Sr Manager, Security Engineering - Engineer
- πΊπΈ United States
- On-site
- Manager or above
- 5 hours ago
- $267,000 β $297,000
- EDR
- AI
- ATT&CK
- Threat Intelligence
- Machine Learning
- SIEM
- AI/ML
- triage
- Incident Response
- Elastic
- Splunk
- Flink
- CrowdStrike
- Wiz
- Okta
- GCP
- OCI
- AWS
- ISO 27001
- SOC2
- Equity
- Pension
The security organization at Uber is dedicated to enabling safe and secure innovation while protecting the communities we serve both online and in the physical world. Our team is responsible for protecting both people and their data across intersections of the digital and physical world. The primary objective for Uber's Engineering Security team is to enable the technical ambitions of the company while maintaining the highest standards of security and privacy for our customers and partners. As cybersecurity threats evolve, so do we.
Detection Engineering sits at the center of that mission. We own the end-to-end path from raw security telemetry to a high-fidelity, actionable case in a responder's hands β the detection content, the platforms that run it, and the signal quality our incident responders depend on. We ingest and normalize telemetry from every control plane at Uber β endpoint (EDR), identity, network, cloud, and AI-agent activity β and turn it into detections that fire fast enough and clean enough to matter.
About the Role
Our mission is to protect, defend, and secure Uber's products, infrastructure, and data by building highly available, scalable, and extensible security solutions and services. We are focused on proactively identifying and remediating security risks as well as swiftly detecting and mitigating security incidents. In the ever-evolving landscape of cybersecurity, we continuously adapt and evolve our defenses in order to always stay one step ahead of potential threats.
We are seeking a talented and experienced Senior Manager to lead our Detection Engineering organization and own the strategy, roadmap, and execution for how Uber detects adversary activity at global scale. You will be accountable for detection coverage against a prioritized threat model, for the latency and fidelity of every signal we produce, and for the engineering platforms that make detection development a fast, testable, measurable discipline rather than an artisanal one.
This is a role for a leader who is as comfortable debating ATT&CK coverage gaps and false-positive economics with a staff detection engineer as they are setting a multi-half roadmap with Security Response, Threat Intelligence, Infrastructure, and Product partners. The security landscape is constantly evolving, and with the adoption of ML/GenAI backed by extensive heterogeneous data, both the threat surface and our detection toolkit are expanding rapidly. With your deep expertise across detection, response, and large-scale data systems, you will lead major efforts to design, implement, and scale industry-leading detection capabilities. You are not only a role model, but also an empathetic leader - a humble teacher who grows engineers and managers while delivering uniquely challenging projects.
What the Candidate Will Do
In this role you will define and execute the strategic roadmap for threat detection across Uber's corporate, production, and cloud environments. The scope includes:
Β
Detection strategy and coverage. Own a versioned, prioritized threat-scenario inventory (grounded in MITRE ATT&CK, intelligence-driven priorities, and newly emerging surfaces) and be accountable for provable detection coverage per scenario and environment, not anecdotal coverage claims.
Detection content and detection-as-code. Lead the teams that author, test, tune, and retire detection logic across SIEM rules, batch/warehouse detections, behavioral and anomaly models, correlation logic, and vendor-native signals. Establish lifecycle standards: every detection has an owner, a mapped use case, test coverage, a documented response path, and measured performance.
Detection platform and pipeline. Set direction for the ingestion, normalization, enrichment, and alerting infrastructure that detections run on - streaming and batch - including end-to-end observability of source freshness, completeness, mapping errors, and enrichment failures.
Latency and fidelity as hard goals. Drive measurable, time-bound improvements in time-to-detect for the highest-priority scenarios, and in signal-to-noise for the response queue. Recover responder capacity by eliminating low-value alerting without degrading true-positive rate.
AI/ML for cyber defense. Lead the responsible adoption of ML and LLM-based techniques for detection, triage, correlation, and case enrichment β moving them from research to production with fairness, safety, auditability, and compliance built into the engineering practice.
Partner with response. Operate in tight feedback loop with Security Response & Investigations, Threat Intelligence, and the SOC so detection quality is measured by investigative outcomes, not rule counts. Act as a senior escalation point during high-severity events and drive detection gaps surfaced in post-incident review back into the roadmap.
Cross-functional influence. Collaborate with Infrastructure, Corporate IT, Identity, Product Engineering, Legal, and Privacy to secure telemetry access, land instrumentation at the source, and integrate detection into systems and development lifecycles across Uber.
Build and lead the team. Manage a team of highly skilled security and software engineers β including senior/staff ICs and, over time, managers and tech leads β fostering a culture of technical excellence, operational rigor, continuous improvement, and strong customer focus. Set clear, ambitious goals to hire, develop, and retain a diverse and inclusive team, and deliver against them.
Vendor and build/buy strategy. Evaluate, select, and manage relationships with external security vendors and platforms; make and defend complex build-vs-buy and cost-vs-coverage tradeoffs with a clear view of short- and long-term implications.
Β
Bachelor's Degree or equivalent in Computer Science, Engineering, Information Security, or a related technical field.
5+ years of full-time work experience in software engineering or security engineeringprior to Engineering Management experience.
5+ years of full-time Engineering Management experience, including experience leading senior/staff engineers and growing other leaders (managers and/or tech leads).
Demonstrable domain expertise owning complex detection and response programs: threat detection, detection engineering, SIEM/security analytics, incident response, or security data platforms at enterprise or cloud scale.
Proven track record of setting multi-team technical strategy and delivering against it over multiple planning cycles, with measurable outcomes in coverage, time-to-detect, or alert quality.
Ability to make complex decisions with incomplete information in ambiguous situations and environments, and to hold accountability for those decisions.
Great interpersonal skills, deep technical ability, and a track record of successful execution in security engineering or software development at cloud scale.
Excellent written and verbal communication, with the ability to convey detection strategy, systemic risk, and tradeoffs to both executive leadership and senior engineers.
Β
Master's Degree or PhD in Computer Science, Engineering, Information Security, or a related field.
Hands-on background in detection engineering: authoring and tuning detection logic across log, network, endpoint, identity, and cloud telemetry, with a track record of improving coverage and signal fidelity while reducing false-positive burden on responders.
Experience operating a modern detection stack at scale β SIEM/security data lake (e.g., Elastic, Splunk), streaming pipelines (e.g., Kafka, Flink), warehouse-based batch detections, EDR (e.g., CrowdStrike, SentinelOne), CNAPP/CDR (e.g., Wiz), identity providers (e.g., Okta), and SOAR/case management (e.g., Torq).
Experience with public cloud security across multiple providers (GCP, OCI, AWS) and modern containerized/orchestrated environments.
Experience incorporating AI/ML and LLM-based techniques into production security systems, including evaluation methodology and precision/recall management.
Experience partnering with EMs, TPMs, and PMs on prioritization, headcount planning, and technical evaluation of team members.
Experience leading teams across multiple locations and working across multiple in-house engineering organizations.
Familiarity with relevant industry frameworks and compliance mandates (e.g., MITRE ATT&CK, NIST CSF, ISO 27001, SOC 2).
For Seattle, WA-based roles: The base salary range for this role is USD $267,000 per year - USD $297,000 per year.
You will be eligible to participate in Uber's bonus program, and may be offered an equity award & other types of comp. All full-time employees are eligible to participate in a 401(k) plan. You will also be eligible for various benefits.
Sr Manager, Security Engineering - Engineer Β· Uber