Security Technologist II - Technical Security
Summary
Security analyst on Uber's CyberSecurity Incident Response Team (CIRT), serving as a first responder to security incidents by conducting digital forensics, threat hunting, and building automation using SIEM/SOAR/EDR and scripting in Python/Bash/Go.
About the Role
The CyberSecurity Incident Response team (CIRT) is at the forefront of protecting Uber, our customers, and our partners from evolving security threats. We are a hands-on, fast-paced team that responds to security incidents, conducts forensic investigations, and builds automated solutions to scale our defence.
As a Security Analyst on the CIRT team, you will be a key player in our incident response efforts. This is a technical and investigative role where you'll be responsible for:
- Responding to security incidents and mitigating threats across the company.
- Conducting in-depth investigations and digital forensics to uncover the root cause of attacks.
- Developing and implementing automation solutions using tools like SIEM and SOAR to improve our response capabilities.
- Collaborating with other security and engineering teams to address vulnerabilities and strengthen our security posture.
- Communicating your findings clearly and concisely to help shape our long-term security strategy.
We are looking for someone who is passionate about solving complex security puzzles and is eager to build innovative solutions to protect a global platform.
What the Candidate Will Need / Bonus Points
---- What the Candidate Will Do ----
- Incident Response : Act as a first responder to security alerts, triaging and containing threats across the Uber platform.
- Forensic Analysis : Investigate security incidents by analyzing logs, network traffic, and host data to determine the root cause, scope, and impact.
- Automation : Develop and deploy scripts and playbooks to automate incident response workflows and improve team efficiency.
- Threat Hunting : Proactively search for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
- Collaboration : Partner with other teams to share threat intelligence, recommend security improvements, and communicate incident findings.
---- Basic Qualifications ----
- Bachelor's degree in Computer Science, Information Security, or a related field..
- 3+ years of professional experience in a security-focused role, such as Incident Response, Security Operations, or Digital Forensics.
- Proven experience with incident response and handling in a professional environment.
- Familiarity with common security tools and technologies (e.g., SIEM, EDR, network monitoring).
- Experience in a scripting language (e.g., Python, Bash) for task automation and data analysis.
- Strong problem-solving skills and the ability to work effectively under pressure.
- Excellent written and verbal communication skills.
---- Preferred Qualifications ----
- Experience in a large-scale, enterprise environment, particularly within the technology sectors.
- Hands-on experience across multiple domains such as network, hosts, applications, data, cloud security etc.
- Strong understanding of network protocols, TCP/IP, and firewall concepts.
- Knowledge of scripting and development in languages like Python or Go .
- Experience with ML and GenAI security concepts is a plus.
For San Francisco, CA-based roles: The base salary range for this role is USD $153,000 per year - USD $170,000 per year.
You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Ready to Ride?
This isn't the kind of place where you follow a playbook — it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves — we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.