Back to all jobs

Security Program Manager, Exam and Audit

Meta

LondonOn-siteFull Time10+ years
Posted 8 hours ago

Meta is seeking a Staff Security Program Manager to lead compliance strategy and assessment programs focused on security examination and audit readiness. In this role, you will drive the design, execution, and continuous improvement of Meta's security compliance programs, including regulatory examinations, third-party audits, and internal control assessments across Meta's platforms and infrastructure. You will serve as a strategic authority on security compliance frameworks, translating complex regulatory requirements into scalable program structures that protect Meta's products and users at a global scale.

Responsibilities

  • Define and own the long-term strategy for Meta's security examination and audit compliance programs, including scope, methodology, and governance frameworks
  • Lead cross-functional coordination across security engineering, legal, privacy, and policy teams to prepare for and respond to regulatory examinations and third-party security audits
  • Drive audit readiness programs by identifying control gaps, assessing risk exposure, and partnering with technical teams to implement remediation plans
  • Establish metrics, reporting cadences, and executive-level communications to convey audit status, findings, and program health to senior leadership
  • Serve as the primary point of contact for external auditors and regulatory examiners, managing evidence collection, inquiry responses, and audit lifecycle coordination
  • Identify systemic compliance risks across Meta's security posture and develop scalable program interventions to address them proactively
  • Influence the design of security controls and engineering processes to embed compliance requirements into product and infrastructure development lifecycles
  • Build and refine program management tooling, workflows, and documentation standards to improve audit efficiency and repeatability across the organization
  • Mentor other program managers and compliance professionals, establishing best practices and elevating the overall maturity of the security compliance function

Minimum Qualifications

  • 8+ years of experience in security compliance, audit management, or regulatory examination programs within a technology or enterprise environment
  • Experience leading end-to-end security audit or examination programs, including evidence management, control testing, and findings remediation at organizational scale
  • Experience applying security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, FedRAMP, or equivalent regulatory standards to large-scale technical environments
  • Experience communicating complex compliance and security risk topics in writing to technical teams and non-technical executive stakeholders
  • Experience driving cross-functional alignment across security, legal, engineering, and policy organizations on compliance program strategy and execution

Preferred Qualifications

  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  • Familiarity with security control automation, continuous compliance monitoring tools, or GRC platforms used to scale audit evidence collection
  • Experience building or maturing a security compliance function from early-stage program design through full operational deployment
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Professional certifications such as CISA, CISSP, CISM, or equivalent security and audit credentials
  • Experience managing security compliance programs in a global technology company subject to multiple concurrent regulatory frameworks and jurisdictions