Sr. Security Investigator

Uber Uber · Consumer · Seattle, WA +2 · Engineering

This role is for a Senior Security Investigator focused on leading complex security investigations, performing deep forensic analysis, and building automation for incident response within Uber's global environment. The role involves partnering with various security and cross-functional teams, mentoring junior investigators, and evolving investigation methodologies. While experience with GenAI in incident response is a plus, the core of the role is not AI/ML development.

What you'd actually do

  1. Lead complex security investigations end-to-end and perform deep forensic analysis across endpoints, cloud environments, identity systems, networks, and application logs to uncover root cause and attack paths.
  2. Own & Build automation and tooling to accelerate evidence collection, log enrichment, triage workflows, and decision-making at global scale.
  3. Improve detection and response capabilities by partnering with Threat Intelligence, Detection Engineering, and Platform teams.
  4. Lead major cross-functional security initiatives that strengthen investigative readiness, digital forensics, cloud incident response, and threat-hunting capabilities.
  5. Mentor and develop investigators and analysts, providing technical guidance, reviewing casework, and elevating investigative rigor.

Skills

Required

  • Security Investigations
  • Incident Response
  • Threat Hunting
  • Digital Forensics
  • forensic tooling
  • log analysis
  • SIEM platforms
  • EDR solutions
  • cloud investigation workflows (AWS/GCP/Azure)
  • attacker TTPs
  • modern threat landscape
  • MITRE ATT&CK
  • Python
  • APIs
  • SOAR
  • leading complex investigations
  • communication to senior leadership
  • large cross-company security projects

Nice to have

  • identity ecosystems (Okta, Azure AD)
  • container security
  • SaaS platform logs
  • programming language (e.g., Python, Go, C++, Java, etc) for incident response related automation and data analysis
  • GenAI in incident response and investigations
  • mentoring or leading security teams

What the JD emphasized

  • Lead complex security investigations
  • perform deep forensic analysis
  • Own & Build automation and tooling
  • Improve detection and response capabilities
  • Lead major cross-functional security initiatives
  • Mentor and develop investigators