Program Manager, Security Risk Program

Meta

Greater London

Hybrid

GBP 90,000 - 130,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Meta is building a governance, risk, and compliance function to enable product launches that withstand regulatory scrutiny. The Security Risk Program will focus on AI risk across Security, Privacy, Integrity, and Legal, from the ground up, and scale from roughly five assessments per quarter today to twenty or more per quarter by H1 2027.

This is a builder and influencer role requiring the ability to translate product realities into a defensible risk position and to drive a shared operating model

Qualifications

  • Experience in governance, risk, and compliance within a corporate setting.
  • Ability to design programs or processes from the ground up including operating model and rollout.
  • Excellent verbal and written communication with senior leadership.
  • Experience assessing risk for AI or ML systems or familiarity with AI regulatory frameworks.
  • Experience embedding risk reviews into product development lifecycles.
  • Knowledge of global regulatory frameworks and best practices.
  • Experience working with cross-functional partners without direct authority.

Responsibilities

  • Design and implement AI product launch risk assessments and governance.
  • Scale the risk assessment program from 5 to 20+ per quarter by H1 2027.
  • Coordinate with Central Security, product teams, Privacy, Integrity, and Legal to ensure a shared process.

Skills

Governance
Risk management
Regulatory compliance
Security risk management
Program management
Cross-functional alignment
Communication skills
AI risk frameworks
GRC automation
Regulatory frameworks
Audits

Education

Advanced degree
CISSP
CRISC
CISM
CISA

Job description

We are building a governance, risk, and compliance function to enable our company to build products that can withstand regulatory scrutiny, and ensure Meta continues to meet global regulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting.

We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receive ad-hoc coverage through security risk assessments designed for infrastructure — not for product-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity, and Legal. You will design that capability from the ground up and scale it from roughly five assessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AI product velocity.

This is a builder and an influencer role in equal measure. AI launch risk cannot be assessed by one function acting alone — it requires Central Security, product groups, Privacy, Integrity, and Legal moving through a shared process on a launch timeline. You will own that operating model: translating product and engineering reality into a defensible risk position, and translating regulatory obligation into assessment work that product teams can actually absorb without stalling a launch. The ideal candidate is comfortable with ambiguity, effective in high-pressure and fast-moving situations, and able to build durable relationships across a wide range of technical and non-technical stakeholders.

  • 6+ years of experience in governance, risk, and compliance, security risk management, regulatory compliance, or a directly related discipline
  • 2+ years of program management experience in a corporate environment
  • Experience with risk and compliance precepts, practices, and solutions
  • Demonstrated experience designing a program or process from the ground up — not solely running an established one — including methodology, operating model, and rollout
  • Demonstrated experience driving cross-functional alignment across technical and non-technical partners without direct authority, including with engineering or product organizations
  • Proven verbal and written communication skills, with success influencing a range of audiences including senior leadership
  • Experience assessing or managing risk for AI or machine learning systems, or familiarity with AI-specific regulatory and risk frameworks (EU AI Act, NIST AI RMF)
  • Experience embedding risk, security, or compliance review into a fast-moving product development lifecycle and launch process
  • Experience working in information security and/or cybersecurity
  • Experience partnering with a central security or infrastructure security organization as a second-line risk function
  • Experience defining tooling requirements or applying automation and AI to scale GRC operations
  • Knowledge of global regulatory frameworks, compliance practices, and risk management best practices
  • experience with risk assessments, regulatory responses, audits, or control design
  • 3+ years working in a corporate environment subject to audit against federal or industry-wide regulations
  • Experience in a technology, financial services, consulting, or related field
  • Advanced degree and/or relevant certification (CISSP, CRISC, CISM, CISA)
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Program Manager, Security Risk Program
Program Manager, Security Risk Program

Meta • City of Westminster

On-site
GBP 90,000 - 130,000
Product Manager (Leadership) - Risk
Product Manager (Leadership) - Risk

Meta • Greater London

Hybrid
GBP 120,000 - 180,000
AI Security Risk Program Lead
AI Security Risk Program Lead

Meta • Greater London

Hybrid
GBP 90,000 - 130,000
AI Launch Risk Program Lead
AI Launch Risk Program Lead

Meta • City of Westminster

On-site
GBP 90,000 - 130,000
Program Manager, Regional Regulatory Readiness - EMEA
Program Manager, Regional Regulatory Readiness - EMEA

Meta • Greater London

Hybrid
GBP 90,000 - 130,000
Program Manager, Regional Regulatory Readiness - EMEA
Program Manager, Regional Regulatory Readiness - EMEA

Meta • City of Westminster

On-site
GBP 90,000 - 130,000
Lead Technical Program Manager - Risk Technology
Lead Technical Program Manager - Risk Technology

JPMorgan Chase & Co. • Greater London

On-site
GBP 90,000 - 130,000
AI Governance | AI Assurance | AI Control Plane Subject Matter Expert
AI Governance | AI Assurance | AI Control Plane Subject Matter Expert

Consulting Point • England

On-site
GBP 120,000 - 190,000
Senior Product Manager: Risk, Compliance & AI Strategy
Senior Product Manager: Risk, Compliance & AI Strategy

Meta • Greater London

Hybrid
GBP 120,000 - 180,000
Lead Technical Program Manager - Risk Technology Engineering & Architecture/Risk Frameworks
Lead Technical Program Manager - Risk Technology Engineering & Architecture/Risk Frameworks

J.P. MORGAN • Glasgow

On-site
GBP 90,000 - 130,000