This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Staff Security Engineer, you will be the lead architect for Uber’s next-generation cloud security infrastructure. Operating at the intersection of Cloud Architecture and Applied AI, you will move beyond static controls to build a dynamic, autonomous security ecosystem across our multi-cloud estate, especially GCP and OCI. Your mission is to transform Cloud Security Posture Management (CSPM) from a reactive alerting system into a proactive, self-healing machine. You will spearhead the use of GenAI and AI Agent Orchestration to automate complex security reasoning—building intelligent agents that can independently analyze, prioritize, and remediate exploitable risks at scale. You will also provide security design solutions to support Uber's new business initiatives to ensure secure-by-design and compliance.
Job Responsibility:
Strategic Architecture: Define the long-term roadmap for Identity-centric security and automated posture management for tens of thousands cloud users
AI Orchestration: Design and deploy Multi-Agent systems and RAG pipelines to automate the end-to-end security remediation lifecycle
Scaling Control: Implement "LLM-as-a-Judge" frameworks to ensure the safety and precision of autonomous security actions
Harden the Perimeter: Eliminate security hotspots and enforce secure-by-default baselines across all cloud platforms
Technical Leadership: Serve as a force-multiplier, mentoring engineers and bridging the gap between security research and production engineering
Requirements:
Multi-Cloud Expertise: 5+ years of experience in Cloud Security, with direct, hands-on experience architecting and securing Google Cloud Platform (GCP) and Oracle Cloud Infrastructure (OCI)
Security Posture Management: Expert-level understanding of CSPM frameworks, Deep knowledge of IAM, Network, vulnerability management (CVE reachability), and the automation of security baselines at scale
Backend Systems Engineering: Proven track record of building scalable distributed systems (Go, Python, or Java) and managing complex security pipelines in large-scale environments
Applied GenAI: Professional experience with LLM application development, including RAG patterns, vector databases, and AI Agent orchestration frameworks (e.g., LangChain, AutoGen)
Nice to have:
Strategic Translation & Execution: Proven ability to translate complex business objectives and regulatory compliance requirements (e.g., SOX, GDPR, PCI) into high-level architectural designs and actionable technical roadmaps. You should have a track record of bridging the gap between legal/audit stakeholders and engineering execution
Security Innovation: Experience pioneering the use of emerging technologies to solve legacy security debt, specifically using AI/ML to automate compliance auditing or to perform predictive risk analysis
Cross-Functional Influence: A history of leading large-scale security transformations by influencing senior leadership and partnering with DevOps/Infrastructure teams to adopt "Security-as-Code" practices
CNAPP Proficiency: Extensive experience operationalizing Cloud-Native Application Protection Platforms (CNAPP) such as Wiz or Orca. Must be able to leverage these tools for deep visibility, risk prioritization (attack path analysis), and automated compliance monitoring
What we offer:
Eligible to participate in Uber's bonus program
May be offered an equity award & other types of comp