We are building a governance, risk, and compliance function to enable our company to build
products that can withstand regulatory scrutiny, and ensure Meta continues to meet global
regulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting.
We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receive
ad-hoc coverage through security risk assessments designed for infrastructure — not for
product-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity,
and Legal. You will design that capability from the ground up and scale it from roughly five
assessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AI
product velocity.
This is a builder and an influencer role in equal measure. AI launch risk cannot be
assessed by one function acting alone — it requires Central Security, product groups, Privacy,
Integrity, and Legal moving through a shared process on a launch timeline. You will own that
operating model: translating product and engineering reality into a defensible risk position, and
translating regulatory obligation into assessment work that product teams can actually absorb
without stalling a launch. The ideal candidate is comfortable with ambiguity, effective in
high-pressure and fast-moving situations, and able to build durable relationships across a wide
range of technical and non-technical stakeholders.
Design and implement Meta's AI Launch Risk Assessment framework end to end — intake criteria, cross-domain risk taxonomy, assessment methodology, and launch-gate outputs — and scale delivery from ~5 to 20+ assessments per quarter by H1 2027.
8+ years of experience in governance, risk, and compliance, security risk management,

Meta's mission is to build the future of human connection and the technology that makes it possible.
Our technologies help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology.
To help create a safe and respectful online space, we encourage constructive conversations on this page. Please note the following:
• Start with an open mind. Whether you agree or disagree, engage with empathy.
• Comments violating our Community Standards will be removed or hidden. Please treat everybody with respect.
• Keep it constructive. Use your interactions here to learn about and grow your understanding of others.
• Our moderators are here to uphold these guidelines for the benefit of everyone, every day.
• If you are seeking support for issues related to your Facebook account, please reference our Help Center (https://www.facebook.com/help) or Help Community (https://www.facebook.com/help/community).
For a full listing of our jobs, visit https://www.metacareers.com