Meta's Security Risk Program (SRP) is the second-line function accountable for how Meta
identifies, assesses, quantifies, and reports its security risk posture — to executive
leadership, the Board, external auditors, and global regulators. The program delivers Global
Security Risk Assessments (regulatory and commercial), Capability Maturity & Effectiveness
(CME) evaluations, AI risk assessments, cloud security risk governance and assessment, unified risk intelligence and quantification, and board and regulatory reporting.
We are looking for a Director of Security Risk Program to lead this portfolio through a period
of significant expansion. The role owns four program pillars and 38+ resources (FTE and contingent workforce), and is accountable for several strategic mandates: standing up Meta's security risk assessment capability for AI and product launches, evolving Meta’s cloud security risk capability, and building a comprehensive security risk intelligence picture across all three lines of defense, to support leadership decision-making and resource prioritization.
Success in this role is defined as much by influence as by ownership. The Director sits at the
intersection of Central Security leadership, Risk Org PM and Eng, Legal Partners, and Meta's product organizations — translating engineering and product reality into a defensible risk position. This is a role for a risk leader who is equally credible in front of a regulator, a Board committee, and an engineering leader whose roadmap they are trying to shape.
The ideal candidate is a proven risk leader, with a background in Security, and an effective cross-organization collaborator and communicator who can distill complex regulatory positions for both technical and executive audiences. They have experience navigating ambiguity, defining structure in evolving problem spaces, and delivering results in rapidly changing product areas; they are skilled at leading a team, developing and driving high-level strategy, and — equally — personally executing on critical workstreams, including program planning and stakeholder coordination. They can sift through complex information, distill key insights, and elevate critical data to drive informed decisions at every level, from the working team to senior leadership.
Own the strategy, operating model, and end-to-end delivery of Meta's Security Risk Program across four programmatic pillars — Risk Assessments, Capability Maturity & Effectiveness, Risk Intelligence, and Cloud Security Risk — and lead, develop, and grow the multidisciplinary team and contingent workforce that delivers it.
15+ years of experience in security risk management, technology risk, GRC, or a directly

Meta's mission is to build the future of human connection and the technology that makes it possible.
Our technologies help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology.
To help create a safe and respectful online space, we encourage constructive conversations on this page. Please note the following:
• Start with an open mind. Whether you agree or disagree, engage with empathy.
• Comments violating our Community Standards will be removed or hidden. Please treat everybody with respect.
• Keep it constructive. Use your interactions here to learn about and grow your understanding of others.
• Our moderators are here to uphold these guidelines for the benefit of everyone, every day.
• If you are seeking support for issues related to your Facebook account, please reference our Help Center (https://www.facebook.com/help) or Help Community (https://www.facebook.com/help/community).
For a full listing of our jobs, visit https://www.metacareers.com