Rodeo
Get started

Meta

Program Manager, Security Risk Program

London
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Title

We are building a governance, risk, and compliance function to enable our company to build products that can withstand regulatory scrutiny, and ensure Meta continues to meet global regulatory requirements and manage risk. Meta's Risk and Compliance Program (RCP) is the central engine driving risk management and compliance at the company, supporting Meta and the family of apps. Within RCP, the Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — delivering global security risk assessments, Capability Maturity & Effectiveness (CME) evaluations, AI and cloud risk assessments, and board-level and regulatory reporting. We are seeking a Security Risk Program Manager to build one of the program's highest-priority new capabilities: security risk assessment of AI product launches. Today, AI launches receive ad-hoc coverage through security risk assessments designed for infrastructure — not for product-launch cadence, and not for cross-domain AI risk spanning Security, Privacy, Integrity, and Legal. You will design that capability from the ground up and scale it from roughly five assessments per quarter today to twenty or more per quarter by H1 2027, in step with Meta's AI product velocity. This is a builder and an influencer role in equal measure. AI launch risk cannot be assessed by one function acting alone — it requires Central Security, product groups, Privacy, Integrity, and Legal moving through a shared process on a launch timeline. You will own that operating model: translating product and engineering reality into a defensible risk position, and translating regulatory obligation into assessment work that product teams can actually absorb without stalling a launch. The ideal candidate is comfortable with ambiguity, effective in high-pressure and fast-moving situations, and able to build durable relationships across a wide range of technical and non-technical stakeholders.

Responsibilities

  • Design and implement Meta's AI Launch Risk Assessment framework end to end — intake criteria, cross-domain risk taxonomy, assessment methodology, and launch-gate outputs — and scale delivery from ~5 to 20+ assessments per quarter by H1 2027.
  • Build and partner to manage the XFN operating model that coordinates Central Security, product groups, Privacy Risk Management, Integrity Risk Management, and Legal through each assessment, with clear roles, handoffs, and decision rights on a launch timeline.
  • Partner directly with product and engineering teams on high-priority AI launches — engaging early enough that security risk review informs design decisions rather than gating release, and giving product teams a predictable, well-documented path through second-line review.
  • Serve as the connection point between the Security Risk Program, Central Security leadership, Legal, and first-line business teams, representing security risk positions and negotiating assessment scope, sequencing, and remediation commitments.
  • Build and maintain a consolidated AI risk register that gives leadership a single view of security risk across the AI product portfolio, and produce the reporting that keeps that view current for VP and executive audiences.
  • Define tooling requirements and drive AI-enabled automation across the assessment lifecycle — identifying where automation can scale throughput without compromising assessment defensibility, and partnering with tooling and engineering owners to deliver it.
  • Ensure assessments and supporting artifacts are produced to internal standards, are submission-ready, and constitute defensible evidence of systematic security due diligence for regulators and auditors (including EU AI Act and NIST AI RMF expectations).
  • Identify risks, dependencies, and blockers across the program, define mitigation plans, monitor key delivery and SLA metrics, and drive corrective action with stakeholders when performance deviates.
  • Create and facilitate presentations that build senior leadership understanding and influence decision-making, and provide mentorship and guidance to junior team members on program design and assessment practice.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Minimum Qualifications

  • 6+ years of experience in governance, risk, and compliance, security risk management, regulatory compliance, or a directly related discipline
  • 2+ years of program management experience in a corporate environment
  • Experience with risk and compliance precepts, practices, and solutions
  • Demonstrated experience designing a program or process from the ground up — not solely running an established one — including methodology, operating model, and rollout
  • Demonstrated experience driving cross-functional alignment across technical and non-technical partners without direct authority, including with engineering or product organizations
  • Proven verbal and written communication skills, with success influencing a range of audiences including senior leadership

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Qualifications

  • Experience assessing or managing risk for AI or machine learning systems, or familiarity with AI-specific regulatory and risk frameworks (EU AI Act, NIST AI RMF)
  • Experience embedding risk, security, or compliance review into a fast-moving product development lifecycle and launch process
  • Experience working in information security and/or cybersecurity
  • Experience partnering with a central security or infrastructure security organization as a second-line risk function
  • Experience defining tooling requirements or applying automation and AI to scale GRC operations
  • Knowledge of global regulatory frameworks, compliance practices, and risk management best practices
  • Experience with risk assessments, regulatory responses, audits, or control design
  • 3+ years working in a corporate environment subject to audit against federal or industry-wide regulations
  • Experience in a technology, financial services, consulting, or related field
  • Advanced degree and/or relevant certification (CISSP, CRISC, CISM, CISA)
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Governance
Risk Management
Compliance
Security Risk Assessment
Program Management
AI Risk Assessment
Regulatory Compliance
Cross-functional Leadership
Stakeholder Management
Process Design
Risk Taxonomy
Automation
Reporting
Cybersecurity
EU AI Act
NIST AI RMF

Location

London, England, United Kingdom

Sign up to applySee more jobs like this