Cleaned Document
USE THIS JD TEMPLATE
About the role and team
Engineering at Uber means building for real-world impact under real-world constraints. The problems are complex, the systems are massive, and the pace is fast. You'll need to make smart decisions with imperfect information - and own them. If you think in systems, stay calm under pressure, and care about building things that actually work - this is where you'll grow.
As a Security Analyst within
< > , you are at the front lines of protecting Uber, our customers, and our partners. This is a technical, investigative role that requires you to stay steady during high-stakes security incidents and move with urgency to mitigate threats. You won't just be monitoring dashboards; you'll be solving complex security puzzles, conducting digital forensics, and building automated solutions to scale our global defenses in a high-pressure environment that demands both grit and adaptability.
What you'll do
- Act as a first responder to security alerts, triaging and containing cyber threats across Uber's global platform in a high-velocity, high-stakes environment.
- Conduct in-depth forensic investigations by analyzing logs, network traffic, and host telemetry to determine the root cause, scope, and impact of sophisticated attacks.
- Develop and deploy automated scripts and SOAR playbooks to streamline incident response workflows and increase team efficiency.
- Proactively hunt for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
- Collaborate across engineering and product teams to share threat intelligence, resolve blockers, and lead incident investigations through to remediation.
- Communicate investigative findings and technical root cause analysis clearly to help shape long-term security strategy and influence senior leadership.
Basic Qualifications
- Bachelor's degree in Computer Engineering, Information Security, or a related technical field (or equivalent professional experience).
- Minimum 2 years of professional experience in a security-focused role such as Incident Response, Security Operations (SOC), or Digital Forensics.
- Experience with technical security solutions including SIEM, EDR, and network monitoring tools.
- Proven track record of managing incident response and handling in a professional, enterprise environment.
- Exceptional communication skills with the ability to independently communicate technical topics concisely and contribute to technical documentation like runbooks or wikis.
Preferred Qualifications
- 2 + years of professional experience in Incident Response or Digital Forensics within a large-scale technology platform.
- Proficiency in a programming language such as Python or Go for incident response automation and data analysis.
- Hands-on experience with SOAR platforms (e.g., Splunk Phantom, Cortex XSOAR) and developing automated response playbooks.
- Experience with using GenAI or vision-language models to assist in investigations and incident response.
- Strong understanding of network protocols, system security, and common threat vectors/TTPs.
-
Scrap
-
JDs leveraged to build template
Role #1
About the role and team
Engineering at Uber means building for real-world impact under real-world constraints. The problems are complex, the systems are massive, and the pace is fast. You'll need to make smart decisions with imperfect information - and own them. If you think in systems, stay calm under pressure, and care about building things that actually work - this is where you'll grow.
As a Security Analyst within our vSOC (Virtual Security Operations Center) and CIRT (CyberSecurity Incident Response Team), you are at the front lines of protecting Uber, our customers, and our partners. This is a technical, investigative role that requires you to stay steady during high-stakes security incidents and move with urgency to mitigate threats. You won't just be monitoring dashboards; you'll be solving complex security puzzles, conducting digital forensics, and building automated solutions to scale our global defenses.
What you'll do
- Act as a first responder to security alerts, triaging and containing cyber threats across Uber's global platform in a high-velocity environment.
- Conduct in-depth forensic investigations by analyzing logs, network traffic, and host telemetry to determine the root cause, scope, and impact of sophisticated attacks.
- Develop and deploy automated scripts and SOAR playbooks to streamline incident response workflows and increase team efficiency.
- Proactively hunt for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
- Coordinate end-to-end incident handling and bug bounty cases, partnering closely with engineering leads and stakeholders to strengthen our security posture.
- Communicate investigative findings clearly and concisely to help shape long-term security strategy and influence senior leadership.
Basic Qualifications
- Minimum 3 years of professional experience in a security-focused role, such as Incident Response or Security Operations (SOC).
