Responsibilities
- Own the strategy, operating model, and end-to-end delivery of Meta's Security Risk Program across four programmatic pillars β Risk Assessments, Capability Maturity & Effectiveness, Risk Intelligence, and Cloud Security Risk β and lead, develop, and grow the multidisciplinary team and contingent workforce that delivers it.
- Serve as the program's primary partner to Central Security leadership, driving a unified approach to security risk management (tooling, process, and methodology), including absorbing in-flight work from 1LOD into the second line: negotiating scope,.
- sequencing, and integration decisions, and establishing clear risk coverage ownership across the lines of defense.
- Embed security risk assessment into how product organizations build and ship β engaging early on predicate, AI, and cloud assessments so that risk review accelerates launches rather than gating them, and so product teams have a clear, predictable path through second-line review.
- Own accountability for Tier 1 regulated deliverables with fixed external deadlines, including Global Security Risk Assessments, EU RED and Data Protection assessments, commercial certifications (SOC 2, HIPAA, FDA, USG), the EU Cyber Resilience Act program, and EU AI Act model assessments.
- Represent Meta's security risk posture to executive leadership, Board committees, internal fora, regulators, and external auditors, and act as the escalation and risk-acceptance decision-maker for the program.
- Build and scale security risk assessment capability for AI, establishing methodology, tiering, and operations for predicate assessments, model assessments, and rapid assessments in close partnership with AI infrastructure, product, and Legal teams.
- Drive cross-domain unification with Privacy Risk Management, Integrity Risk Management, Legal, Compliance, and Internal Audit β owning the Unified Risk Quantification model and a common risk taxonomy so Meta presents one coherent risk picture rather than several competing ones.
- Own program financials and resourcing, and drive the strategy for automation and AI that scales assessment throughput without compromising defensibility.
Minimum Qualifications
- 15+ years of experience in security risk management, technology risk, GRC, or a directly
- related discipline
- 8+ years of experience managing and developing teams, including experience managing managers or senior individual contributors with demonstrated progression into organizational leadership
- Demonstrated experience attracting talent, developing leadership pipelines, managing org health through growth or change
- Demonstrated experience owning a security or technology risk program end-to-end across multiple organizations, including methodology, operations, and reporting
- Demonstrated experience partnering with and presenting to executive leadership to shape organizational strategy, influence technical roadmaps, drive XFN alignment
- Experience partnering directly with a Central Security or infrastructure security organizations and engineering leaders as a second-line risk function
- Experience delivering assessments or reporting against external regulatory or certification regimes (e.g., EU regulatory frameworks, SOC 2, HIPAA, FDA, US Government requirements)
- Demonstrated experience with risk assessment and capability maturity frameworks (e.g., NIST CSF, CMMI, ISO 27001, FAIR or comparable quantification approaches)
Preferred Qualifications
- Experience building a risk assessment capability for AI systems, including AI-specific
- regulatory regimes (EU AI Act) or emerging AI risk frameworks
- Experience integrating first-line and second-line risk responsibilities, or consolidating risk
- functions across domains
- Experience embedding risk review into a fast-moving product development lifecycle
- Experience with quantitative risk modeling and unified risk quantification at enterprise scale
- Experience with cloud security risk governance in a large multi-cloud environment
- Experience applying automation and AI tooling to scale GRC operations
- Experience managing program resourcing, budget, and vendor or contingent workforce delivery
- Familiarity with EU regulatory frameworks including GDPR/DPIA, RED, DORA, NIS2, or the Cyber Resilience Act
- Relevant certifications (CISSP, CRISC, CISM, CISA) or an advanced degree in a related field
$227,000/year to $287,000/year + bonus + equity + benefits
Learn more about this Employer on their Career Site
