Security Engineer

MetaLondon, EnglandOn-siteFull-timeMid level, 2–5 yearsListed 1 hour ago

Apply now

About this role

Meta's Security Engineering team is seeking a Security Engineer to help protect billions of users and Meta's global infrastructure from evolving threats. In this role, you will conduct security assessments, vulnerability research, and threat modeling across Meta's products and systems — spanning mobile applications, web platforms, backend services, and internal infrastructure. You will identify systemic security gaps, drive mitigations at scale, and partner with engineering teams to embed security best practices into the software development lifecycle. Your work will directly reduce risk for Meta and its users by turning one-off security findings into durable, scalable defenses.

Responsibilities

Conduct security assessments, penetration testing, and vulnerability research across Meta's web, mobile, and backend systems to identify and remediate security risks
Perform threat modeling and security architecture reviews for new and existing products and infrastructure
Identify systemic security gaps and drive cross-functional mitigations that scale beyond individual findings
Develop and improve security tooling, automation, and detection capabilities to enhance the team's ability to identify and respond to threats
Collaborate with product and infrastructure engineering teams to define security requirements and integrate security controls into the software development lifecycle
Lead complex security investigations and incident response efforts, coordinating with cross-functional partners to resolve issues and prevent recurrence
Translate security findings into actionable, prioritized recommendations for engineering and leadership audiences through clear written documentation
Mentor other engineers on security best practices, contribute to team culture, and support recruiting and onboarding efforts
Manage oncall security responsibilities independently, triaging and resolving security issues with cross-functional support as needed
Identify and land new security initiatives on the team roadmap that address high-complexity, ambiguous risk areas aligned with broader team strategy

Qualifications

6+ years of experience in security engineering, including hands-on work in penetration testing, vulnerability research, or security assessments of web, mobile, or backend systems
Experience performing threat modeling and security architecture reviews for large-scale software systems
Experience identifying systemic security risks and driving cross-functional remediation efforts that result in scalable, durable improvements
Experience developing or improving security tooling, automation, or detection capabilities to support team-level security operations
Experience communicating security findings and risk assessments in writing to both technical and non-technical stakeholders Experience with security automation, static or dynamic analysis tooling, or building internal security platforms
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Familiarity with security considerations specific to large-scale distributed systems, mobile platforms (iOS or Android), or cloud infrastructure
Experience with offensive security techniques including exploit development, binary analysis, or red team operations
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Proficiency in one or more programming or scripting languages (e.g., Python, C/C++, Java) used to develop security tools or analyze vulnerabilities
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)