Program Manager, Security Risk Program
Listed on 2026-09-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
We are building a governance, risk, and compliance function to enable our company to build products that can withstand regulatory scrutiny, and ensure Meta continues to meet global regulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting.
We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receivead-hoc coverage through security risk assessments designed for infrastructure — not for product-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity,and Legal. You will design that capability from the ground up and scale it from roughly five assessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AIproduct velocity.
This is a builder and an influencer role in equal measure. AI launch risk cannot be assessed by one function acting alone — it requires Central Security, product groups, Privacy,Integrity, and Legal moving through a shared process on a launch timeline. You will own that operating model: translating product and engineering reality into a defensible risk position, and translating regulatory obligation into assessment work that product teams can actually absorb without stalling a launch.
The ideal candidate is comfortable with ambiguity, effective inhigh-pressure and fast-moving situations, and able to build durable relationships across a widerange of technical and non-technical stakeholders.
- Design and implement Meta's AI Launch Risk Assessment framework end to end — intake criteria, cross-domain risk taxonomy, assessment methodology, and launch-gate outputs — and scale delivery from ~5 to 20+ assessments per quarter by H1 2027.
- Build and partner to manage the XFN operating model that coordinates Central Security, product groups, Privacy Risk Management, Integrity Risk Management, and Legal through each assessment, with clear roles, handoffs, and decision rights on a launch timeline.
- Partner directly with product and engineering teams on high-priority AI launches — engaging early enough that security risk review informs design decisions rather than gating release, and giving product teams a predictable, well-documented path through second-line review.
- Serve as the connection point between the Security Risk Program, Central Security leadership, Legal, and first-line business teams, representing security risk positions and negotiating assessment scope, sequencing, and remediation commitments.
- Build and maintain a consolidated AI risk register that gives leadership a single view of.
- security risk across the AI product portfolio, and produce the reporting that keeps that view current for VP and executive audiences.
- Define tooling requirements and drive AI-enabled automation across the assessment lifecycle — identifying where automation can scale throughput without compromising assessment defensibility, and partnering with tooling and engineering owners to deliver it.
- Ensure assessments and supporting artifacts are produced to internal standards, are.
- submission-ready, and constitute defensible evidence of systematic security due diligence for regulators and auditors (including…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).