Meta
Security Program Manager, Exam and Audit

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Meta is seeking a Staff Security Program Manager
Meta is seeking a Staff Security Program Manager to lead compliance strategy and assessment programs focused on security examination and audit readiness. In this role, you will drive the design, execution, and continuous improvement of Meta's security compliance programs, including regulatory examinations, third-party audits, and internal control assessments across Meta's platforms and infrastructure. You will serve as a strategic authority on security compliance frameworks, translating complex regulatory requirements into scalable program structures that protect Meta's products and users at a global scale.
Responsibilities
- Define and own the long-term strategy for Meta's security examination and audit compliance programs, including scope, methodology, and governance frameworks
- Lead cross-functional coordination across security engineering, legal, privacy, and policy teams to prepare for and respond to regulatory examinations and third-party security audits
- Drive audit readiness programs by identifying control gaps, assessing risk exposure, and partnering with technical teams to implement remediation plans
- Establish metrics, reporting cadences, and executive-level communications to convey audit status, findings, and program health to senior leadership
- Serve as the primary point of contact for external auditors and regulatory examiners, managing evidence collection, inquiry responses, and audit lifecycle coordination
- Identify systemic compliance risks across Meta's security posture and develop scalable program interventions to address them proactively
- Influence the design of security controls and engineering processes to embed compliance requirements into product and infrastructure development lifecycles
- Build and refine program management tooling, workflows, and documentation standards to improve audit efficiency and repeatability across the organization
- Mentor other program managers and compliance professionals, establishing best practices and elevating the overall maturity of the security compliance function
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Minimum Qualifications
- 8+ years of experience in security compliance, audit management, or regulatory examination programs within a technology or enterprise environment
- Experience leading end-to-end security audit or examination programs, including evidence management, control testing, and findings remediation at organizational scale
- Experience applying security compliance frameworks such as ISO 27001, SOC 2, NIST CSF, FedRAMP, or equivalent regulatory standards to large-scale technical environments
- Experience communicating complex compliance and security risk topics in writing to technical teams and non-technical executive stakeholders
- Experience driving cross-functional alignment across security, legal, engineering, and policy organizations on compliance program strategy and execution


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Preferred Qualifications
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Familiarity with security control automation, continuous compliance monitoring tools, or GRC platforms used to scale audit evidence collection
- Experience building or maturing a security compliance function from early-stage program design through full operational deployment
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Professional certifications such as CISA, CISSP, CISM, or equivalent security and audit credentials
- Experience managing security compliance programs in a global technology company subject to multiple concurrent regulatory frameworks and jurisdictions
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location