Product Security Engineer

MetaMenlo Park, CaliforniaOn-siteFull-timeMid level, 2–5 yearsListed 1 hour ago

Apply now

About this role

Meta's Security Engineering team is looking for a Security Engineer to help protect the billions of people who use Meta's family of products and services. In this role, you will identify and mitigate security vulnerabilities across Meta's infrastructure, applications, and platforms, working closely with engineering and product teams to drive systemic security improvements at scale. You will apply deep technical expertise in offensive and defensive security to reduce risk and build resilient systems that safeguard user data and platform integrity.

Responsibilities

Conduct security assessments, threat modeling, and code reviews across Meta's products and infrastructure to identify and remediate vulnerabilities
Develop and implement scalable security tooling, automation, and frameworks to detect and prevent security issues across the engineering organization
Partner with engineering and product teams to embed security requirements into the design and development lifecycle
Investigate security incidents and drive root cause analysis, translating findings into systemic mitigations and process improvements
Identify gaps in security coverage and drive cross-functional efforts to close them through tooling, policy, or architectural changes
Turn one-off vulnerability findings into repeatable detection and remediation patterns that scale across the codebase
Represent the security team in cross-functional collaborations, communicating risk posture and mitigation strategies to engineering leadership
Mentor other engineers on secure coding practices, vulnerability classes, and security review methodologies
Manage and independently resolve security incidents, coordinating with cross-functional partners to drive timely remediation

Qualifications

5+ years of experience in security engineering, including vulnerability research, penetration testing, or security assessments of applications and infrastructure
Experience identifying and exploiting common vulnerability classes such as memory corruption, injection flaws, authentication bypasses, or privilege escalation
Experience developing security tooling, automation, or detection frameworks in one or more general-purpose programming or scripting languages
Experience conducting threat modeling and security design reviews for large-scale distributed systems or web and mobile applications
Experience collaborating with cross-functional engineering teams to drive security mitigations and communicate risk in written and verbal formats
Bachelor's or Master's degree in Computer Science or related field or equivalent technical security experience Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Familiarity with security challenges specific to large-scale social platforms, including account integrity, data access controls, and API security
Experience building static or dynamic analysis tools to identify security vulnerabilities at scale across large codebases
Contributions to the security community through public research, vulnerability disclosures, bug bounty programs, conference presentations, or open-source tooling
Experience with both offensive security techniques (e.g., red teaming, exploit development) and defensive security engineering (e.g., detection engineering, secure architecture design)