Non-Human Identity Governance
— Build the tooling and detection logic that governs the sprawling web of permissions between personnel, workloads, agents, service accounts, and infrastructure. Develop inventory and risk-identification pipelines that surface dangerous patterns — runaway group membership, over-privileged service accounts — before they become incidents. Contribute to eliminating personnel misuse of non-human identities by migrating credentials to secretless patterns and onboarding privileged access management (PAM) enforcement.
Security Knowledge Graph
— Help build a single, queryable knowledge graph of identity, assets, ownership, and access controls that is becoming foundational to Uber’s security infrastructure strategy. Design and ship the ingestion framework, CI/CD pipeline, and self-service tooling (schema browsing, query benchmarking, scaffolding) that let any security or infra team onboard their own data sources without bespoke integration work. Build toward near-real-time ingestion for high-value signals like access and group-membership changes, and extend the graph to support both human consumers (dashboards, investigation tools) and AI agents querying it directly.
uSSO / Agentic R&D
— Help evolve uSSO into an identity platform that works natively for both humans and autonomous agents, strengthening authentication as more of Uber’s workload shifts to agentic systems acting on behalf of people and services. This means building the underlying platform to be robust and agent-compatible, and defining how Uber issues, verifies, and scopes identity for agents — establishing clear on-behalf-of relationships and policy standards for how agents can safely access production systems and SaaS.
Diagnose and resolve complex distributed-systems problems across these platforms under continuous, high-volume, security-critical traffic — with a focus on correctness, latency, and operational resilience.