Program Manager, Security Risk Program

Meta

Washington (District of Columbia)

On-site

USD 153,000 - 209,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Meta seeks a Security Risk Program Manager to design and scale an AI Launch Risk Assessment capability. You will own the operating model, coordinate across Central Security, product groups, Privacy, Integrity, and Legal, and translate regulatory obligations into actionable assessment work for product teams.

The role combines governance, risk management, and program leadership to enable AI product velocity while ensuring regulatory compliance and defensible risk posture across the portfolio.

Qualifications

  • 8+ years of experience in governance, risk, and compliance, security risk management, or related discipline.
  • 3+ years of program management experience in a corporate environment.
  • Experience designing a program or process from the ground up with methodology, operating model, and rollout.
  • Demonstrated ability to drive cross-functional alignment without direct authority across engineering or product teams.
  • Proven verbal and written communication skills with senior leadership influence.

Responsibilities

  • Design and implement Meta's AI Launch Risk Assessment framework end to end and scale delivery from 5 to 20+ assessments per quarter by H1 2027.
  • Coordinate cross-domain risk management with Central Security, product groups, Privacy, Integrity, and Legal through each assessment.
  • Engage product and engineering teams early to inform design decisions and provide a clear path through second-line review.
  • Represent security risk positions to leadership and negotiate assessment scope, sequencing, and remediation commitments.
  • Build and maintain a consolidated AI risk register for leadership visibility and reporting.

Skills

Cross-functional collaboration
Security risk management
Effective communication
Program management

Education

Advanced degree or relevant certification (CISSP, CRISC, CISM, CISA)

Job description

Summary:

We are building a governance, risk, and compliance function to enable our company to buildproducts that can withstand regulatory scrutiny, and ensure Meta continues to meet globalregulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting.We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receivead-hoc coverage through security risk assessments designed for infrastructure — not forproduct-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity,and Legal. You will design that capability from the ground up and scale it from roughly fiveassessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AIproduct velocity.This is a builder and an influencer role in equal measure. AI launch risk cannot beassessed by one function acting alone — it requires Central Security, product groups, Privacy,Integrity, and Legal moving through a shared process on a launch timeline. You will own thatoperating model: translating product and engineering reality into a defensible risk position, andtranslating regulatory obligation into assessment work that product teams can actually absorbwithout stalling a launch. The ideal candidate is comfortable with ambiguity, effective inhigh-pressure and fast-moving situations, and able to build durable relationships across a widerange of technical and non-technical stakeholders.

Required Skills:

Program Manager, Security Risk Program Responsibilities:

  1. Design and implement Meta's AI Launch Risk Assessment framework end to end — intake criteria, cross-domain risk taxonomy, assessment methodology, and launch-gate outputs — and scale delivery from ~5 to 20+ assessments per quarter by H1 2027.

  2. Build and partner to manage the XFN operating model that coordinates Central Security, product groups, Privacy Risk Management, Integrity Risk Management, and Legal through each assessment, with clear roles, handoffs, and decision rights on a launch timeline.

  3. Partner directly with product and engineering teams on high-priority AI launches — engaging early enough that security risk review informs design decisions rather than gating release, and giving product teams a predictable, well-documented path through second-line review.

  4. Serve as the connection point between the Security Risk Program, Central Security leadership, Legal, and first-line business teams, representing security risk positions and negotiating assessment scope, sequencing, and remediation commitments.

  5. Build and maintain a consolidated AI risk register that gives leadership a single view of.

  6. security risk across the AI product portfolio, and produce the reporting that keeps that view current for VP and executive audiences.

  7. Define tooling requirements and drive AI-enabled automation across the assessment lifecycle — identifying where automation can scale throughput without compromising assessment defensibility, and partnering with tooling and engineering owners to deliver it.

  8. Ensure assessments and supporting artifacts are produced to internal standards, are.

  9. submission-ready, and constitute defensible evidence of systematic security due diligence for regulators and auditors (including EU AI Act and NIST AI RMF expectations).

