Staff Security Engineer - Vulnerability Management

Uber - Seattle, WA

Hiring: Staff Security Engineer - Vulnerability Management Company: Uber Location: Seattle, WA Job Posted Time: 2026-09-03 02:13:00 Employment Type: Full-time / Remote Target Skills & Keywords : CI/CD, Compliance, Go, Java, Kind, LLM, Python, SBOM, containerd About the job Experience: •7+ years of industry experience in software development, with a focus on large-scale security or infrastructure engineering. Required Skills: •Staff Security Engineer, Vulnerability Management •To lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk-Based Vulnerability Management (RBVM) systems, transforming how we identify, prioritize, and remediate exposure across a massive digital footprint. •RBVM Platform Architecture: Design and scale Security Posture Management tools and platforms to provide a unified, risk-scored view of vulnerabilities across on-prem, cloud, containers, VMs, and endpoints. •Automation & Orchestration: Build automated remediation workflows and systems that will reduce median response times for emerging threats and scale across decentralized teams. •Technical Strategy: Lead "Shift-Left" initiatives by integrating vulnerability scanning into development workflows, CI/CD pipelines, and infrastructure provisioning to enforce security policies consistently across all asset types, including cloud resources, endpoints, and applications. •AI/ML Innovation: Leverage LLMs and AI agents for automated triage, impact analysis, and generating context-aware remediation instructions for service owners across the infrastructure. •Vulnerability Governance: Partner with Compliance and IT to mature vulnerability standards, SLAs, and risk exception processes across the global digital estate. •Vulnerability Analysis: Provide deep security subject matter expertise to analyze complex vulnerabilities, assess true risk, and drive informed decisions on remediation verdicts, false positives, and risk acceptance. Qualifications: •7+ years of industry experience in software development, with a focus on large-scale security or infrastructure engineering. •Expertise in building distributed systems and high-availability security platforms using Golang, Java, or Python. •Demonstrated success in designing and operating vulnerability management tools at scale. •Comprehensive expertise in container security, cloud-native infrastructure, and CI/CD pipelines. •Experience leading cross-functional security initiatives and mentoring senior engineering staff. •Hands-on experience developing Risk-Based Vulnerability Management (RBVM) frameworks and automated prioritization logic. •Knowledge of AI/ML applications in security, specifically for vulnerability triage or large-scale data analysis. •Practical experience utilizing External Attack Surface Management (EASM) and tracking internet-facing asset exposure. •Operational familiarity with Software Supply Chain Security (SSCS), including SBOM and internal package registries. •For New York City, NY-based roles: The base salary range for this role is USD $232,000 per year - USD $258,000 per year. Compensation: •$232,000 per year •$258,000 per year •Flexible work environment (work from home / hybrid options) •All full-time employees are eligible to participate in a 401(k) plan Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!