Sr. Security Engineer - Application Security @ Uber - Pacifica, CA

Job Overview

12 days ago

Sr. Security Engineer - Application Security

Uber - Pacifica, CA

About the Role
We are seeking a hardworking Sr. Security Engineer to join our Vulnerability Discovery team. The new member of our team will focus on scaling the traditional AppSec model of finding vulnerabilities manually to a fully automated and autonomous system. To that end, our new teammate will be tasked with designing, implementing and deploying security automation and services capable of identifying security vulnerabilities such as XSS, SQLi, CSRF, SSRF, etc. in our mobile, web and infrastructure-related apps and services. You can expect to spend 50+% of your time writing code/implementing security tools to scale the discovery of common security vulnerabilities. The nUber will also lead medium- to large-scale security projects, be responsible for creating long-term project roadmaps, prioritizing project objectives, as well as executing on those objectives and roadmaps in well-defined timelines.

What You'll Do
  • Design, build and deploy automation leveraging manually discovered security findings to scale vulnerability discovery efforts across more than 5,000 services
  • Identify security-sensitive functionality in apps and services lacking security coverage and build out automation to bring security awareness into the affected areas
  • Identify novel attacks and security weaknesses in company-owned assets and automate their discovery using state-of-the-art control-flow and data-flow analysis techniques, methods, and tools
  • Identify gaps in apps, services, and infrastructure lacking proper security scans, build-out and execute on a project roadmap to ensure 100% coverage across all assets and asset groups.
  • Perform threat modeling, design, and code reviews to assess security implications and requirements for the introduction of new systems and technologies
  • Provide security guidance to application and service owners to remediate security vulnerabilities
  • Mentor junior security engineers

Basic Qualifications:
  • Bachelor's in Computer Science or a related field or equivalent industry experience
  • Expertise in at least one security domain (e.g., web security, reverse engineering, etc.)
  • Expertise finding and fixing common security vulnerabilities (e.g., OWASP Top 10)
  • Programming skills in at least one of: Go, Java, Python, NodeJS, etc.

Preferred Qualifications:
  • Mobile (iOS/Android) development experience
  • Experience designing, implementing, and deploying large distributed systems
  • Prior vulnerability management experience
  • Expertise in multiple security domains or cryptosystems
  • Ability to see the big picture, build out concise, comprehensive, yet realistic project plans
  • Ability to communicate ideas and proposals concisely
  • Proven track record demonstrating impact across several teams, organizations and/or security areas

About the Team
We are a team of Software Engineers with Security Mindsets. We lead the vulnerability discovery initiative at Uber. We ensure that all code at Uber adheres to company-wide security standards and is devoid of known security vulnerabilities.
To that end, we design, develop and deploy automation to detect, track and remediate vulnerabilities in over 5,000 services.
In addition, we crowdsource security intelligence via our Bug Bounty program, red team exercises, as well as manual and automated security audits.
Finally, we use research-quality CFG and DFG principles to codify the latest security breakthroughs into custom queries, which we then deploy across our fleet of advanced security scanners. As a result, we expand the return on investment of our manual labor. Our constantly increasing corpus of security queries enables us to perform automated, systematic and comprehensive security analysis across all of Uber's applications and services.

Similar Jobs

Sr. Associate, Cyber Security – Cloud DevOps Engineer

KPMG

Santa Clara, CA

Automate, build, deploy and integrate security tools with application pipelines. Experience with security tools for SAST/DAST/RASP like SonarQube, Snyk etc.

Sr. Associate, Cyber Security – Cloud DevOps Engineer

KPMG

San Francisco, CA

Automate, build, deploy and integrate security tools with application pipelines. Experience with security tools for SAST/DAST/RASP like SonarQube, Snyk etc.

Sr. Associate, Cyber Security – Cloud DevOps Engineer

KPMG

Sacramento, CA

Automate, build, deploy and integrate security tools with application pipelines. Experience with security tools for SAST/DAST/RASP like SonarQube, Snyk etc.

Sr. Associate, Cyber Security - Cloud DevOps

KPMG

Santa Clara, CA

Automate, build, deploy and integrate security tools with application pipelines. Experience with security tools for SAST/DAST/RASP like SonarQube, Snyk etc.

Sr. Associate, Cyber Security - Cloud DevOps

KPMG

San Francisco, CA

Automate, build, deploy and integrate security tools with application pipelines. Experience with security tools for SAST/DAST/RASP like SonarQube, Snyk etc.

Sr. Associate, Cyber Security - Cloud, DevOps, HashiCorp

KPMG

Sacramento, CA

Lead and mentor teams of Cloud architects and engineers. Proficiency in understanding concepts and technologies in DevOps, IT operations, security, cloud,…

Cybersecurity Assurance Analyst

Intuitive

Sunnyvale, CA

Experienced with network security infrastructure, threats, and vulnerabilities to networks, and mitigate security threats.

Director, Cyber Security - Cloud, DevOps, HashiCorp

KPMG

Sacramento, CA

Lead and mentor teams of Cloud architects and engineers. Proficiency in understanding concepts and technologies in DevOps, IT operations, security, cloud,…

Sr. Associate, Cyber Security - Cloud DevOps

KPMG

Sacramento, CA

Automate, build, deploy and integrate security tools with application pipelines. Experience with security tools for SAST/DAST/RASP like SonarQube, Snyk etc.

Sr. Specialist, Cyber Security - Cloud, DevOps, HashiCorp

KPMG

Sacramento, CA

Lead and mentor teams of Cloud architects and engineers. Proficiency in understanding concepts and technologies in DevOps, IT operations, security, cloud,…

Manager, Cyber Security - Cloud DevOps

KPMG

Sacramento, CA

Lead and mentor teams of Cloud architects and engineers. Proficiency in understanding concepts and technologies in DevOps, IT operations, security, cloud,…

Lead Specialist, Cyber Security - Cloud, DevOps, HashiCorp

KPMG

Sacramento, CA

Lead and mentor teams of Cloud architects and engineers. Proficiency in understanding concepts and technologies in DevOps, IT operations, security, cloud,…

Staff Software Security Engineer Trust & Abuse

Databricks

San Francisco, CA

Represent the security engineering discipline throughout the organization, having a powerful voice to make us more data-driven.

Sr. Software Engineer, Data Security

Block

San Francisco, CA

Act as an internal security subject matter expert, advocating for better security practices throughout Block. PCI security standards (including DSS and PTS).

Principal Cloud Security Engineer

Palo Alto Networks

Santa Clara, CA

7-10 years of combined experience as an software engineer, infrastructure engineer, network engineer or cloud security engineer.

Senior Staff Cyber Offense Engineer

Databricks

San Francisco, CA

Understanding of security technologies, especially their limitations. Knowledge and experience with network, host and application security practices.

Principal Software Engineer , Prisma Cloud Security

Palo Alto Networks

Santa Clara, CA

It is easy to operate, with capabilities that work together, so customers can prevent successful cyberattacks.

Sr. Threat and Vulnerability Analyst

LiveRamp

San Francisco, CA

Hand-on experience with Static and Dynamic application security testing. Analyze and validate security assessment findings leveraging different tools (i.e. Burp…

PES Security and Compliance Engineer - 76393

Pinnacle Group

Austin, CA

Must thoroughly understand web application n-tier architecture and web security. For the last 6 months at least, has been doing nothing but penetration testing…

Engineering Manager, Platform Security

Discord

San Francisco, CA

Guide important security programs the affect hundreds of developers including Identity and Access management, Secrets management, CI/CD security, and cloud and…

Lead Information Security Analyst

WELLS FARGO BANK

Concord, CA

Provide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediation.

Lead Information Security Analyst

WELLS FARGO BANK

San Francisco, CA

Provide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediation.

Lead Information Security Analyst

WELLS FARGO BANK

San Leandro, CA

Provide advanced information security consultation for all aspects of information security compliance policy, risk management, and remediation.

Lead Information Security Engineer

WELLS FARGO BANK

San Francisco, CA

Provide security consulting on large projects for internal clients to ensure conformity with corporate information, security policy, and standards.

Ad