  10. Identify risks, dependencies, and blockers across the program, define mitigation plans, monitor key delivery and SLA metrics, and drive corrective action with stakeholders when performance deviates.

  11. Create and facilitate presentations that build senior leadership understanding and influence decision-making, and provide mentorship and guidance to junior team members on program design and assessment practice.

Minimum Qualifications:

Minimum Qualifications:

  1. 8+ years of experience in governance, risk, and compliance, security risk management,

  2. regulatory compliance, or a directly related discipline

  3. 3+ years of program management experience in a corporate environment

  4. Experience with risk and compliance precepts, practices, and solutions

  5. Demonstrated experience designing a program or process from the ground up — not solely running an established one — including methodology, operating model, and rollout

  6. Demonstrated experience driving cross-functional alignment across technical and non-technical partners without direct authority, including with engineering or product organizations

  7. Proven verbal and written communication skills, with success influencing a range of audiences including senior leadership

Preferred Qualifications:

Preferred Qualifications:

  1. Experience assessing or managing risk for AI or machine learning systems, or familiarity with AI-specific regulatory and risk frameworks (EU AI Act, NIST AI RMF)

  2. Experience embedding risk, security, or compliance review into a fast-moving product

  3. development lifecycle and launch process

  4. Experience working in information security and/or cybersecurity

  5. Experience partnering with a central security or infrastructure security organization as a

  6. second-line risk function

  7. Experience defining tooling requirements or applying automation and AI to scale GRC operations

  8. Knowledge of global regulatory frameworks, compliance practices, and risk management best

  9. practices

  10. experience with risk assessments, regulatory responses, audits, or control design

  11. 3+ years working in a corporate environment subject to audit against federal or industry-wide regulations

  12. Experience in a technology, financial services, consulting, or related field

  13. Advanced degree and/or relevant certification (CISSP, CRISC, CISM, CISA)

  14. Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)

  15. Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)

  16. Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emergi ng AI technologies

Public Compensation:

$153,000/year to $209,000/year + bonus + equity + benefits

Industry:

Internet

Equal Opportunity:

Meta is proud to be an Equal Employment Opportunity and Affinary Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.

Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@meta.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Program Manager, Security Risk Program
Program Manager, Security Risk Program

Meta • New York (NY)

On-site
USD 153,000 - 209,000
Program Manager, Compliance Assurance
Program Manager, Compliance Assurance

Meta • Menlo Park (CA)

On-site
USD 122,000 - 180,000
Bonus
Equity
Benefits
Program Manager, Compliance Assurance
Program Manager, Compliance Assurance

Meta • Washington

On-site
USD 122,000 - 180,000
Program Manager, Security Risk Program
Program Manager, Security Risk Program

Meta • Menlo Park (CA)

On-site
USD 190,000 - 260,000
Exam & Audit — Integrity Program Manager
Exam & Audit — Integrity Program Manager

Meta • Washington

On-site
USD 122,000 - 180,000
Product Risk Program Manager - Product Enablement
Product Risk Program Manager - Product Enablement

Meta • New York (NY)

On-site
USD 122,000 - 180,000
Bonus
Equity
Benefits
Technical Program Manager, Risk Organization
Technical Program Manager, Risk Organization

Meta • United States

On-site
USD 199,000 - 272,000
Program Manager, Compliance Assurance
Program Manager, Compliance Assurance

Meta • New York (NY)

On-site
USD 122,000 - 180,000
Bonus
Equity
Benefits
Program Manager, Privacy Risk Assessment
Program Manager, Privacy Risk Assessment

Meta • Menlo Park (CA)

On-site
USD 122,000 - 180,000
Bonus
Equity
Benefits
Product Risk Program Manager
Product Risk Program Manager

Meta • Austin (TX)

On-site
USD 153,000 - 209,000