×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Security Strategist GRC

Job in Sunnyvale, Santa Clara County, California, 94087, USA
Listing for: Uber
Full Time position
Listed on 2026-07-15
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 211000 - 234000 USD Yearly USD 211000.00 234000.00 YEAR
Job Description & How to Apply Below
Position: Staff Security Strategist GRC

Uber's Engineering Security team works to ensure the security of information for our full set of users - riders, eaters, drivers and partners. Our ultimate goal is to ensure that every experience with Uber is simple, secure, and safe. We are seeking a talented Senior Security Strategist, GRC to join our Tech Risk and Assurance team within Engineering Security.

About the Role

The Senior Security Strategist, GRC partners with engineering, security, and cross‑functional risk stakeholders to strengthen Uber's cybersecurity posture through scalable cyber risk management, risk governance, and control design programs. This role is responsible for driving and implementing security, compliance, and risk management programs on the Service Now eGRC platform at Uber, working with the engineering team to develop and enable technical solutions that satisfy a variety of risk and compliance processes.

This role operates at the intersection of technical security, process design, and risk governance. The successful candidate will translate control gaps, threat and business context, and compliance requirements into practical risk treatment plans that engineering teams can execute, while driving consistent risk analysis, decision‑making, and follow‑through. The role must be able to deliver work products required by Agile development methodologies for software development delivery as defined.

What you will do

  • Own cyber risk intake, triage, and prioritization, ensuring clear accountability, well‑formed risk statements, and timely treatment decisions.
  • Develop product strategy and lead project execution for multiple major components of Uber’s Risk and Compliance technology solutions.
  • Manage different solutions on Uber's internal eGRC platform (Service Now) and collaborate with stakeholders to implement their program improvements.
  • Partner with engineering teams to define risk treatment plans, identify sustainable fixes, and drive mitigation or remediation to the last mile rather than stopping at documentation.
  • Gather business and functional requirements from partner teams and deliver a product/release that meets the needs presented. Develop technical specifications documentation.
  • Lead or materially contribute to control design reviews, risk assessments, and risk decisions that require judgment, stakeholder alignment, and tradeoff management.
  • Drive and evangelize vision for overall GRC strategy across engineering and security organizations.
  • Analyze and fully understand user stories and internal procedures in order to improve system capabilities, automate process workflows, and address scheduling limitations throughout the development and delivery of the eGRC platform.
  • Work with developers to implement workflows from customer requirements including workflows, UI actions, client scripts, business rules, etc.
  • Load, manipulate, and maintain data between the eGRC platform and other systems as needed.
  • Build and maintain risk reporting for leaders and partner teams, including KRIs, exposure trends, risk acceptance aging, decision status, and escalation triggers.
  • Design and develop dashboards, home pages, performance analytics data collectors, and reports as needed to support program requirements.
  • Improve the efficiency of risk workflows through automation, better tooling, clearer operating models, and reusable knowledge assets.
  • Perform system and integration testing with sample and live data.
  • Review product performance and provide a continuous improvement path through leveraging industry standard tools and capabilities as well as building new ones.
  • Serve as a bridge between cybersecurity, engineering, audit, privacy, and compliance stakeholders so that security risk becomes practical engineering action.
  • Mentor analysts and junior security partners on risk analysis, risk statement quality, treatment planning, stakeholder communication, and operational rigor.

Basic Qualifications:

  • Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, Risk Management, or related field, or equivalent practical experience.
  • 10+ years of experience in security, cyber risk, GRC, assurance, security operations, or…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary