Software Engineer II - Security Review Automation
Listed on 2026-10-09
-
IT/Tech
Cybersecurity
The Role And Team
As a member of Uber's Offensive Security team, you will build the security tools, platforms, and AI-powered automation that enable security testing and risk reduction at Uber scale. You will develop software that automates and enhances security processes including security design reviews, threat modeling, penetration testing, vulnerability discovery and validation, and AI agent security testing. This role combines strong software engineering with an automation-first mindset, applying AI and frontier models to transform traditionally manual security processes into continuous, scalable capabilities integrated across Uber's technology ecosystem.
As a member of Uber's Offensive Security team, you will build the security tools, platforms, and AI-powered automation that enable security testing and risk reduction at Uber scale. You will develop software that automates and enhances security processes including security design reviews, threat modeling, penetration testing, vulnerability discovery and validation, and AI agent security testing. This role combines strong software engineering with an automation-first mindset, applying AI and frontier models to transform traditionally manual security processes into continuous, scalable capabilities integrated across Uber's technology ecosystem.
The problems here are messy and the systems are global. You'll need to make smart decisions with imperfect information, own your work end-to-end, and stay calm when high-load systems are on the line. We are looking for engineers who think in systems, pride themselves on robust monitoring, and believe that the best solutions are built through candid feedback and cross-functional collaboration.
If you're energized by challenges and motivated to move the real world - this is where you'll grow.
- Build software platforms and automation across static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), penetration testing, AI red teaming, security design reviews, and threat modeling.
- Develop AI-powered agents and workflows that analyze source code and technical designs, orchestrate security assessments, generate test cases, and validate findings.
- Partner with security engineers to translate their expertise into repeatable, scalable capabilities.
- Build and scale foundational infrastructure and data pipelines, balancing technical debt and shifting priorities while keeping long-term impact in mind.
- Integrate security capabilities with source control, CI/CD pipelines, service inventories, and issue-tracking systems to enable continuous and on-demand testing throughout the software development lifecycle.
- Build shared services for assessment orchestration, findings normalization and deduplication, and remediation tracking, reducing duplicate findings and manual work for security and engineering teams.
- Design, develop, and maintain high-quality code for features of moderate complexity and projects with multiple dependencies.
- Develop evaluation frameworks and operational safeguards for AI-driven security workflows, measuring accuracy, coverage, latency, and cost while enforcing appropriate access controls, execution boundaries, and auditability.
- Own the software lifecycle end-to-end, from drafting design docs to debugging production issues and managing incidents independently.
- Collaborate across disciplines - including Product, Data Science, and Ops - to translate ambiguous requirements into simple, elegant system designs.
- Champion engineering best practices by providing quality code reviews, creating comprehensive tests, and improving system performance.
- Navigate internal complexity and stakeholder inquiries to unblock…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).