- Proven track record of ownership within a service scope, prioritizing key areas of improvement and delivering on tasks that support standards of excellence.
- Basic working knowledge of security design, architecture, and platforms, with the ability to troubleshoot issues and analyze technical details within a specific domain.
- Demonstrated bias for action as a self-starter who simplifies decision-making processes and uses data to inform deadlines and action-oriented results.
- Exceptional communication skills with the ability to independently communicate low-complexity topics concisely and contribute to technical documentation (runbooks, wikis, ERDs).
- Proficiency in delivering results by effectively managing time, breaking large tasks into smaller components, and proactively communicating progress to stakeholders.
- Experience with technical security solutions including SIEM, EDR, and network monitoring tools.
- Bachelor's degree in Computer Science, Information Security, or a related technical field (or equivalent professional experience).
Preferred Qualifications
- Experience working in a 24/7 global operations model and handling crisis events for large-scale technology platforms.
- Proficiency in a programming language (e.g., Python, Go) for incident response automation and data analysis.
- Hands-on experience across multiple domains such as cloud security, host forensics, and vision-language or GenAI-assisted investigations.
- Strong understanding of network protocols (TCP/IP stack), system security, and common threat vectors/TTPs.
- Professional security certifications (e.g., GIAC, OSCP) are a plus.
Role #2
About the Role
The CyberSecurity Incident Response team (CIRT) is at the forefront of protecting Uber, our customers, and our partners from evolving security threats. We are a hands-on, fast-paced team that responds to security incidents, conducts forensic investigations, and builds automated solutions to scale our defenses.
As a Security Analyst on the CIRT team, you will be a key player in our incident response efforts. This is a technical and investigative role where you'll be responsible for:
- Responding to security incidents and mitigating threats across the company. Partner closely with the SOC analysts and incident commanders, leading incident investigations.
- Conducting in-depth investigations and digital forensics to uncover the root cause of attacks.
- Developing and implementing automation solutions using tools like SIEM and SOAR to improve our response capabilities.
- Collaborating with other security and engineering teams to address vulnerabilities and strengthen our security posture.
- Communicating your findings clearly and concisely to help shape our long-term security strategy.
We are looking for someone who is passionate about solving complex security puzzles and is eager to build innovative solutions to protect a global platform.
What the Candidate Will Need / Bonus Points
- What the Candidate Will Do -
Incident Response : Act as a first responder to security alerts, triaging and containing threats across the Uber platform.
Forensic Analysis : Investigate security incidents by analyzing logs, network traffic, and host data to determine the root cause, scope, and impact.
Automation : Develop and deploy scripts and playbooks to automate incident response workflows and improve team efficiency.
Threat Hunting : Proactively search for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
Collaboration : Partner with other teams to share threat intelligence, recommend security improvements, and communicate incident findings.
- Basic Qualifications -
- Bachelor's degree in Computer Science, Information Security, or a related field..
- 2+ years of professional experience in a security-focused role, such as Incident Response, Security Operations, or Digital Forensics.
- Proven experience with incident response and handling in a professional environment.
- Familiarity with common security tools and technologies (e.g., SIEM, EDR, network monitoring).
- Experience with SOAR platforms (e.g., Splunk Phantom, Cortex XSOAR etc) and developing automated playbooks.
- Strong problem-solving skills and the ability to work effectively under pressure.
- Excellent written and verbal communication skills.
- Preferred Qualifications -
- 3+ years of professional experience in a security-focused role, such as Incident Response, Security Operations, or Digital Forensics.
- Experience in a large-scale, enterprise environment, particularly within the technology sectors.
- Hands-on experience across multiple domains such as network, hosts, applications, data, cloud security etc.
- Experience in a programming language (e.g., Python, Go, C++, Java, etc) for incident response related automation and data analysis.
Experience with using GenAI in incident response and investigations is a plus.
Ready to Ride?
This isn't the kind of place where you follow a playbook - it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves - we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.