Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
M
Meta
Director, Security Risk Program
Career Insights for Director of Risk Management
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Washington, D.C. (District of Columbia) data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Director of Risk Management directs and oversees risk management activity for a company or organization. Evaluates risk, develops strategies to mitigate or offset risks that could result in financial losses, and directs implementation of risk management strategies. May direct risk management in investments, business operations and finance, or insurance..
$128,916 / year median in Washington, D.C. (District of Columbia)
Job Description
Director, Security Risk Program Meta - 4.0 Washington, DC Job Details $227,000 - $287,000 a year 21 hours ago Qualifications Capability maturity model Security team coordination Security risk assessment investigation Talent management Talent acquisition Managing IT teams Information & network security team management Team development Regulatory Frameworks (Architecture security) Recruiting Leading team collaboration initiatives Regulatory compliance analysis Cross-functional team management Cross-functional communication Senior leadership Full Job Description Meta's Security Risk Program (SRP) is the second-line function accountable for how Metaidentifies, assesses, quantifies, and reports its security risk posture — to executiveleadership, the Board, external auditors, and global regulators. The program delivers GlobalSecurity Risk Assessments (regulatory and commercial), Capability Maturity & Effectiveness(CME) evaluations, AI risk assessments, cloud security risk governance and assessment, unified risk intelligence and quantification, and board and regulatory reporting.
We are looking for a Director of Security Risk Program to lead this portfolio through a periodof significant expansion. The role owns four program pillars and 38+ resources (FTE and contingent workforce), and is accountable for several strategic mandates: standing up Meta's security risk assessment capability for AI and product launches, evolving Meta's cloud security risk capability, and building a comprehensive security risk intelligence picture across all three lines of defense, to support leadership decision-making and resource prioritization.
Success in this role is defined as much by influence as by ownership. The Director sits at theintersection of Central Security leadership, Risk Org PM and Eng, Legal Partners, and Meta's product organizations — translating engineering and product reality into a defensible risk position. This is a role for a risk leader who is equally credible in front of a regulator, a Board committee, and an engineering leader whose roadmap they are trying to shape.
The ideal candidate is a proven risk leader, with a background in Security, and an effective cross-organization collaborator and communicator who can distill complex regulatory positions for both technical and executive audiences. They have experience navigating ambiguity, defining structure in evolving problem spaces, and delivering results in rapidly changing product areas; they are skilled at leading a team, developing and driving high-level strategy, and — equally — personally executing on critical workstreams, including program planning and stakeholder coordination. They can sift through complex information, distill key insights, and elevate critical data to drive informed decisions at every level, from the working team to senior leadership.
We are looking for a Director of Security Risk Program to lead this portfolio through a periodof significant expansion. The role owns four program pillars and 38+ resources (FTE and contingent workforce), and is accountable for several strategic mandates: standing up Meta's security risk assessment capability for AI and product launches, evolving Meta's cloud security risk capability, and building a comprehensive security risk intelligence picture across all three lines of defense, to support leadership decision-making and resource prioritization.
Success in this role is defined as much by influence as by ownership. The Director sits at theintersection of Central Security leadership, Risk Org PM and Eng, Legal Partners, and Meta's product organizations — translating engineering and product reality into a defensible risk position. This is a role for a risk leader who is equally credible in front of a regulator, a Board committee, and an engineering leader whose roadmap they are trying to shape.
The ideal candidate is a proven risk leader, with a background in Security, and an effective cross-organization collaborator and communicator who can distill complex regulatory positions for both technical and executive audiences. They have experience navigating ambiguity, defining structure in evolving problem spaces, and delivering results in rapidly changing product areas; they are skilled at leading a team, developing and driving high-level strategy, and — equally — personally executing on critical workstreams, including program planning and stakeholder coordination. They can sift through complex information, distill key insights, and elevate critical data to drive informed decisions at every level, from the working team to senior leadership.
