Jobs · Information Technology · Washington

Staff Security Engineer - Vulnerability Management

Uber · Seattle, WA · 5 days ago
Information Technology$232k/yrFull-time

About The Role

Our mission is to protect, defend, and secure the company's products, infrastructure, and data by building highly available, scalable, and extensible security solutions and services. We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk-Based Vulnerability Management (RBVM) systems, transforming how we identify, prioritize, and remediate exposure across a massive digital footprint. You will drive technical excellence across our vulnerability management landscape, from on-prem, cloud, container security to corporate endpoint hygiene. As a Staff Engineer, you will be a technical visionary and mentor, leading the transition toward Continuous Threat Exposure Management and AI-driven remediation workflows that operate at enterprise scale.

What You Will Do

  • RBVM Platform Architecture: Design and scale Security Posture Management tools and platforms to provide a unified, risk-scored view of vulnerabilities across on-prem, cloud, containers, VMs, and endpoints.
  • Automation & Orchestration: Build automated remediation workflows and systems that will reduce median response times for emerging threats and scale across decentralized teams.
  • Technical Strategy: Lead "Shift-Left" initiatives by integrating vulnerability scanning into development workflows, CI/CD pipelines, and infrastructure provisioning to enforce security policies consistently across all asset types, including cloud resources, endpoints, and applications.
  • AI/ML Innovation: Leverage LLMs and AI agents for automated triage, impact analysis, and generating context-aware remediation instructions for service owners across the infrastructure.
  • Vulnerability Governance: Partner with Compliance and IT to mature vulnerability standards, SLAs, and risk exception processes across the global digital estate.
  • Vulnerability Analysis: Provide deep security subject matter expertise to analyze complex vulnerabilities, assess true risk, and drive informed decisions on remediation verdicts, false positives, and risk acceptance.
  • Cross-Functional Collaboration: Partner with IT, product, and operations teams to integrate security posture improvements across the entire environment.

Basic Qualifications

  • 7+ years of industry experience in software development, with a focus on large-scale security or infrastructure engineering.
  • Expertise in building distributed systems and high-availability security platforms using Golang, Java, or Python.
  • Proven track record of designing and operating vulnerability management tools at scale.
  • Deep understanding of container security, cloud-native infrastructure, and CI/CD pipelines.
  • Experience leading cross-functional security initiatives and mentoring senior engineering staff.

Preferred Qualifications

  • Hands-on experience developing Risk-Based Vulnerability Management (RBVM) frameworks and automated prioritization logic.
  • Knowledge of AI/ML applications in security, specifically for vulnerability triage or large-scale data analysis.
  • Experience with External Attack Surface Management (EASM) and tracking internet-facing asset exposure.
  • Familiarity with Software Supply Chain Security (SSCS), including SBOM and internal package registries.

Similar jobs