About this role
We are building a governance, risk, and compliance function to enable our company to build products that can withstand regulatory scrutiny, and to ensure Meta continues to meet global regulatory requirements and manage risk. Within the Regulatory Compliance Programs team, the Examinations & Audit (E&A) team owns Meta's readiness for, and execution of, external audit engagements — including the independent audit required under the EU Digital Services Act (DSA) — and operates at the intersection of policy, legal, engineering, and product.
We are seeking a candidate to serve as E&A's most senior technical authority on control identification, technical response development, and evidence production across Meta's external audit portfolio. This is a portfolio-level role: rather than owning a single engagement, you will set the technical strategy that determines how Meta evidences regulatory compliance across multiple concurrent audits and regulatory regimes, and you will be accountable for whether that strategy holds up under independent testing.
This is both a technical program and project management role. You should be able to read a system design, follow a data flow, and reason about whether a given log, pipeline, config, or metric can withstand independent testing — then drive the cross-functional work to make it so. At this level you are expected to do that at scale: establishing the evidence and control standards other teams build to, resolving the hardest and most ambiguous testability problems, and acting as the authoritative translation layer between external auditors and the engineering organizations whose systems are under examination.
Responsibilities
Set the technical strategy for how Meta identifies, designs, and evidences controls across the E&A audit portfolio, spanning multiple regulatory regimes and concurrent engagements.
Define the control architecture that maps regulatory obligations to the specific systems, pipelines, configurations, and enforcement mechanisms that implement them — and establish the standards other teams and subject matter leads build to.
Own Meta's technical position on the most complex and contested auditor requests: determining what evidence exists, what it actually demonstrates, where it is authoritative, and how it must be presented to withstand independent testing.
Serve as Meta's senior technical voice with external auditors, regulators, and independent assessors, coordinating Meta's technical position and submissions across engagements.
Direct technical evidence production across the portfolio — scoping, sequencing across engineering and data teams, and validating that deliverables meet auditor expectations at first submission.
Drive remediation of the most significant findings, holding accountable engineering and product owners to management action plans (MAPs) through to closure.
Own maturation of E&A's control framework — control objectives, testing methodologies, and evidence standards — so that annual audit cycles are repeatable and scale as the regulatory portfolio expands.
Scale audit and compliance effectiveness using AI to deliver monitoring, oversight, artifact generation, and org-wide continuous improvement; develop and deliver an AI-native approach to evidence gathering and control testing.
Design the tooling, automation, and reporting architecture that gives leadership visibility into audit status, control health, evidence readiness, and remediation progress.
Build consensus and buy-in across Product, Engineering, Legal, Policy, Data Science, Operations, and Internal Audit on control ownership and evidence obligations, surfacing risk and dependencies early with clear mitigation and escalation paths.
Maintain an in-depth understanding of the evolving regulatory landscape affecting Meta — including Integrity, Youth, Privacy, and Security — and translate it into audit and control strategy.
Mentor and develop technical program managers and subject matter leads across the team, raising the technical bar of the function.
Qualifications
12+ years of experience in compliance, audit, technology risk, or technical program management, including significant experience in a technical program management capacity
Experience setting the technical strategy for, or leading, multiple concurrent regulatory audit programs or external assessments (e.g., SOC, ISO, DSA, or government/regulatory audits). Deep experience with control identification, control design, and control testing, including establishing what constitutes sufficient and reliable evidence
Technical acumen — demonstrated ability to reason about systems architecture, data flows, logging, and engineering trade-offs in the context of compliance requirements
Experience directing technical evidence production across multiple engineering and data organizations under external deadlines
Experience serving as a senior technical counterpart to external auditors, regulators, or independent assessors
Experience developing and delivering AI-native strategies to scale compliance, assurance, or audit operations
Demonstrated ability to operate as a single-threaded owner for highly complex, ambiguous, cross-functional portfolios
Experience building governance structures, escalation processes, and reporting mechanisms that drive accountability across distributed teams
Excellent written and verbal communication skills, with proven success influencing senior leadership across technical and non-technical audiences Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Experience with the EU Digital Services Act, including the independent audit obligation, or comparable Trust and Safety, Youth, and/or other platform-accountability regimes
Experience with audit and control frameworks (e.g., COSO, COBIT, NIST) and risk management methodologies such as control self-assessments, gap analyses, issue management, and compliance maturity models
Experience building or scaling 1LoD / 2LoD audit and assurance programs at a technology company
Experience developing compliance monitoring systems or automated controls embedded within software development or deployment pipelines
Experience with data capability (e.g., SQL, log and pipeline analysis) sufficient to independently validate evidence populations and reported figures
Experience with transparency reporting and integrity measurement methodologies, including metric definition, population scoping, calculation methodology, and data lineage
Knowledge of global content regulations, content moderation, and Trust & Safety best practices
Experience in Trust & Safety, Content Integrity, or Policy Compliance at a major technology platform
Experience in regulated industries, information security, and/or cybersecurity
Advanced degree and/or relevant certification (e.g., CIA, CISA, CRISC, CIPP)
