Staff Security Strategist Grc

Uber Uber · Consumer · San Francisco, CA +1 · Engineering

This role focuses on cyber risk management, governance, and control design within Uber's Engineering Security team. The Senior Security Strategist, GRC will partner with engineering and risk stakeholders to strengthen the company's cybersecurity posture, primarily using the ServiceNow eGRC platform. Responsibilities include managing cyber risk intake, developing product strategy for risk and compliance technology, driving risk treatment plans with engineering teams, leading control design reviews, and building risk reporting. The role also involves improving risk workflows through automation and serving as a liaison between various security, engineering, audit, privacy, and compliance teams. While the role mentions leveraging AI for improvement, its core function is GRC and risk management, not direct AI/ML development.

What you'd actually do

  1. Own cyber risk intake, triage, and prioritization, ensuring clear accountability, well-formed risk statements, and timely treatment decisions.
  2. Develop product strategy and lead project execution for multiple major components of Uber's Risk and Compliance technology solutions.
  3. Manage different solutions on Uber's internal eGRC platform (ServiceNow) and collaborate with stakeholders to implement their program improvements.
  4. Partner with engineering teams to define risk treatment plans, identify sustainable fixes, and drive mitigation or remediation to the last mile rather than stopping at documentation.
  5. Gather business and functional requirements from partner teams and deliver a product/release that meets the needs presented. Develop technical specifications documentation.

Skills

Required

  • Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Systems, Cybersecurity, Risk Management, or related field, or equivalent practical experience.
  • 10+ years of experience in security, cyber risk, GRC, assurance, security operations, or related technical risk roles.
  • Security certifications e.g. CISA, CISSP, CISM, or other relevant certifications.
  • Demonstrated success managing security risk programs, treatment decisions, and cross-functional execution end to end.
  • Strong understanding of security controls, risk treatment, and how to work with engineering on implementation details.
  • Experience operating across multiple stakeholders, handling ambiguity, and driving accountability.
  • Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision.
  • Excellent written and verbal communication skills, including the ability to present risk, status, and decision points to leadership and technical audiences.

Nice to have

  • CRISC, ISO 27001 Lead Auditor, or comparable additional certifications.
  • Hands-on experience with ServiceNow eGRC platform, including configuration, workflow development, and integration.
  • Experience with other GRC/ERM tooling such as AuditBoard, Archer, OpenPages, or SAP GRC.
  • Big 4 accounting firm and/or internet/technology industry experience.
  • Process management experience, including process redesign and optimization.
  • Proven track record in driving security risk treatment to closure across multiple engineering teams.
  • Ability to leverage AI, data analytics, and workflow automation to improve risk program performance and reporting.
  • Experience with risk quantification methodologies and risk lifecycle tooling.
  • Strong knowledge of control frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, NIST RMF, SOC 2, and CIS.
  • Proficiency in Python, SQL, dashboards, or similar tools for data analysis

What the JD emphasized

  • security, compliance, and risk management programs
  • technical solutions that satisfy a variety of risk and compliance processes
  • practical risk treatment plans that engineering teams can execute
  • drive mitigation or remediation to the last mile rather than stopping at documentation
  • control design reviews, risk assessments, and risk decisions
  • drive and evangelize vision for overall GRC strategy
  • improve system capabilities, automate process workflows
  • implement workflows from customer requirements
  • risk reporting
  • Improve the efficiency of risk workflows through automation
  • Serve as a bridge between cybersecurity, engineering, audit, privacy, and compliance stakeholders
  • security certifications e.g. CISA, CISSP, CISM, or other relevant certifications
  • Demonstrated success managing security risk programs, treatment decisions, and cross-functional execution end to end.
  • Strong understanding of security controls, risk treatment, and how to work with engineering on implementation details.
  • Experience operating across multiple stakeholders, handling ambiguity, and driving accountability.
  • Ability to effectively and autonomously accomplish outcomes across cross-functional teams in ambiguous situations with minimal supervision.
  • Excellent written and verbal communication skills, including the ability to present risk, status, and decision points to leadership and technical audiences.