Security Program Manager, Exam and Audit
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Meta's Regulatory Compliance Program sits at the intersection of global security regulation, product integrity, and enterprise risk management. The Exam and Audit team is responsible for establishing, maturing, and managing Meta's security compliance posture across external regulatory examinations, third-party audits, and internal assurance activities. As a Staff-level Security Program Manager on this team, you will serve as a strategic leader and subject-matter expert, driving the design and execution of audit-readiness programs, overseeing second-line-of-defense compliance functions, and partnering with security engineering, legal, and policy teams to ensure Meta's security practices meet the expectations of regulators and auditors worldwide.
- 8+ years of experience in security compliance, governance, risk and compliance (GRC), or regulatory program management within the technology, financial services, or healthcare industry
- Experience leading or managing external security audits, regulatory examinations, or third-party assessments, including evidence coordination, findings response, and remediation oversight
- Experience applying security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, FedRAMP, or equivalent regulatory standards in an enterprise environment
- Experience communicating complex security and compliance concepts in writing to technical, legal, and executive stakeholders, including audit reports, control narratives, and regulatory correspondence
- Experience identifying and driving resolution of systemic compliance gaps across cross-functional security and engineering organizations
- Professional certification in security or audit disciplines such as CISSP, CISA, CISM, or equivalent
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience engaging directly with external regulators or audit bodies on behalf of a large-scale technology platform
- Experience designing or maturing second-line-of-defense oversight functions within a security or privacy compliance program
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Demonstrated ability to integrate AI-assisted tools to improve audit workflow efficiency, evidence analysis, or compliance monitoring at scale
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).