This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Uber’s Incident Command team, part of the Threat Defense and Response (TDR) organization, leads the coordination and response to the company’s highest-severity cybersecurity incidents, spanning threats, vulnerabilities, insider risks, and large-scale fraud. The team operates at the intersection of security, reliability, and engineering - across both digital and physical domains - applying disciplined incident management practices to complex, high-impact events. In this role, you will not only lead incident response but also drive its evolution by building and integrating automation and AI-powered systems across response, post-incident review, and proactive readiness programs. You will partner closely with Security, Infrastructure, Product, and Business teams to build a scalable, intelligent incident response ecosystem. Ultimately, you will help define how Uber responds to and prevents incidents - designing systems that augment human decision-making and strengthen resilience across the company.
Job Responsibility:
Lead a global team of incident commanders managing Uber’s highest severity security incidents
Drive structured, effective coordination across engineering, security, and business teams during high-impact events
Partner with Security, Legal, and Privacy on sensitive incidents requiring careful judgment and handling
Evolve incident management practices by integrating security IR and SRE/Ring0 disciplines
Own postmortem, premortem, and incident simulation programs to improve resilience and organizational readiness
Translate external incidents and emerging threats into actionable risk reduction across Uber
Build and integrate automation and AI-driven capabilities into incident response, postmortems, premortems, and incident simulations
Translate incident processes into scalable systems, defining safe automation boundaries and human-in-the-loop decision frameworks
Mentor and grow incident commanders in leadership, decision-making, engineering, and operational excellence
Foster an inclusive, high-performing culture grounded in accountability, learning, and continuous improvement
Requirements:
8+ years of experience in one or more of the following: Security incident response
Production incident management (e.g., SRE, Ring0, reliability engineering)
Security or infrastructure operations
Experience leading or coordinating high-severity incidents in a complex, distributed environment
Experience serving as an incident commander, incident lead, or equivalent leadership role during critical incidents
Strong systems thinking: ability to navigate incidents across infrastructure, applications, and services
Excellent communication and stakeholder management skills, especially under pressure
Experience mentoring or managing engineers or operational responders
Nice to have:
Background in cybersecurity incident response or strong demonstrated ability to quickly ramp in security domains
Experience leading complex, cross-functional incidents end-to-end, including coordination across engineering, security, legal, and business teams
Experience building or improving incident management programs (e.g., postmortems, simulations, escalation/decision frameworks)
Experience designing or implementing automation, platforms, or AI-driven solutions in operational workflows
Familiarity with security concepts such as threats, vulnerabilities, or attacker behaviors (e.g., MITRE ATT&CK)
Experience operating in global, distributed environments with follow-the-sun models
What we offer:
Eligible to participate in Uber's bonus program
May be offered an equity award & other types of comp
All full-time employees are eligible to participate in a 401(k) plan