-
View all jobs
About The Role
The CyberSecurity Incident Response team (CIRT) is at the forefront of protecting Uber, our customers, and our partners from evolving security threats. We are a hands-on, fast-paced team that responds to security incidents, conducts forensic investigations, and builds automated solutions to scale our defenses.
Responsibilities
As a Security Analyst on the CIRT team, you will be a key player in our incident response efforts. This is a technical and investigative role where you'll be responsible for:
What The Candidate Will Need / Bonus Points
---- What the Candidate Will Do ----
Incident Response: Act as a first responder to security alerts, triaging and containing threats across the Uber platform.
Forensic Analysis: Investigate security incidents by analyzing logs, network traffic, and host data to determine the root cause, scope, and impact.
Automation: Develop and deploy scripts and playbooks to automate incident response workflows and improve team efficiency.
Threat Hunting: Proactively search for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
Collaboration: Partner with other teams to share threat intelligence, recommend security improvements, and communicate incident findings.
Basic Qualifications
The CyberSecurity Incident Response team (CIRT) is at the forefront of protecting Uber, our customers, and our partners from evolving security threats. We are a hands-on, fast-paced team that responds to security incidents, conducts forensic investigations, and builds automated solutions to scale our defenses.
Responsibilities
As a Security Analyst on the CIRT team, you will be a key player in our incident response efforts. This is a technical and investigative role where you'll be responsible for:
- Responding to security incidents and mitigating threats across the company. Partner closely with the SOC analysts and incident commanders, leading incident investigations.
- Conducting in-depth investigations and digital forensics to uncover the root cause of attacks.
- Developing and implementing automation solutions using tools like SIEM and SOAR to improve our response capabilities.
- Collaborating with other security and engineering teams to address vulnerabilities and strengthen our security posture.
- Communicating your findings clearly and concisely to help shape our long-term security strategy.
What The Candidate Will Need / Bonus Points
---- What the Candidate Will Do ----
Incident Response: Act as a first responder to security alerts, triaging and containing threats across the Uber platform.
Forensic Analysis: Investigate security incidents by analyzing logs, network traffic, and host data to determine the root cause, scope, and impact.
Automation: Develop and deploy scripts and playbooks to automate incident response workflows and improve team efficiency.
Threat Hunting: Proactively search for emerging threats and vulnerabilities using threat intelligence to mitigate risks before they can be exploited.
Collaboration: Partner with other teams to share threat intelligence, recommend security improvements, and communicate incident findings.
Basic Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field..
- 2+ years of professional experience in a security-focused role, such as Incident Response, Security Operations, or Digital Forensics.
- Proven experience with incident response and handling in a professional environment.
- Familiarity with common security tools and technologies (e.g., SIEM, EDR, network monitoring).
- Experience with SOAR platforms (e.g., Splunk Phantom, Cortex XSOAR etc) and developing automated playbooks.
- Strong problem-solving skills and the ability to work effectively under pressure.
- Excellent written and verbal communication skills.
- 3+ years of professional experience in a security-focused role, such as Incident Response, Security Operations, or Digital Forensics.
- Experience in a large-scale, enterprise environment, particularly within the technology sectors.
- Hands-on experience across multiple domains such as network, hosts, applications, data, cloud security etc.
- Experience in a programming language (e.g., Python, Go, C++, Java, etc) for incident response related automation and data analysis.
- Experience with using GenAI in incident response and investigations is a plus.
Key Skills
Ranked by relevance
incident response
siem
digital forensics
cloud security
cybersecurity
data analysis
python
splunk
cloud
java
c
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Senior Security Engineer (IT)
2026-05-29
Full-time
Not Applicable
Ireland
Internet Marketplace Platforms
Information Technology
View Job Details
Related
Director of IT & Security
2026-05-26
Contract
Not Applicable
Canada
Internet Marketplace Platforms
Information Technology
View Job Details
Related
Director – Technology Development
2026-05-27
Full-time
Not Applicable
United States
Internet Marketplace Platforms
Engineering
Login to Apply
- Posted
- Nov 13, 2025
- Type
- Full-time
- Level
- Mid-Senior
- Location
- Seattle
- Company
- Uber
Industries
Internet Marketplace Platforms
Categories
Information Technology
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Senior Security Engineer (IT)
2026-05-29
Full-time
Not Applicable
Ireland
Internet Marketplace Platforms
Information Technology
View Job Details
Related
Director of IT & Security
2026-05-26
Contract
Not Applicable
Canada
Internet Marketplace Platforms
Information Technology
View Job Details
Related
Director – Technology Development
2026-05-27
Full-time
Not Applicable
United States
Internet Marketplace Platforms
Engineering