Security Engineer - Vulnerability Management

Meta

Washington (District of Columbia)

On-site

USD 184,000 - 257,000

Full time

15 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Bonus
Equity
Benefits

Job summary

Meta is seeking a Security Engineer to advance vulnerability management at scale. You will build ML-based systems to identify, triage, and remediate vulnerabilities across Meta's codebase with autonomous pipelines and AI agents, enabling proactive, automated defenses across the supply chain.

The role involves cross-functional collaboration with security, infrastructure, and product engineering teams to scale automation, design time-locked mirrors, and enrich metadata for safer upgrades.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or relevant field (or equivalent experience)
  • 5+ years work experience securing enterprise-scale infrastructure software and services
  • 3-5+ years programming experience in Python, PHP, Ruby, or similar scripting languages
  • Experience remediating infrastructure security gaps across broad corporate boundaries
  • Experience with security control automation/monitoring or “compliance as code” implementations
  • Experience thinking critically and communicating across technical levels
  • Experience identifying, triaging, and remediating software security vulnerabilities in large codebases

Responsibilities

  • Design and build AI-powered autonomous remediation pipelines that detect and patch third-party library vulnerabilities across Meta's codebase, scaling from thousands to hundreds of thousands of packages
  • Develop ML-driven triage and contextualization agents that autonomously assess, prioritize, and suppress vulnerability tasks with high precision
  • Architect supply-chain defense systems, including time-locked package mirrors and metadata-enrichment services
  • Drive cross-functional strategy across security, infrastructure, and product engineering teams for scalable automation
  • Identify and solve ambiguous, open-ended problems owning technically complex workstreams

Skills

Python
PHP
Ruby
Security engineering
Infrastructure security

Education

Bachelor's degree in Computer Science, Information Security, or relevant field

Job description

Meta protects billions of people, and at our scale, vulnerabilities can't be managed by hand. As a Security Engineer on the Scaling – Vulnerability Management team, you'll build ML-based systems that automate how vulnerabilities are identified, triaged, and remediated across Meta's codebase. You'll design autonomous remediation pipelines and AI agents (like Viper and FixieAI) that cut through noise, surface real risk, and patch issues at a scale manual review can't reach — while building the supply-chain defenses (package mirrors, metadata services, and orchestration via VMMC) that keep automated upgrades safe. It's a chance to turn vulnerability management from a reactive queue into a proactive, automated defense.

Security Engineer - Vulnerability Management Responsibilities:
  • Design and build AI-powered autonomous remediation pipelines that detect and patch third-party library vulnerabilities across Meta's codebase, scaling from thousands to hundreds of thousands of packages.
  • Develop ML-driven triage and contextualization agents (e.g., Viper Assist, FixieAI) that autonomously assess, prioritize, and suppress vulnerability tasks with high precision — compressing remediation queues down to real, actionable risk.
  • Architect supply-chain defense systems, including time-locked package mirrors, quarantine mechanisms, and package decoration services that enrich dependency metadata for safer automated upgrades.
  • Drive cross-functional strategy across security, infrastructure, and product engineering teams, defining processes that enable multiple teams to operate at scale with automation.
  • Identify and solve ambiguous, open-ended problems where the solution is not initially known — owning technically complex workstreams while enabling others to execute.
Minimum Qualifications:
  • Bachelor's degree in Computer Science, Information Security, or relevant field (or equivalent experience)
  • 5+ years work experience securing enterprise-scale infrastructure software and services
  • 3-5+ years programming experience with at least one of the following languages: Python, PHP, Ruby, or similar scripting languages
  • Experience remediating infrastructure security gaps across broad corporate boundaries using influence and relationships
  • Experience with security control automation/monitoring or “compliance as code” implementations
  • Experience thinking critically and defending solutions with communication skills in a cross-functional setting to influence decision makers across all levels of technical background
  • Experience identifying, triaging, and remediating software security vulnerabilities - including third-party/open-source dependency vulnerabilities across a large-scale codebase
Preferred Qualifications:
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
About Meta:

Meta builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. People who choose to build their careers by building with us at Meta help shape a future that will take us beyond what digital connection makes possible today—beyond the constraints of screens, the limits of distance, and even the rules of physics.

Meta is proud to be an Equal Employment Opportunity and Affiantive Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.

Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@meta.com.

$184,000/year to $257,000/year + bonus + equity + benefits

Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate, monthly rate, or annual salary only, and do not include bonus, equity or sales incentives, if applicable. In addition to base compensation, Meta offers benefits. Learn more about benefits at Meta.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Meta • New York (NY)

On-site
USD 184,000 - 257,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Meta • United States

On-site
USD 184,000 - 257,000
Bonus
Equity
Benefits
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Meta • Juneau (AK)

On-site
USD 184,000 - 257,000
Bonus
Equity
Benefits
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Meta • Honolulu (HI)

On-site
USD 184,000 - 257,000
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Meta • Menlo Park (CA)

On-site
USD 184,000 - 257,000
Bonus
Equity
Benefits
Security Engineer - Vulnerability Management
Security Engineer - Vulnerability Management

Meta • Dover (DE)

On-site
USD 184,000 - 257,000
Security Engineer
Security Engineer

Meta • Menlo Park (CA)

On-site
USD 271,000 - 347,000
Security Engineer
Security Engineer

Meta • New York (NY)

On-site
USD 271,000 - 347,000
Security Engineer
Security Engineer

Meta • Washington

On-site
USD 271,000 - 347,000
Security Engineer - Security Risk Management
Security Engineer - Security Risk Management

Meta • Seattle (WA)

On-site
USD 154,000 - 217,000