Software Engineer II, Security Review Automation

Uber Com — United States · Posted ~3 hours ago

Mid Visa History ✓

Skills

software engineering security automation security design reviews threat modeling penetration testing vulnerability discovery vulnerability validation AI security testing monitoring AI AI agents

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join an offensive security engineering team building software and AI-powered automation for continuous security testing and risk reduction. You will automate security design reviews, threat modeling, penetration testing, vulnerability discovery and validation, and AI agent security testing while developing robust, highly monitored systems at global scale.

Highlights

Build security tools and AI-powered automation that scale across a large technology environment. The role combines software engineering, offensive security, threat modeling, vulnerability testing, AI security, monitoring, and end-to-end ownership of complex systems.

Description

About The Role And Team As a member of Uber's Offensive Security team, you will build the security tools, platforms, and AI-powered automation that enable security testing and risk reduction at Uber scale. You will develop software that automates and enhances security processes including security design reviews, threat modeling, penetration testing, vulnerability discovery and validation, and AI agent security testing. This role combines strong software engineering with an automation-first mindset, applying AI and frontier models to transform traditionally manual security processes into continuous, scalable capabilities integrated across Uber's technology ecosystem. The problems here are messy and the systems are global. You'll need to make smart decisions with imperfect information, own your work end-to-end, and stay calm when high-load systems are on the line. We are looking for engineers who think in systems, pride themselves on robust monitoring, and believe that the best solutions are built through candid feedback and cross-functional collaboration. If you're energized by challenges and motivated to move the real world - this is where you'll grow. What You'll Do Build software platforms and automation across static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), penetration testing, AI red teaming, security design reviews, and threat modeling. Develop AI-powered agents and workflows that analyze source code and technical designs, orchestrate security assessments, generate test cases, and validate findings. Partner with security engineers to translate their expertise into repeatable, scalable capabilities. Build and scale foundational infrastructure and data pipelines, balancing technical debt and shifting priorities while keeping long-term impact in mind. Integrate security capabilities with source control, CI/CD pipelines, service inventories, and issue-tracking systems to enable continuous and on-demand testing throughout the software development lifecycle. Build shared services for assessment orchestration, findings normalization and deduplication, and remediation tracking, reducing duplicate findings and manual work for security and engineering teams. Design, develop, and maintain high-quality code for features of moderate complexity and projects with multiple dependencies. Develop evaluation frameworks and operational safeguards for AI-driven security workflows, measuring accuracy, coverage, latency, and cost while enforcing appropriate access controls, execution boundaries, and auditability. Own the software lifecycle end-to-end, from drafting design docs to debugging production issues and managing incidents independently. Collaborate across disciplines - including Product, Data Science, and Ops - to translate ambiguous requirements into simple, elegant system designs. Champion engineering best practices by providing quality code reviews, creating comprehensive tests, and improving system performance. Navigate internal complexity and stakeholder inquiries to unblock dependencies and ensure the reliability of our production environment. Basic Qualifications 3+ years of professional software engineering experience in backend development, distributed systems, or data engineering. Proficiency in one or more object-oriented or functional programming languages (e.g., Go, Java, Python, or C++). Experience with data modeling, query optimization, and translating customer problems into system design. Bachelor's Degree (or equivalent experience) in Computer Science, Engineering, or a related technical field. Experience writing tests to verify functionality and establishing monitoring systems to ensure code stability. Experience building APIs, service integrations, or automated workflows that connect multiple systems in production environments. Understanding of secure software development fundamentals, including authentication, authorization, data protection, and safe handling of credentials. Familiarity with source control, CI/CD, and automated testing practices for delivering reliable software. Preferred Qualifications Experience building agentic security workflows that autonomously gather technical context, reason across multiple data sources, invoke security tools, validate conclusions, and produce evidence-backed security assessments. Experience applying frontier LLMs to complex security reasoning, including architecture analysis, attack-path identification, threat enumeration, vulnerability discovery, and security control validation. Experience developing multi-agent or multi-model architectures that use specialized agents, model routing, or model-as-judge techniques to improve the accuracy, coverage, and confidence of automated security reviews. Experience identifying and reducing code-level technical debt in high-load distributed systems. Background in mentoring new team members and contributing to engineering culture. Proficiency with Big Data frameworks (e.g., Spark, Flink) or real-time data streaming (e.g., Kafka). Demonstrated ability to exercise sound judgment on engineering trade-offs for complex systems. Experience building security tools or automation in one or more of the following domains: SAST, DAST, SCA, penetration testing, AI red teaming, security design reviews, or threat modeling. Experience developing LLM-powered applications or agentic workflows, including model integration, tool execution, context retrieval, and orchestration. Experience building evaluation frameworks for AI-driven systems, including reproducible benchmarks, regression testing, and measurement of output quality and reliability. Familiarity with source-code analysis, dependency graphs, API testing, or isolated execution environments for automated security testing. Experience using AI-assisted development tools to accelerate software implementation, testing, debugging, and maintenance. features. For San Francisco, CA-based roles: The base salary range for this role is USD $171,000 per year - USD $190,000 per year. For Seattle, WA-based roles: The base salary range for this role is USD $171,000 per year - USD $190,000 per year. For Sunnyvale, CA-based roles: The base salary range for this role is USD $171,000 per year - USD $190,000 per year. For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits. Ready to Ride? This isn't the kind of place where you follow a playbook - it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves - we'd love to hear from you. You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits. Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements. Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.