Enterprise Application Security Engineer (Builder)

Meta·New York, New York, United States·posted 21d ago · last seen 1m ago

Track this application

Get Started Free

Match score against your CV

Get Started Free

Tailor your resume to this job

Get Started Free

About interviewing at Meta

Recruiter screen, a technical screen (60-minute asynchronous challenge or paired live coding), a short culture-fit questionnaire, then a virtual onsite of about four rounds: fast-paced coding with multiple problems per round, system design scoped to level, a lighter behavioral, and an AI-enabled coding round assessing how you work with a coding assistant.

Read the full Meta interview process →

Description

About

Meta's Enterprise Application Security team is seeking a security engineer with proven experience identifying weaknesses and crafting creative solutions to eliminate those weaknesses at scale. We secure and harden the enterprise applications Meta runs on, both first-party and third-party, and we protect the sensitive data they hold. We don't just identify and help fix security vulnerabilities, we go beyond by preventing security problems before they exist. Our scope includes securing how Meta adopts third-party AI applications and agentic workflows across the enterprise, a high-priority area with significant visibility across the company. You will be expected to collaborate technically with developers and engineers across large organizations, and you will be relied upon to provide application and infrastructure teams with the security expertise necessary to build the secure enterprise that underpins Meta.

Responsibilities

  • Conceive, design, develop and improve effective security tooling, automation and/or frameworks that enable enterprise teams at scale to deliver applications and services with appropriate security controls to meet evolving requirements for security, privacy, and data protection
  • Identify and eliminate classes of security problems by shifting detection and prevention left into the development workflow
  • Provide just-in-time, actionable, technical security guidance to enterprise application and service teams through code reviews, penetration tests, adversarial testing, threat modeling, architecture design reviews, and other security activities
  • Collaborate with cross-functional teams to ensure security work is being prioritized and addressed
  • Design and build security controls and guardrails that allow the safe adoption of third-party AI applications and agentic workflows across the enterprise, including controls governing what automated systems can access and what data they can reach
  • Protect sensitive and highly confidential data held in enterprise applications by building enforcement mechanisms that operate continuously and at scale

Minimum Qualifications

  • B.S. or M.S in Computer Science, Engineering, or related technical discipline, or equivalent experience
  • 2+ years of work experience developing production-level code in Python, PHP, Java, Ruby, Go, Rust, C/C++, or similar language
  • 2+ years of work experience identifying and mitigating security issues in software (Python, PHP, Java, Ruby, Go, Rust, C/C++ or similar language) and knowledge of best practice secure code development
  • Experience owning a particular component, feature or system
  • Experience building and securing enterprise-scale software, services, and infrastructure
  • Experience communicating technical security findings and recommendations in writing to technical and non-technical stakeholders Experience developing software that enables or evaluates security controls in complex systems
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  • Experience fixing enterprise security problems across broad corporate boundaries using influence and relationships
  • Experience in designing, analyzing and conducting threat model assessments of enterprise software and services
  • Experience in penetration testing or red team operations
  • Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)
  • Experience automating application security controls in large-scale enterprise environments
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Broad knowledge of the security domain, which may include security investigations, incident management, digital forensics, offensive security, vulnerability management, application security, and other security disciplines

More engineering roles at Meta