About this role
Meta's Network Production Engineering organization is seeking a Infrastructure Security Monitoring Engineer to help protect the global network infrastructure that underpins Meta's family of apps and services. In this role, you will design and build detection systems that identify malicious activity, anomalous traffic patterns, and network-layer threats across Meta's large-scale infrastructure. You will work at the intersection of network engineering and security, developing tooling and automation that enables rapid identification and response to threats targeting Meta's backbone, edge, and data center networks.
Responsibilities
Design and implement network threat detection systems that identify malicious traffic, protocol abuse, and anomalous behavior across Meta's global network infrastructure
Develop and maintain automated detection pipelines that process high-volume network telemetry including flow data, packet captures, and routing protocol events
Investigate network security incidents by analyzing traffic patterns, correlating signals across infrastructure layers, and producing detailed retrospectives
Build and refine detection logic for network-layer threats such as DDoS, BGP hijacking, route leaks, and lateral movement across data center fabrics
Collaborate with network engineering, security, and infrastructure teams to identify detection gaps and drive improvements to network visibility and coverage
Instrument monitoring and alerting systems to surface anomalies in network behavior and reduce mean time to detection for active threats
Participate in on-call rotations to respond to network security incidents, triage alerts, and implement mitigations during active events
Contribute to the design and code review of detection frameworks, ensuring reliability, scalability, and maintainability of owned systems
Evaluate network telemetry sources and propose enhancements to data collection infrastructure that improve detection fidelity and reduce blind spots
Document detection methodologies, runbooks, and architectural decisions to support knowledge sharing across the team
Qualifications
Currently has, or is in the process of obtaining a Bachelor's degree in Computer Science, Computer Engineering, relevant technical field, or equivalent practical experience. Degree must be completed prior to joining Meta
2+ years of experience in network security, network operations, or production engineering with a focus on threat detection or security monitoring
Experience developing detection or monitoring tooling in at least one programming language such as Python, Go, or C++
Experience with network protocols and technologies including TCP/IP, BGP, DNS, and network flow analysis (e.g., NetFlow, sFlow, or IPFIX)
Experience building or operating network security monitoring systems, including log aggregation, alerting pipelines, or anomaly detection at scale
Experience investigating network security incidents, including traffic analysis, root cause identification, and post-incident documentation Familiarity with the MITRE ATT&CK for Enterprise or ICS frameworks and applying threat intelligence to network detection use cases
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Experience with stream processing or big data platforms used for real-time network telemetry analysis (e.g., Apache Kafka, Flink, or Spark)
Experience with large-scale distributed network environments such as data center fabrics, backbone networks, or internet exchange points
Experience applying machine learning techniques to network anomaly detection or traffic classification problems
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
