Sr. Technical Program Manager — Engineering Security & AI Governance

Uber Uber · Consumer · Sao Paulo, Brazil · Engineering

This role is for a Sr. Technical Program Manager within Uber's Engineering Security organization, focusing on AI governance and AI agent oversight. The TPM will drive cross-functional reviews of security standards, support AI agent inventory and governance, coordinate AI red teaming activities, and manage security and privacy review programs. The role involves using and improving internal AI tooling for tasks like triage, assignment, and reporting, and ensuring AI agents are accurate and calibrated. It also includes managing a security champions network and performing cross-program analysis to drive improvements. The TPM will partner with senior leaders to shape AI governance across the engineering organization.

What you'd actually do

  1. Drive cross-functional review of new and updated security standards, gathering input from senior engineers, AI/ML stakeholders, IAM, AppSec, OffSec, legal, and Product Security.
  2. Support the operating cadence for AI agent inventory and governance, ensuring agents move through review, approval, and ongoing oversight in line with internal standards and external regulatory expectations.
  3. Coordinate intake and follow-through for AI red teaming and threat modeling activities, ensuring findings are routed to the right remediation owners and reflected back into review criteria.
  4. Run the day-to-day of the engineering security and privacy review program: intake, routing, capacity planning, SLA tracking, and escalation.
  5. Use existing internal AI tooling to scale your own throughput and the program's.

Skills

Required

  • 4+ years as a TPM, Program Manager, or equivalent in a software or technology environment.
  • Strong analytical skills: you see patterns in data and operational signals that others miss, and turn those observations into action.
  • Excellent written and verbal English.
  • Strong follow-through. You drive things to completion across multiple stakeholders without needing to be reminded of status.
  • JIRA proficiency: JQL, dashboards, automation rules, sprint management.
  • Daily use of AI tools (Claude, ChatGPT, etc.) as productivity accelerators or demonstrated ability to ramp up within four weeks.
  • Self-directed across time zones; comfortable making decisions with incomplete information.
  • Skilled at driving alignment across teams without formal authority.

Nice to have

  • Experience supporting security, privacy, compliance, risk, or audit programs.
  • Familiarity with security review, privacy review, threat modeling, or risk assessment workflows.
  • Experience with AI governance, responsible AI, LLM applications, AI agents, or AI security programs.
  • Experience improving workflow automations using AI tools, scripts, JIRA automation, APIs, or low-code tooling.
  • Experience running training, certification, champion, or distributed reviewer programs.
  • Comfort with CLI tools and lightweight scripting.
  • Familiarity with regulatory or audit-sensitive environments where documentation quality and evidence readiness matter.

What the JD emphasized

  • AI agent governance
  • AI red teaming
  • AI governance
  • AI security
  • AI agent oversight
  • AI standards
  • AI-assisted execution
  • AI tooling
  • AI-native environment
  • AI workflows
  • AI is built and used
  • AI security and privacy reviews
  • AI red teaming
  • AI agent governance
  • AI red teaming
  • AI-assisted triage
  • AI tooling
  • AI tooling
  • AI tooling

Other signals

  • AI governance
  • AI agent oversight
  • AI red teaming
  • AI standards
  • AI-assisted execution
  • AI tooling