Skip to main content

Application Security Engineer - Enterprise Engineering


Meta's Enterprise Engineering Application Security team is seeking a passionate security engineer with a hacker mindset who derives purpose in life by revealing potential weaknesses and then crafting creative solutions to eliminate those weaknesses. Your skills will be the foundation of security initiatives that protect the security and privacy of over two billion people. You will be expected to operate at an expert technical level with developers and engineers across large organizations. You will be relied upon to provide engineering and product teams with the web, mobile, or native-code security expertise necessary to build great products. Come help us make life hard for the bad guys.

**Required Skills:**

Application Security Engineer - Enterprise Engineering Responsibilities:

1. Engaging with our teams to design, develop, and deliver applications that meet evolving requirements for security and privacy. Ensure direction, prioritization, and timely delivery of this work within a changing business environment.

2. Automated Analysis and Secure Frameworks: build and deploy automation (static and dynamic analysis) and frameworks with software engineers that enable Meta to operate with appropriate security controls across all of our products and services.

3. Engineer Guidance: provide detailed technical guidance and education to developers that help prevent the introduction of vulnerabilities. Develop guidance based on output from static analysis platforms, vulnerability analysis tools, posture management tools, and other security assurance activities.

4. Security Reviews: perform periodic manual design and implementation reviews of products and services that make up the Meta ecosystem, including tools built in Python, containerized applications, web based services. Design methods for automating manual reviews to scale services to our internal customers.

**Minimum Qualifications:**

Minimum Qualifications:

5. 8+ years of experience identifying and mitigating security issues in software (python, ruby, Java). Knowledge of best practice secure code development

6. Experience leading and managing complex cross-functional security programs.

7. Experience with exploiting common security vulnerabilities in software.

**Preferred Qualifications:**

Preferred Qualifications:

8. Experience writing software that enables or evaluates security control in complex systems

9. 3+ years of experience in penetration testing or red team operations

10. Experience automating security controls in cloud environments (e.g. AWS, GCP, Azure)

11. Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)

**Public Compensation:**

$177,000/year to $251,000/year + bonus + equity + benefits

**Industry:** Internet

**Equal Opportunity:**

Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.

Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at

Similar jobs

Application Security Engineer - Enterprise Engineering

Full time
New York, NY

Published on 04/20/2024

Share this job now