The Exam and Audit team is responsible for establishing, maturing, and managing Meta's security compliance posture across external regulatory examinations, third-party audits, and internal assurance activities. As a Staff-level Security Program Manager on this team, you will serve as a strategic leader and subject-matter expert, driving the design and execution of audit-readiness programs, overseeing second-line-of-defense compliance functions, and partnering with security engineering, legal, and policy teams to ensure Meta's security practices meet the expectations of regulators and auditors worldwide.
Responsibilities
Lead the end-to-end strategy and execution of external security regulatory examinations and third-party audits, including scoping, evidence coordination, findings management, and remediation tracking
• Serve as a senior subject-matter expert on security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, and applicable regulatory requirements, advising cross-functional teams on audit obligations and control expectations
• Develop and maintain a comprehensive audit-readiness program, including control testing schedules, evidence libraries, and continuous monitoring mechanisms to sustain audit-ready posture
• Provide second-line-of-defense oversight by independently assessing the design and operating effectiveness of security controls across product, infrastructure, and operational domains
• Partner with security engineering, legal, privacy, and policy teams to translate regulatory requirements into actionable control frameworks and scalable compliance processes
• Identify systemic compliance gaps and drive prioritized remediation efforts, serving as a key escalation point for risk acceptance decisions and regulatory risk mitigation strategies
• Define long-term roadmaps for the evolution of Meta's security exam and audit program, including operating model improvements, tooling investments, and program maturity milestones
• Communicate audit findings, compliance posture, and program status to senior leadership and external stakeholders through clear written briefings, executive summaries, and regulatory response documentation
• Mentor other program managers and compliance professionals on audit methodology, regulatory engagement, and security control assessment practices
• Anticipate regulatory trends and emerging audit requirements, proactively adjusting program strategy to address new obligations before they become compliance risks
Minimum Qualifications
• 8+ years of experience in security compliance, governance, risk and compliance (GRC), or regulatory program management within the technology, financial services, or healthcare industry
• Experience leading or managing external security audits, regulatory examinations, or third-party assessments, including evidence coordination, findings response, and remediation oversight
• Experience applying security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, FedRAMP, or equivalent regulatory standards in an enterprise environment
• Experience communicating complex security and compliance concepts in writing to technical, legal, and executive stakeholders, including audit reports, control narratives, and regulatory correspondence
• Experience identifying and driving resolution of systemic compliance gaps across cross-functional security and engineering organizations
Preferred Qualifications
• Professional certification in security or audit disciplines such as CISSP, CISA, CISM, or equivalent
• Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
• Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
• Experience engaging directly with external regulators or audit bodies on behalf of a large-scale technology platform
• Experience designing or maturing second-line-of-defense oversight functions within a security or privacy compliance program
• Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
• Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
• Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
• Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
• Demonstrated ability to integrate AI-assisted tools to improve audit workflow efficiency, evidence analysis, or compliance monitoring at scale