- Meta
- Menlo Park, CA
- Full-Time
- 44 days ago
- $184,000–$257,000 / year
Security Engineer - Vulnerability Management.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Security Engineer - Vulnerability Management: our view in 3 lines...
- The Role:This role is for a security engineer focused on vulnerability management and automated remediation at Meta scale.
- The Person:The person will build AI-powered remediation pipelines, develop ML-driven triage agents, architect supply-chain defense systems, and work across security, infrastructure, and product engineering teams to automate vulnerability management.
- Requirements:The ideal candidate has a bachelor’s degree in Computer Science, Information Security, or a relevant field, 5+ years securing enterprise-scale infrastructure, and 3-5+ years programming in Python, PHP, Ruby, or similar scripting languages.
About the role
Meta protects billions of people, and at our scale, vulnerabilities can't be managed by hand. As a Security Engineer on the Scaling – Vulnerability Management team, you'll build ML-based systems that automate how vulnerabilities are identified, triaged, and remediated across Meta's codebase. You'll design autonomous remediation pipelines and AI agents (like Viper and FixieAI) that cut through noise, surface real risk, and patch issues at a scale manual review can't reach — while building the supply-chain defenses (package mirrors, metadata services, and orchestration via VMMC) that keep automated upgrades safe. It's a chance to turn vulnerability management from a reactive queue into a proactive, automated defense.
- Design and build AI-powered autonomous remediation pipelines that detect and patch third-party library vulnerabilities across Meta's codebase, scaling from thousands to hundreds of thousands of packages.
- Develop ML-driven triage and contextualization agents (e.g., Viper Assist, FixieAI) that autonomously assess, prioritize, and suppress vulnerability tasks with high precision — compressing remediation queues down to real, actionable risk.
- Architect supply-chain defense systems, including time-locked package mirrors, quarantine mechanisms, and package decoration services that enrich dependency metadata for safer automated upgrades.
- Drive cross-functional strategy across security, infrastructure, and product engineering teams, defining processes that enable multiple teams to operate at scale with automation.
- Identify and solve ambiguous, open-ended problems where the solution is not initially known — owning technically complex workstreams while enabling others to execute.
- Bachelor's degree in Computer Science, Information Security, or relevant field (or equivalent experience)
- 5+ years work experience securing enterprise-scale infrastructure software and services
- 3-5+ years programming experience with at least one of the following languages: Python, PHP, Ruby, or similar scripting languages
- Experience remediating infrastructure security gaps across broad corporate boundaries using influence and relationships
- Experience with security control automation/monitoring or “compliance as code” implementations
- Experience thinking critically and defending solutions with communication skills in a cross-functional setting to influence decision makers across all levels of technical background
- Experience identifying, triaging, and remediating software security vulnerabilities - including third-party/open-source dependency vulnerabilities across a large-scale codebase
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
$184,000/year to $257,000/year + bonus + equity + benefits

