams and vendors, and driving findings through remediation and validation.

Similar roles