Security Program Manager, Exam and Audit

Meta

$150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security compliance, governance, risk management, or regulatory program management (technology, finance, healthcare)
  • Proven leadership in external audits, regulatory examinations, and third-party assessments
  • Deep understanding of compliance frameworks (ISO 27001, SOC 2, NIST CSF, FedRAMP) in enterprise settings
  • Skilled communicator of complex security concepts to technical and executive audiences
  • Experience in identifying and resolving systemic compliance issues across organizations

Responsibilities

  • Lead strategy and execution of regulatory examinations and audits, including scoping and evidence coordination
  • Act as a subject-matter expert for security compliance frameworks, advising teams on audit obligations
  • Establish and maintain an audit-readiness program with control testing and continuous monitoring
  • Evaluate effectiveness of security controls across various domains for second-line-of-defense oversight
  • Collaborate with cross-functional teams to translate regulations into actionable compliance frameworks
  • Identify compliance gaps and direct remediation efforts effectively
  • Develop long-term plans for enhancing the security exam and audit program, incorporating technological advancements
  • Communicate audit outcomes and program status to senior leadership and external stakeholders

Benefits

  • Comprehensive health benefits including medical, dental, and vision coverage
  • Generous paid time off policy to promote work-life balance
  • Retirement savings options with company matching contributions
  • Access to professional development and training resources
  • Opportunities for advancement within a leading technology company
Full Job Description
The Exam and Audit team is responsible for establishing, maturing, and managing Meta's security compliance posture across external regulatory examinations, third-party audits, and internal assurance activities. As a Staff-level Security Program Manager on this team, you will serve as a strategic leader and subject-matter expert, driving the design and execution of audit-readiness programs, overseeing second-line-of-defense compliance functions, and partnering with security engineering, legal, and policy teams to ensure Meta's security practices meet the expectations of regulators and auditors worldwide.

Responsibilities

Lead the end-to-end strategy and execution of external security regulatory examinations and third-party audits, including scoping, evidence coordination, findings management, and remediation tracking
• Serve as a senior subject-matter expert on security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, and applicable regulatory requirements, advising cross-functional teams on audit obligations and control expectations
• Develop and maintain a comprehensive audit-readiness program, including control testing schedules, evidence libraries, and continuous monitoring mechanisms to sustain audit-ready posture
• Provide second-line-of-defense oversight by independently assessing the design and operating effectiveness of security controls across product, infrastructure, and operational domains
• Partner with security engineering, legal, privacy, and policy teams to translate regulatory requirements into actionable control frameworks and scalable compliance processes
• Identify systemic compliance gaps and drive prioritized remediation efforts, serving as a key escalation point for risk acceptance decisions and regulatory risk mitigation strategies
• Define long-term roadmaps for the evolution of Meta's security exam and audit program, including operating model improvements, tooling investments, and program maturity milestones
• Communicate audit findings, compliance posture, and program status to senior leadership and external stakeholders through clear written briefings, executive summaries, and regulatory response documentation
• Mentor other program managers and compliance professionals on audit methodology, regulatory engagement, and security control assessment practices
• Anticipate regulatory trends and emerging audit requirements, proactively adjusting program strategy to address new obligations before they become compliance risks

Minimum Qualifications
• 8+ years of experience in security compliance, governance, risk and compliance (GRC), or regulatory program management within the technology, financial services, or healthcare industry
• Experience leading or managing external security audits, regulatory examinations, or third-party assessments, including evidence coordination, findings response, and remediation oversight
• Experience applying security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, FedRAMP, or equivalent regulatory standards in an enterprise environment
• Experience communicating complex security and compliance concepts in writing to technical, legal, and executive stakeholders, including audit reports, control narratives, and regulatory correspondence
• Experience identifying and driving resolution of systemic compliance gaps across cross-functional security and engineering organizations

Preferred Qualifications
• Professional certification in security or audit disciplines such as CISSP, CISA, CISM, or equivalent
• Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
• Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
• Experience engaging directly with external regulators or audit bodies on behalf of a large-scale technology platform
• Experience designing or maturing second-line-of-defense oversight functions within a security or privacy compliance program
• Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
• Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
• Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
• Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
• Demonstrated ability to integrate AI-assisted tools to improve audit workflow efficiency, evidence analysis, or compliance monitoring at scale

Similar Jobs

More Jobs at Meta

More Information Technology Jobs

Find similar Security Program Manager, Exam and Audit jobs: