Uber logo

Sr Security Technologist - Third Party Risk

Uber

Seattle, WA · HybridFull-time$180–200K/yrSeen 2 days agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$180–200K/yr
Location
Seattle, WAHybrid
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Sr Security Technologist on Uber's Third-Party Risk Management team will engineer and automate the TPRM program, building code, AI‑assisted workflows, and integrations to identify, assess, and monitor vendor security risks at scale while leading day‑to‑day operations and managing escalations.

Skills & qualifications

RequiredNice to have

Skills

PythonGoBashAutomationAI‑Assisted DevelopmentAPI IntegrationSecurity ToolingCloud InfrastructureIdentity and Access ManagementEndpoint SecurityVulnerability ManagementLogging and TelemetryEnterprise SaaS PlatformsNetworking FundamentalsRisk ManagementTechnical Security ControlsProgram ManagementWritten CommunicationProblem Solving

Qualifications

5+ Years Security Engineering ExperienceBachelor's Degree in Computer Science or Related Field

Benefits

401(k) Match

Full job description

About the Role

As a Senior Security Technologist on Uber's Third-Party Risk Management (TPRM) team, you will help operate, engineer, and transform Uber's TPRM program. You will help ensure third-party security risks are effectively identified, assessed, monitored, and managed across Uber's global vendor ecosystem while building the technology and automation needed to operate the program at scale.

This role requires an automation-first, engineering mindset. You will approach operational and risk challenges by first asking how they can be solved through code, automation, AI, better data, or system integrations, rather than adding manual processes. You will be expected to prototype and build solutions yourself, automate repeatable work, and partner with engineering teams on larger capabilities that fundamentally improve how third-party risk is managed.

You will also serve as a lead for day-to-day TPRM operations. You will oversee our managed service provider (MSP), manage escalations and complex vendor issues, support third-party security incidents, and partner across Engineering Security, Legal, Privacy, Procurement, and business teams to drive appropriate risk decisions. You will use the problems, friction, and patterns you see in the program to identify what should be automated, redesigned, or eliminated.

You will help move TPRM beyond manual, point-in-time assessments toward a more automated, continuous, data-driven, and intelligence-led approach. This includes building automation and integrations, developing AI-assisted workflows and agents, improving the TPRM platform and data ecosystem, and bringing together internal and external security signals to enable faster and better risk decisions.

The ideal candidate is comfortable:

  • writing code and independently building automation, integrations, and technical solutions,

  • identifying manual processes and redesigning them through an automation-first approach,

  • leveraging AI and agentic workflows to solve security and operational problems,

  • leading day-to-day TPRM operations and managing escalations,

  • managing MSP delivery, quality, and performance,

  • assessing third-party security risk and technical security controls,

  • working directly with vendors to resolve complex security and risk issues,

  • supporting third-party security incidents and assessing potential impact,

  • managing and improving TPRM platforms, workflows, and data,

  • and communicating technical risk to leadership and business stakeholders.

You'll be successful in this role if you can combine security risk expertise with hands-on technical execution-solving today's operational challenges while continuously engineering better ways for TPRM to operate at scale.

What You'll Do

  • Build automation, tooling, agents, and integrations to solve TPRM problems, eliminate repetitive manual work, improve decision quality, and enable the program to scale

  • Write code and prototype solutions directly, using APIs, security and risk data, AI-assisted development, and other technologies to rapidly solve operational and risk management challenges

  • Identify recurring operational problems and determine where automation, AI, improved data, or redesigned workflows can replace manual processes

  • Lead day-to-day TPRM operations, including third-party security assessments, risk decisions, stakeholder and vendor escalations, and delivery against established service levels

  • Oversee TPRM managed service provider delivery and performance, including workload, quality, capacity, SLAs, issue resolution, and continuous improvement

  • Manage complex third-party security issues and work directly with vendors and internal stakeholders to evaluate risk, challenge responses, resolve gaps, and drive appropriate remediation or risk treatment

  • Support third-party security incidents by assessing Uber's potential exposure, coordinating with relevant Engineering Security teams and vendors, and helping drive appropriate risk response

  • Manage and continuously improve TPRM platforms, workflows, integrations, data quality, and reporting, and partner with engineering teams on larger program transformation capabilities

  • Help evolve TPRM toward more continuous and intelligence-driven risk management by integrating security signals, automating assessments and monitoring, and identifying opportunities for program-wide transformation

Basic Qualifications

  • 5+ years of experience in security engineering, third-party risk management, cloud security, infrastructure security, security assurance, security risk, or related technical security roles

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience

  • Hands-on experience writing code and building automation using languages such as Python, Go, Bash, or similar, with the ability to translate manual or operational problems into scalable technical solutions

  • Experience building integrations and working with APIs, security tooling, automation platforms, and AI-assisted development workflows

  • Experience managing or supporting day-to-day third-party risk management or security assurance operations, including complex security and stakeholder escalations

  • Experience overseeing managed service providers, external delivery teams, or similar operational delivery models

  • Experience applying risk management principles, assessing technical security controls, and evaluating security evidence across modern cloud, SaaS, and enterprise environments

  • Understanding of:

  • cloud infrastructure and security

  • identity and access management

  • endpoint security

  • vulnerability management

  • logging and telemetry systems

  • enterprise SaaS platforms

  • networking fundamentals

  • Ability to communicate complex technical concepts and security risk clearly to technical teams, vendors, business stakeholders, and leadership

  • Comfort navigating ambiguity, managing escalations, and independently solving technical and operational problems in fast-moving environments

Preferred Qualifications

  • Strong experience in Third-Party Risk Management, vendor security, or security assurance

  • Experience leading or managing TPRM operations at scale

  • Experience managing MSP performance, including quality, capacity, SLAs, and operational metrics

  • Experience supporting third-party security incidents and evaluating organizational exposure to vendor incidents or vulnerabilities

  • Experience administering, configuring, or helping manage TPRM, GRC, or security workflow platforms

  • Experience building internal security tooling, agents, workflow automation, or operational automation platforms

  • Experience designing integrations across security systems and data sources using APIs and automated workflows

  • Experience using LLMs or AI tooling to build or significantly improve security analysis, assessment, or TPRM workflows

  • Strong investigative, problem-solving, written communication, and program management skills

  • Demonstrated ability to identify opportunities for process improvement and translate them into practical technical solutions

  • Ability to balance hands-on technical execution, day-to-day operations, and longer-term program transformation

For San Francisco, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For Seattle, WA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For Sunnyvale, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.

For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.

Ready to Ride?

This isn't the kind of place where you follow a playbook - it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves - we'd love to hear from you.

You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits. (https://jobs.uber.com/en/benefits/)

Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.

Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form. (https://forms.gle/aDWTk9k6xtMU25Y5A?uclick\_id=d56eb634-bfb9-455e-a50d-901b3de0490c)

Uber is proud to be an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form- https://docs.google.com/forms/d/e/1FAIpQLSdb_Y9Bv8-lWDMbpidF2GKXsxzNh11wUUVS7fM1znOfEJsVeA/viewform

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.