Stand out for this role — generate a tailored resume and cover letter in about a minute.
Meta seeks a Security Risk Program Manager to create and scale AI product launch risk assessments across Security, Privacy, Integrity, and Legal. You will own the operating model, expanding from ~5 to 20+ assessments per quarter by H1 2027, coordinating across engineering, product, and governance functions.
The role requires building durable relationships, navigating ambiguity, and delivering clear risk positions to senior leadership.
We are building a governance, risk, and compliance function to enable our company to build products that can withstand regulatory scrutiny, and ensure Meta continues to meet global regulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting.
We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receive ad-hoc coverage through security risk assessments designed for infrastructure — not for product-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity, and Legal. You will design that capability from the ground up and scale it from roughly five assessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AI product velocity.
This is a builder and an influencer role in equal measure. AI launch risk cannot be assessed by one function acting alone — it requires Central Security, product groups, Privacy, Integrity, and Legal moving through a shared process on a launch timeline. You will own that operating model: translating product and engineering reality into a defensible risk position, and translating regulatory obligation into assessment work that product teams can actually absorb without stalling a launch. The ideal candidate is comfortable with ambiguity, effective in high-pressure and fast-moving situations, and able to build durable relationships across a wide range of technical and non-technical stakeholders.