Senior Security Incident Commander

Uber Uber · Consumer · Seattle, WA +2 · Engineering

This role leads critical security incidents, acting as an incident commander and technical investigator. It involves making high-stakes decisions under pressure, conducting deep technical analysis, and driving systemic remediation. The role also focuses on maturing the incident response program through simulations, threat-informed planning, and adopting new investigative techniques, including AI-assisted workflows and AI-driven tooling.

What you'd actually do

  1. Command the highest severity and most complex security incidents across Uber and its subsidiaries, serving as the single accountable leader during active response.
  2. Participate in an on-call rotation where you are expected to make real-time decisions with incomplete information, balancing speed, risk, and impact.
  3. Act as the incident authority, not just a facilitator - forming hypotheses, setting strategy, and directing investigative focus.
  4. Transition seamlessly between executive-level incident leadership and hands-on technical investigation, including log analysis, system interrogation, and root cause validation.
  5. Serve as the primary interface to senior leadership during critical incidents, translating evolving technical realities into clear risk, impact, and decision frameworks.

Skills

Required

  • Security operations, detection, or incident response at scale
  • Technical investigation skills
  • Executive briefing during incidents
  • Incident simulation design/execution
  • Building or leveraging AI-driven tooling for incident response

Nice to have

  • Leading responders
  • Technical mentorship
  • Bias for action and continuous improvement
  • Experience in distributed, cloud-scale environments
  • Broad security domain knowledge
  • Scripting or coding (Python, Go, or similar)

What the JD emphasized

  • ownership of ambiguous, large, complex, high-impact incidents
  • Deep familiarity with modern attacker TTPs
  • Strong technical investigation skills
  • Experience briefing executives during active incidents
  • Experience designing or running technical incident simulations
  • Experience building or leveraging AI-driven tooling to improve incident response posture, applying frontier technology to workflows such as triage, investigation, correlation, or decision support.