Program Manager, Security Risk Program

Meta

Menlo Park (CA)

On-site

USD 190,000 - 260,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Meta seeks a Security Risk Program Manager to create and scale AI product launch risk assessments across Security, Privacy, Integrity, and Legal. You will own the operating model, expanding from ~5 to 20+ assessments per quarter by H1 2027, coordinating across engineering, product, and governance functions.

The role requires building durable relationships, navigating ambiguity, and delivering clear risk positions to senior leadership.

Qualifications

  • 8+ years in governance, risk, and compliance or related field.
  • 3+ years of program management in a corporate setting.
  • Experience with risk and compliance principles, practices, and solutions.
  • Proven ability to design programs or processes from scratch including methodology and rollout.
  • Ability to drive cross-functional alignment without direct authority.
  • Strong verbal and written communication with senior stakeholders.
  • Experience assessing or managing risk for AI/ML systems; knowledge of AI regulatory frameworks.
  • Experience embedding risk reviews into product development lifecycles.
  • Background in information security/cybersecurity.
  • Experience partnering with central security or infra security organizations.
  • Ability to define tooling requirements or apply automation to scale GRC.
  • Knowledge of global regulatory frameworks and best practices.
  • Experience in corporate audits and regulatory responses.
  • Industry experience in tech/finance/consulting.
  • Demonstrated AI tool integration to optimize workflows.
  • Commitment to responsible AI practices and ongoing AI skill development.

Responsibilities

  • Build and scale the AI product risk assessment capability across launch workflows.
  • Own the operating model; translate product reality into defensible risk positions.
  • Coordinate across Central Security, product groups, Privacy, Integrity, and Legal.
  • Influence senior leadership and diverse stakeholders to align on risk posture.
  • Design processes to enable faster product launches without compromising risk management.

Skills

Security risk management
Program management
Cross-functional collaboration
Communication skills
AI risk & regulatory knowledge
Risk assessment execution
Policy & governance
Ambiguity handling
Security/InfoSec
Automation & tooling for GRC
Stakeholder influence
AI/ML risk frameworks (EU AI Act, NIST

Education

Advanced degree and/or relevant certification (CISSP, CRISC, CISM, CISA)

Tools

None

Job description

We are building a governance, risk, and compliance function to enable our company to build products that can withstand regulatory scrutiny, and ensure Meta continues to meet global regulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting.

We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receive ad-hoc coverage through security risk assessments designed for infrastructure — not for product-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity, and Legal. You will design that capability from the ground up and scale it from roughly five assessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AI product velocity.

This is a builder and an influencer role in equal measure. AI launch risk cannot be assessed by one function acting alone — it requires Central Security, product groups, Privacy, Integrity, and Legal moving through a shared process on a launch timeline. You will own that operating model: translating product and engineering reality into a defensible risk position, and translating regulatory obligation into assessment work that product teams can actually absorb without stalling a launch. The ideal candidate is comfortable with ambiguity, effective in high-pressure and fast-moving situations, and able to build durable relationships across a wide range of technical and non-technical stakeholders.

  • 8+ years of experience in governance, risk, and compliance, security risk management, regulatory compliance, or a directly related discipline
  • 3+ years of program management experience in a corporate environment
  • Experience with risk and compliance precepts, practices, and solutions
  • Demonstrated experience designing a program or process from the ground up — not solely running an established one — including methodology, operating model, and rollout
  • Demonstrated experience driving cross-functional alignment across technical and non-technical partners without direct authority, including with engineering or product organizations
  • Proven verbal and written communication skills, with success influencing a range of audiences including senior leadership
  • Experience assessing or managing risk for AI or machine learning systems, or familiarity with AI-specific regulatory and risk frameworks (EU AI Act, NIST AI RMF)
  • Experience embedding risk, security, or compliance review into a fast-moving product development lifecycle and launch process
  • Experience working in information security and/or cybersecurity
  • Experience partnering with a central security or infrastructure security organization as a second-line risk function
  • Experience defining tooling requirements or applying automation and AI to scale GRC operations
  • Knowledge of global regulatory frameworks, compliance practices, and risk management best practices
  • experience with risk assessments, regulatory responses, audits, or control design
  • 3+ years working in a corporate environment subject to audit against federal or industry-wide regulations
  • Experience in a technology, financial services, consulting, or related field
  • Advanced degree and/or relevant certification (CISSP, CRISC, CISM, CISA)
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Security Risk Program
Director, Security Risk Program

Meta • Washington, Northern (KY)

Hybrid
USD 260,000 - 360,000
Director, Security Risk Program
Director, Security Risk Program

Socket.dev • Washington

On-site
USD 227,000 - 287,000
Bonus
Equity
Benefits
Security Program Manager, Exam and Audit
Security Program Manager, Exam and Audit

Meta • Menlo Park (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Program Manager, Assurance
Program Manager, Assurance

Meta • Menlo Park (CA), Northern (KY)

Hybrid
USD 250,000 - 350,000
Technical Program Manager, Developers Infrastructure
Technical Program Manager, Developers Infrastructure

Meta • Menlo Park (CA), Seattle (WA)

On-site
USD 190,000 - 270,000
AI Security Risk Program Lead
AI Security Risk Program Lead

Meta • Menlo Park (CA)

On-site
USD 190,000 - 260,000
Design Program Manager
Design Program Manager

Meta • Washington, New York (NY), Menlo Park (CA)

On-site
USD 130,000 - 170,000
Director, Security Risk Program — AI, Cloud & Regulators
Director, Security Risk Program — AI, Cloud & Regulators

Meta • Washington, Northern (KY)

Hybrid
USD 260,000 - 360,000
Senior Project Controls & Risk Strategist, Data Center Development
Senior Project Controls & Risk Strategist, Data Center Development

Meta • Menlo Park (CA)

On-site
USD 180,000 - 260,000
Director, Security Risk Strategy & AI Governance
Director, Security Risk Strategy & AI Governance

Socket.dev • Washington

On-site
USD 227,000 - 287,000
Bonus
Equity
Benefits