Meta's Network Production Engineering organization is seeking a Infrastructure Security Monitoring Engineer to help protect the global network infrastructure that underpins Meta's family of apps and services. In this role, you will design and build detection systems that identify malicious activity, anomalous traffic patterns, and network-layer threats across Meta's large-scale infrastructure. You will work at the intersection of network engineering and security, developing tooling and automation that enables rapid identification and response to threats targeting Meta's backbone, edge, and data center networks.
Responsibilities
Design and implement network threat detection systems that identify malicious traffic, protocol abuse, and anomalous behavior across Meta's global network infrastructure
• Develop and maintain automated detection pipelines that process high-volume network telemetry including flow data, packet captures, and routing protocol events
• Investigate network security incidents by analyzing traffic patterns, correlating signals across infrastructure layers, and producing detailed retrospectives
• Build and refine detection logic for network-layer threats such as DDoS, BGP hijacking, route leaks, and lateral movement across data center fabrics
• Collaborate with network engineering, security, and infrastructure teams to identify detection gaps and drive improvements to network visibility and coverage
• Instrument monitoring and alerting systems to surface anomalies in network behavior and reduce mean time to detection for active threats
• Participate in on-call rotations to respond to network security incidents, triage alerts, and implement mitigations during active events
• Contribute to the design and code review of detection frameworks, ensuring reliability, scalability, and maintainability of owned systems
• Evaluate network telemetry sources and propose enhancements to data collection infrastructure that improve detection fidelity and reduce blind spots
• Document detection methodologies, runbooks, and architectural decisions to support knowledge sharing across the team
Minimum Qualifications
• Currently has, or is in the process of obtaining a Bachelor's degree in Computer Science, Computer Engineering, relevant technical field, or equivalent practical experience. Degree must be completed prior to joining Meta
• 2+ years of experience in network security, network operations, or production engineering with a focus on threat detection or security monitoring
• Experience developing detection or monitoring tooling in at least one programming language such as Python, Go, or C++
• Experience with network protocols and technologies including TCP/IP, BGP, DNS, and network flow analysis (e.g., NetFlow, sFlow, or IPFIX)
• Experience building or operating network security monitoring systems, including log aggregation, alerting pipelines, or anomaly detection at scale
• Experience investigating network security incidents, including traffic analysis, root cause identification, and post-incident documentation
Preferred Qualifications
• Familiarity with the MITRE ATT&CK for Enterprise or ICS frameworks and applying threat intelligence to network detection use cases
• Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
• Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
• Experience with stream processing or big data platforms used for real-time network telemetry analysis (e.g., Apache Kafka, Flink, or Spark)
• Experience with large-scale distributed network environments such as data center fabrics, backbone networks, or internet exchange points
• Experience applying machine learning techniques to network anomaly detection or traffic classification problems
• Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)