Sr Security Technologist - Third Party Risk
About the Role
As a Senior Security Technologist on Uber's Third-Party Risk Management (TPRM) team, you will help operate, engineer, and transform Uber's TPRM program. You will help ensure third-party security risks are effectively identified, assessed, monitored, and managed across Uber's global vendor ecosystem while building the technology and automation needed to operate the program at scale.
This role requires an automation-first, engineering mindset. You will approach operational and risk challenges by first asking how they can be solved through code, automation, AI, better data, or system integrations, rather than adding manual processes. You will be expected to prototype and build solutions yourself, automate repeatable work, and partner with engineering teams on larger capabilities that fundamentally improve how third-party risk is managed.
You will also serve as a lead for day-to-day TPRM operations. You will oversee our managed service provider (MSP), manage escalations and complex vendor issues, support third-party security incidents, and partner across Engineering Security, Legal, Privacy, Procurement, and business teams to drive appropriate risk decisions. You will use the problems, friction, and patterns you see in the program to identify what should be automated, redesigned, or eliminated.
You will help move TPRM beyond manual, point-in-time assessments toward a more automated, continuous, data-driven, and intelligence-led approach. This includes building automation and integrations, developing AI-assisted workflows and agents, improving the TPRM platform and data ecosystem, and bringing together internal and external security signals to enable faster and better risk decisions.
The ideal candidate is comfortable:
- writing code and independently building automation, integrations, and technical solutions,
- identifying manual processes and redesigning them through an automation-first approach,
- leveraging AI and agentic workflows to solve security and operational problems,
- leading day-to-day TPRM operations and managing escalations,
- managing MSP delivery, quality, and performance,
- assessing third-party security risk and technical security controls,
- working directly with vendors to resolve complex security and risk issues,
- supporting third-party security incidents and assessing potential impact,
- managing and improving TPRM platforms, workflows, and data,
- and communicating technical risk to leadership and business stakeholders.
You'll be successful in this role if you can combine security risk expertise with hands-on technical execution-solving today's operational challenges while continuously engineering better ways for TPRM to operate at scale.
What You'll Do
- Build automation, tooling, agents, and integrations to solve TPRM problems, eliminate repetitive manual work, improve decision quality, and enable the program to scale
- Write code and prototype solutions directly, using APIs, security and risk data, AI-assisted development, and other technologies to rapidly solve operational and risk management challenges
- Identify recurring operational problems and determine where automation, AI, improved data, or redesigned workflows can replace manual processes
- Lead day-to-day TPRM operations, including third-party security assessments, risk decisions, stakeholder and vendor escalations, and delivery against established service levels
- Oversee TPRM managed service provider delivery and performance, including workload, quality, capacity, SLAs, issue resolution, and continuous improvement
- Manage complex third-party security issues and work directly with vendors and internal stakeholders to evaluate risk, challenge responses, resolve gaps, and drive appropriate remediation or risk treatment
- Support third-party security incidents by assessing Uber's potential exposure, coordinating with relevant Engineering Security teams and vendors, and helping drive appropriate risk response
- Manage and continuously improve TPRM platforms, workflows, integrations, data quality, and reporting, and partner with engineering teams on larger program transformation capabilities
- Help evolve TPRM toward more continuous and intelligence-driven risk management by integrating security signals, automating assessments and monitoring, and identifying opportunities for program-wide transformation
Basic Qualifications
- 5+ years of experience in security engineering, third-party risk management, cloud security, infrastructure security, security assurance, security risk, or related technical security roles
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience
- Hands-on experience writing code and building automation using languages such as Python, Go, Bash, or similar, with the ability to translate manual or operational problems into scalable technical solutions
- Experience building integrations and working with APIs, security tooling, automation platforms, and AI-assisted development workflows
- Experience managing or supporting day-to-day third-party risk management or security assurance operations, including complex security and stakeholder escalations
- Experience overseeing managed service providers, external delivery teams, or similar operational delivery models
- Experience applying risk management principles, assessing technical security controls, and evaluating security evidence across modern cloud, SaaS, and enterprise environments
- Understanding of:
Want more jobs like this?
Get Software Engineering jobs in Seattle, WA delivered to your inbox every week.

- cloud infrastructure and security
- identity and access management
- endpoint security
- vulnerability management
- logging and telemetry systems
- enterprise SaaS platforms
- networking fundamentals
Preferred Qualifications
- Strong experience in Third-Party Risk Management, vendor security, or security assurance
- Experience leading or managing TPRM operations at scale
- Experience managing MSP performance, including quality, capacity, SLAs, and operational metrics
- Experience supporting third-party security incidents and evaluating organizational exposure to vendor incidents or vulnerabilities
- Experience administering, configuring, or helping manage TPRM, GRC, or security workflow platforms
- Experience building internal security tooling, agents, workflow automation, or operational automation platforms
- Experience designing integrations across security systems and data sources using APIs and automated workflows
- Experience using LLMs or AI tooling to build or significantly improve security analysis, assessment, or TPRM workflows
- Strong investigative, problem-solving, written communication, and program management skills
- Demonstrated ability to identify opportunities for process improvement and translate them into practical technical solutions
- Ability to balance hands-on technical execution, day-to-day operations, and longer-term program transformation
For San Francisco, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.
For Seattle, WA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.
For Sunnyvale, CA-based roles: The base salary range for this role is USD $180,000 per year - USD $200,000 per year.
For all US locations, you will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Ready to Ride?
This isn't the kind of place where you follow a playbook - it's where you help write one. If you're driven by impact, energized by challenge, and ready to shape how the world moves - we'd love to hear from you.
You may be eligible for bonuses, equity, and other compensation, as well as a range of benefits. Explore our benefits.
Offices remain key to collaboration and Uber's culture. Unless approved for full remote work, employees must spend at least 50% of their time in-office. Some roles, like those at greenlight hubs, require full-time in-office presence. Ask your Recruiter for details about this role's requirements.
Uber is proud to be an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires accommodation, please let us know by completing this form.
Perks and Benefits
Health and Wellness
- Health Insurance
- Health Reimbursement Account
- Dental Insurance
- Vision Insurance
- Life Insurance
- FSA With Employer Contribution
- Fitness Subsidies
- On-Site Gym
- Mental Health Benefits
Parental Benefits
- Fertility Benefits
Work Flexibility
- Flexible Work Hours
- Remote Work Opportunities
- Hybrid Work Opportunities
Office Life and Perks
- Casual Dress
- Pet-friendly Office
- Snacks
- Some Meals Provided
- On-Site Cafeteria
Vacation and Time Off
- Paid Vacation
- Unlimited Paid Time Off
- Paid Holidays
- Personal/Sick Days
- Sabbatical
- Volunteer Time Off
Financial and Retirement
- 401(K)
- Company Equity
- Performance Bonus
Professional Development
- Work Visa Sponsorship
- Associate or Rotational Training Program
- Promote From Within
- Mentor Program
- Access to Online Courses
Diversity and Inclusion
- Employee Resource Groups (ERG)
- Diversity, Equity, and Inclusion Program