Privacy Engineer, Red Team

MetaMenlo Park, CaliforniaOn-siteFull-timeMid level, 2–5 yearsListed 1 hour ago

Apply now

About this role

Meta is seeking a Privacy Engineer to join our Privacy Red Team, a specialized function dedicated to proactively identifying and exposing privacy risks across Meta's family of apps and services before they can impact the people who use our products. In this role, you will conduct adversarial privacy assessments, simulate real-world privacy attack scenarios, and drive systemic improvements to how Meta designs and builds privacy-protective systems. You will operate at the intersection of offensive security thinking and privacy engineering, partnering with product, legal, policy, and engineering teams to surface and remediate privacy vulnerabilities at scale. This is a high-impact, technically demanding role for an experienced privacy engineer who thinks like an adversary and builds like an engineer.

Responsibilities

Design and execute adversarial privacy assessments across Meta's products and infrastructure, simulating real-world threat scenarios to identify data exposure, unauthorized access, and privacy control failures
Develop and maintain a red team methodology and testing framework specific to privacy risks, including data minimization failures, consent bypass, re-identification attacks, and cross-context data leakage
Identify systemic privacy vulnerabilities across multiple product surfaces and drive remediation through cross-functional partnerships with engineering, product, legal, and policy teams
Define and improve privacy red team processes, tooling, and workflows that enable scalable, repeatable adversarial testing across Meta's evolving product portfolio
Translate complex privacy attack findings into actionable risk assessments and communicate them clearly to both technical engineering teams and non-technical leadership audiences
Partner with privacy engineering, security, and compliance teams to align red team findings with regulatory obligations and internal privacy standards
Drive the long-term strategy and roadmap for privacy red team operations, identifying emerging threat vectors and influencing organizational priorities accordingly
Mentor other engineers on adversarial privacy testing techniques, fostering a culture of proactive privacy risk identification across the broader engineering organization
Lead coordinated responses to large-scale privacy risk escalations, managing cross-functional mitigation efforts and tracking resolution across multiple teams
Identify gaps in existing privacy controls, detection capabilities, and engineering processes, and drive technical solutions to close those gaps at scale

Qualifications

8+ years of experience in privacy engineering, security engineering, or a related field with a focus on adversarial testing, vulnerability research, or privacy risk assessment
Experience designing and executing privacy or security red team assessments, including threat modeling, attack simulation, and control validation across large-scale consumer products
Experience identifying and exploiting privacy vulnerabilities such as re-identification risks, data minimization failures, unauthorized data access patterns, or consent and purpose limitation bypass
Experience communicating technical privacy risk findings in written form to both engineering teams and non-technical leadership stakeholders
Experience driving cross-functional remediation efforts and influencing engineering and product decisions through privacy risk analysis Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Experience developing automated tooling or testing pipelines to scale privacy red team assessments across large, distributed codebases
Track record of defining and operationalizing privacy red team programs from early-stage development through organizational adoption
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Experience with data flow analysis, traffic inspection, or reverse engineering techniques applied to privacy control validation
Familiarity with global privacy regulations and frameworks such as GDPR, CCPA, or ISO 29134, and experience applying them in an adversarial or audit context