Security Engineer

Meta•Published 20 hours ago•First seen 11 hours ago

Description

Meta's Security Engineering team is looking for a security engineer to help protect the billions of people who use Meta's products and services. In this role, you will identify security vulnerabilities, drive mitigations across complex systems, and build scalable solutions that raise the security bar across Meta's infrastructure and product ecosystem. You will partner closely with engineering and product teams to embed security into the development lifecycle, turning one-off findings into systemic improvements that reduce risk at scale.

Responsibilities

Conduct in-depth security assessments, threat modeling, and vulnerability research across Meta's products, services, and infrastructure Identify security gaps in system designs and implementations, and drive cross-functional mitigations to resolution Develop and improve security tooling, automation, and frameworks — including static and dynamic analysis — to enable scalable security coverage across engineering teams Translate complex security findings into actionable guidance for engineering and product partners, influencing design and implementation decisions Lead large-complexity security projects with ambiguous requirements, defining the approach and driving outcomes from discovery through remediation Serve as a domain expert for the team, representing security positions in cross-functional collaborations and roadmap discussions Handle security incident response and on-call duties independently, coordinating with cross-functional partners to resolve issues Mentor other engineers on secure coding practices, vulnerability classes, and security review methodologies Identify opportunities to convert point-in-time security fixes into reusable, systemic improvements that benefit multiple teams and product areas Proactively communicate project status, risks, and blockers to leadership and cross-functional stakeholders

Qualifications

6+ years of experience in security engineering, including vulnerability research, penetration testing, or security assessments of production systems Experience identifying and exploiting common vulnerability classes (e.g., injection, authentication flaws, insecure deserialization, privilege escalation) across web, mobile, or infrastructure environments Experience developing security tooling or automation in one or more general-purpose programming or scripting languages Experience conducting threat modeling and security design reviews for large-scale distributed systems Experience driving security mitigations across cross-functional engineering teams, including communicating risk and influencing technical decisions through written proposals and stakeholder alignment Experience with security assessment of mobile platforms (iOS or Android) or cloud infrastructure environments Experience building static or dynamic analysis tools that scale security review processes across large engineering organizations Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements) Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements) Demonstrated contributions to the security community through public research, vulnerability disclosures, bug bounty programs, or conference presentations Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews) Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews) Familiarity with exploit mitigation techniques and experience evaluating their effectiveness in production environments

Compensation: $154,000/year to $217,000/year + bonus + equity + benefits