SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Technologist II - Privacy Design Review

Uber - San Francisco, CA, United States - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 153,000 - 170,000 / annual

Uber's Security Review Team is seeking a Security Technologist II to proactively identify and reduce risk across critical services and emerging technologies. This role combines deep technical security expertise with an automation-first engineering mindset, evolving traditional point-in-time testing toward continuous, scalable adversarial security testing. Key Responsibilities: - Lead complex security and privacy design reviews across Uber services, applications, APIs, infrastructure, and AI systems, independently analyzing architecture, data flows, trust boundaries, access controls, and security assumptions to identify systemic risks early in development. - Lead threat modeling for critical and high-risk systems, identifying attack surfaces, trust boundaries, abuse cases, and architectural weaknesses while partnering with engineering teams to design effective mitigations. - Conduct advanced hands-on adversarial assessments of third-party AI agents and agentic systems, evaluating security risks across models, sensitive data, permissions, tools, external integrations, and runtime behavior. - Perform code-assisted security reviews and targeted penetration testing to validate architectural assumptions, security controls, authorization boundaries, and potential attack paths. - Lead security and privacy analysis of sensitive-data handling across complex systems and AI integrations, evaluating data collection, access, processing, storage, sharing, retention, and deletion. - Own complex security assessments end-to-end, from scoping and technical analysis through risk determination, remediation guidance, stakeholder alignment, and validation of implemented controls. - Partner directly with engineering teams, security and privacy stakeholders, and third-party vendors to resolve complex security issues and drive findings through remediation. - Design and advance AI-powered automation for security design reviews, threat modeling, adversarial testing, and vulnerability validation, transforming expert security analysis into scalable workflows. - Develop new assessment methodologies, threat models, testing techniques, and reusable frameworks that enable consistent assessment of emerging technologies. - Identify recurring vulnerabilities and systemic security weaknesses, partnering with teams to develop durable controls that eliminate entire classes of security risk. - Serve as a technical security resource for complex assessments, providing guidance and review to other security practitioners. Requirements: - 5+ years of professional experience in security engineering, application security, product security, offensive security, or related technical security roles, with demonstrated experience independently leading complex security assessments. - Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience. - Demonstrated ability to independently review complex technical designs and architectures, identify systemic security risks, and provide security guidance across applications, APIs, cloud services, distributed systems, infrastructure, and third-party integrations. - Advanced experience performing threat modeling and attack-path analysis across complex systems, including identifying attack surfaces, trust boundaries, security assumptions, chained attack paths, and appropriate mitigations. - Strong knowledge of security and privacy principles, including authentication, authorization, identity, least privilege, data protection, isolation, trust boundaries, and secure handling of sensitive information. - Significant hands-on experience with security testing, vulnerability research and investigation, penetration testing, or adversarial testing, including validating exploitability and effectiveness of security controls. - Ability to analyze source code, system architecture, APIs, and runtime behavior to validate security assumptions and identify vulnerabilities. - Proficiency developing security tooling and automation using languages such as Python, Go, or similar, with demonstrated ability to use AI-assisted development and automation to improve security assessment workflows. - Demonstrated ability to independently own complex security assessments from initial scoping through findings, remediation guidance, stakeholder alignment, and validation. - Strong written and verbal communication skills, with demonstrated ability to explain complex security risks to engineering and non-technical stakeholders, influence technical decisions, and drive remediation across organizational boundaries. Preferred Qualifications: - Advanced experience conducting adversarial security assessments of AI agents, large language model applications, agentic systems, or systems that interact with external tools, sensitive data, and third-party services. - Deep understanding of AI-specific attack surfaces and vulnerabilities, including prompt injection, indirect prompt injection, sensitive-data disclosure, excessive agency and permissions, tool misuse, insecure integrations, and unintended autonomous behavior. - Experience performing complex privacy design reviews and analyzing end-to-end data lifecycles. - Demonstrated experience identifying complex and chained attack paths across application, identity, infrastructure, cloud, data, and third-party trust boundaries. - Experience performing code-assisted security reviews and using source code, configuration, APIs, and runtime behavior to validate architectural assumptions. - Advanced experience applying AI/LLMs and agentic workflows to automate or augment security design reviews, threat modeling, vulnerability discovery, adversarial testing, and security control validation. - Experience designing AI-powered security workflows that autonomously gather technical context, reason across multiple sources, invoke security tools, generate attack hypotheses, validate findings, and produce evidence-backed security assessments. - Experience building or integrating security knowledge systems that leverage security standards, historical findings, architectural patterns, threat intelligence, and previous assessments. - Experience evaluating AI-generated security analysis through benchmarking, regression testing, expert comparison, coverage measurement, false-positive analysis, and other methods. - Experience assessing complex security architectures spanning interconnected cloud services, distributed systems, enterprise SaaS platforms, APIs, identity systems, data platforms, and third-party integrations. - Demonstrated ability to develop reusable security methodologies, threat models, assessment frameworks, testing approaches, and automation that improve the quality, consistency, and scalability of security reviews. - Experience serving as a technical security resource for other engineers, providing guidance on complex assessments, reviewing security analysis, and helping raise the technical capabilities of the broader team. - Demonstrated experience managing multiple complex assessments simultaneously and working directly with engineering teams, security and privacy stakeholders, and third-party vendors.

Similar roles