Those at Uber, there seems to be a trend (via various posts) of negativity towards engsec.
Can anyone share in more tangible details what folks might be referring to? Culture? Low quality results? Poor partners? Engineering maturity?
What do you think are some of the root causes? Have you noticed a positive trajectory of improvement recently?
Are you a customer of the team or a part of it?
comments
Generally, the culture has improved. Recent hires have been great and I enjoy working with them.
However most eye opening part of this thread is the experience of the person from Coupang. I am not surprised- it is how they operate. Very desperate to hire because the image of Engsec preceded it. Feel free to message.
- Promos given to people who threaten to leave/have competing offers. Nowhere close to a meritocracy as others have said.
- Everyone who the ciso brought from fb has left. That was after he downleveled a bunch of them.
- Shitshow that was goldstar - so badly done, ciso had to tell all of eng not to use it. People actually got promoted, not fired, off that project. No wonder eng wanted (and got) their own infra security team and told engsec to f*** off.
- Started/Named a bunch of random teams to sound "innovative". "Guidance" and "Access Insights" and "Vulnerability Discovery" and bleh.