Product Security Engineer
Job Description
Meta’s Security Engineering team is looking for a Product Security Engineer to help uncover and reduce security vulnerabilities across Meta’s infrastructure, applications, and platforms. In this onsite role in Menlo Park, you will work closely with engineering and product teams to create security improvements that hold up at scale.
This position blends offensive and defensive security expertise, with a focus on turning findings into repeatable patterns, scalable tooling, and durable mitigations across the organization.
Responsibilities
- Perform security assessments, threat modeling, and code reviews across Meta products and infrastructure to identify and remediate vulnerabilities
- Build and roll out scalable security tooling, automation, and frameworks to detect and prevent security issues throughout the engineering organization
- Partner with engineering and product teams to embed security requirements into the design and development lifecycle
- Investigate security incidents and lead root cause analysis, then translate results into systemic mitigations and process improvements
- Spot gaps in security coverage and coordinate cross-functional efforts to close them through tooling, policy, or architectural changes
- Convert one-off vulnerability discoveries into repeatable detection and remediation patterns that scale across the codebase
- Represent the security team in cross-functional collaborations by communicating risk posture and mitigation strategies to engineering leadership
- Mentor engineers on secure coding practices, vulnerability classes, and security review methodologies
- Manage and independently resolve security incidents, coordinating with cross-functional partners to drive timely remediation
Requirements
- 5+ years of experience in security engineering, including vulnerability research, penetration testing, or security assessments for applications and infrastructure
- Experience identifying and exploiting common vulnerability classes, including memory corruption, injection flaws, authentication bypasses, or privilege escalation
- Experience developing security tooling, automation, or detection frameworks using one or more general-purpose programming or scripting languages
- Experience conducting threat modeling and security design reviews for large-scale distributed systems or web and mobile applications
- Experience collaborating with cross-functional engineering teams to drive security mitigations and communicate risk in written and verbal formats
- Bachelor’s or Master’s degree in Computer Science or a related field, or equivalent technical security experience
Preferred Qualifications
- Demonstrated ongoing AI skill development (for example, prompt/context engineering or agent orchestration) and staying current with emerging AI technologies
- Demonstrated ability to integrate AI tools to optimize or redesign workflows and drive measurable impact such as efficiency gains or quality improvements
- Experience adhering to and implementing responsible, ethical AI practices, including risk assessment, bias mitigation, and quality and accuracy reviews
- Familiarity with security challenges specific to large-scale social platforms, including account integrity, data access controls, and API security
- Experience building static or dynamic analysis tools to identify security vulnerabilities at scale across large codebases
- Contributions to the security community through public research, vulnerability disclosures, bug bounty programs, conference presentations, or open-source tooling
- Experience across both offensive security (for example, red teaming or exploit development) and defensive security engineering (for example, detection engineering or secure architecture design)
Location: Menlo Park, CA (onsite)
Compensation: USD 154,000 - 217,000 per year
Minimum experience: 5 years
Education: Bachelor’s or Master’s degree in Computer Science or related field