The security engineer will conduct in-depth security assessments, threat modeling, and vulnerability research to identify and mitigate security gaps across Meta's infrastructure. They will also develop security tooling and automation while mentoring engineering teams on secure coding practices and incident response.
Meta's Security Engineering team is looking for a security engineer to help protect the billions of people who use Meta's products and services. In this role, you will identify security vulnerabilities, drive mitigations across complex systems, and build scalable solutions that raise the security bar across Meta's infrastructure and product ecosystem. You will partner closely with engineering and product teams to embed security into the development lifecycle, turning one-off findings into systemic improvements that reduce risk at scale.
Responsibilities
Conduct in-depth security assessments, threat modeling, and vulnerability research across Meta's products, services, and infrastructure
Identify security gaps in system designs and implementations, and drive cross-functional mitigations to resolution
Develop and improve security tooling, automation, and frameworks — including static and dynamic analysis — to enable scalable security coverage across engineering teams
Translate complex security findings into actionable guidance for engineering and product partners, influencing design and implementation decisions
Lead large-complexity security projects with ambiguous requirements, defining the approach and driving outcomes from discovery through remediation
Serve as a domain expert for the team, representing security positions in cross-functional collaborations and roadmap discussions
Handle security incident response and on-call duties independently, coordinating with cross-functional partners to resolve issues
Mentor other engineers on secure coding practices, vulnerability classes, and security review methodologies
Identify opportunities to convert point-in-time security fixes into reusable, systemic improvements that benefit multiple teams and product areas
Proactively communicate project status, risks, and blockers to leadership and cross-functional stakeholders
Minimum Qualifications
6+ years of experience in security engineering, including vulnerability research, penetration testing, or security assessments of production systems
Experience identifying and exploiting common vulnerability classes (e.g., injection, authentication flaws, insecure deserialization, privilege escalation) across web, mobile, or infrastructure environments
Experience developing security tooling or automation in one or more general-purpose programming or scripting languages
Experience conducting threat modeling and security design reviews for large-scale distributed systems
Experience driving security mitigations across cross-functional engineering teams, including communicating risk and influencing technical decisions through written proposals and stakeholder alignment
Preferred Qualifications
Experience with security assessment of mobile platforms (iOS or Android) or cloud infrastructure environments
Experience building static or dynamic analysis tools that scale security review processes across large engineering organizations
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Demonstrated contributions to the security community through public research, vulnerability disclosures, bug bounty programs, or conference presentations
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Familiarity with exploit mitigation techniques and experience evaluating their effectiveness in production environments
$154,000/year to $217,000/year + bonus + equity + benefits
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”