Director, Security Risk Program Responsibilities:
Own the strategy, operating model, and end-to-end delivery of Meta's Security Risk Program across four programmatic pillars — Risk Assessments, Capability Maturity & Effectiveness, Risk Intelligence, and Cloud Security Risk — and lead, develop, and grow the multidisciplinary team and contingent workforce that delivers it. Serve as the program's primary partner to Central Security leadership, driving a unified approach to security risk management (tooling, process, and methodology), including absorbing in-flight work from 1LOD into the second line: negotiating scope,. sequencing, and integration decisions, and establishing clear risk coverage ownership across the lines of defense. Embed security risk assessment into how product organizations build and ship — engaging early on predicate, AI, and cloud assessments so that risk review accelerates launches rather than gating them, and so product teams have a clear, predictable path through second-line review. Own accountability for Tier 1 regulated deliverables with fixed external deadlines, including Global Security Risk Assessments, EU RED and Data Protection assessments, commercial certifications (SOC 2, HIPAA, FDA, USG), the EU Cyber Resilience Act program, and EU AI Act model assessments. Represent Meta's security risk posture to executive leadership, Board committees, internal fora, regulators, and external auditors, and act as the escalation and risk-acceptance decision-maker for the program. Build and scale security risk assessment capability for AI, establishing methodology, tiering, and operations for predicate assessments, model assessments, and rapid assessments in close partnership with AI infrastructure, product, and Legal teams. Drive cross-domain unification with Privacy Risk Management, Integrity Risk Management, Legal, Compliance, and Internal Audit — owning the Unified Risk Quantification model and a common risk taxonomy so Meta presents one coherent risk picture rather than several competing ones. Own program financials and resourcing, and drive the strategy for automation and AI that scales assessment throughput without compromising defensibility.Minimum Qualifications:
15+ years of experience in security risk management, technology risk, GRC, or a directly related discipline 8+ years of experience managing and developing teams, including experience managing managers or senior individual contributors with demonstrated progression into organizational leadership Demonstrated experience attracting talent, developing leadership pipelines, managing org health through growth or change Demonstrated experience owning a security or technology risk program end-to-end across multiple organizations, including methodology, operations, and reporting Demonstrated experience partnering with and presenting to executive leadership to shape organizational strategy, influence technical roadmaps, drive XFN alignment Experience partnering directly with a Central Security or infrastructure security organizations and engineering leaders as a second-line risk function Experience delivering assessments or reporting against external regulatory or certification regimes (e.g., EU regulatory frameworks, SOC 2, HIPAA, FDA, US Government requirements) Demonstrated experience with risk assessment and capability maturity frameworks (e.g., NISTCSF, CMMI, ISO
27001, FAIR or comparable quantification approaches)Preferred Qualifications:
Experience building a risk assessment capability for AI systems, including AI-specific regulatory regimes (EU AI Act) or emerging AI risk frameworks Experience integrating first-line and second-line risk responsibilities, or consolidating risk functions across domains Experience embedding risk review into a fast-moving product development lifecycle Experience with quantitative risk modeling and unified risk quantification at enterprise scale Experience with cloud security risk governance in a large multi-cloud environment Experience applying automation and AI tooling to scale GRC operations Experience managing program resourcing, budget, and vendor or contingent workforce delivery Familiarity with EU regulatory frameworks including GDPR/DPIA, RED, DORA, NIS2, or the Cyber Resilience Act Relevant certifications (CISSP, CRISC, CISM, CISA) or an advanced degree in a related fieldAbout Meta:
Meta builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. People who choose to build their careers by building with us at Meta help shape a future that will take us beyond what digital connection makes possible today—beyond the constraints of screens, the limits of distance, and even the rules of physics. Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment. Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at . $227,000/year to $287,000/year + bonus + equity + benefits Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate, monthly rate, or annual salary only, and do not include bonus, equity or sales incentives, if applicable. In addition to base compensation, Meta offers benefits. Learn more about benefits at Meta.Benefits
- Dental Insurance