Security Engineer, Vulnerability Management

3 weeks ago


Washington, United States META Full time

Summary:

The Meta Security Organization is seeking a passionate and experienced Security Engineer to help us mature Meta’s security posture through our vulnerability management program. Our team strives to go beyond identifying vulnerabilities by preventing security problems during the development process to eliminate entire classes of vulnerabilities.Do you have experience analyzing vulnerabilities and building vulnerability management programs? Can you identify when a vulnerability is critical enough to require real-time security response?Have you partnered with cross-functional partners to measure and improve how to identify, fix, and prevent vulnerabilities? Does the idea of having a meaningful and measurable impact on the security of one of the world's largest infrastructures, which serves billions of people, sound exciting to you? Well, good news, we need your help

Required Skills:

Security Engineer, Vulnerability Management Responsibilities:

  1. Analyze vulnerabilities to determine the real impact to our systems and applications, incorporating threat intelligence.

  2. Drive solutions that enable high fidelity vulnerability contextualization, tracking, and remediation.

  3. Influence what areas of the vulnerability pipeline would most benefit from automation to improve operational efficiency and influence the team to prioritize the work.

  4. Dive into large datasets to identify strategic opportunities for security posture improvement.

  5. Influence the Meta-wide vulnerability management strategy, collaborating with partners to deliver multi-year roadmaps, while coaching and supporting team members.

  6. Provide rapid-response vulnerability analysis for active zero-days and participate in regular on-call vulnerability management rotation.

Minimum Qualifications:

Minimum Qualifications:

  1. 5+ years of experience in identifying security vulnerabilities, issues, risks, and developing mitigation plans.

  2. 4+ years of experience in network, system, or software architecture: design, implementation, support, and evaluation of security-focused tools and services.

  3. Technical and process subject matter expert regarding vulnerability management operations and company-wide programs to address the risk at scale.

  4. Experience responding to both external and insider threats.

  5. Coding/scripting experience in one or more general purpose languages.

Preferred Qualifications:

Preferred Qualifications:

  1. Experience generating automated metrics to measure service and program effectiveness and consistency.

  2. Experience making contributions to the security or privacy community (public research, blogging, presentations, etc.).

  3. Background in malware analysis, digital forensics, intrusion detection, and/or threat intelligence.

  4. Broad knowledge across the security domain.

  5. Experience with attacker tactics, techniques, and procedures.

Public Compensation:

$147,000/year to $208,000/year + bonus + equity + benefits

Industry: Internet

Equal Opportunity:

Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.

Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.



  • Washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • Washington, United States Coalfire Federal Full time

    Coalfire Federal is a market leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. Coalfire Federal along with its parent company, Coalfire, has an unparalleled client list with deep customer relationships with...


  • Washington, United States Fiserv Full time

    Calling all innovators - find your future at Fiserv. We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card,...


  • Washington, United States TechnoGen Full time

    I am Kishore from TechnoGen Inc., I am currently looking for Security Vulnerability Engineer - Windows forone of our clients. Below is the job description for your review...Please let me know if you would be interested and please attach your updated resume at kishore.b@technogeninc.com We are seeking a highly skilled Security Vulnerability Engineer with deep...


  • Washington, United States TechnoGen Full time

    I am Kishore Mandaloju from TechnoGen Inc., I am currently looking for Security Vulnerability Engineer - Windows forone of our clients. Below is the job description for your review...Please let me know if you would be interested and please attach your updated resume at kishore.m@technogeninc.com We are seeking a highly skilled Security Vulnerability Engineer...


  • Washington, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:NoneClearance Level Must Be Able to Obtain:NoneSuitability:Public Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Technology Security, Remediation, Vulnerability ManagementCertifications:Experience:5 + years of related experienceUS Citizenship...


  • Washington, United States General Dynamics Information Technology Full time

    Type of Requisition:RegularClearance Level Must Currently Possess:NoneClearance Level Must Be Able to Obtain:NonePublic Trust/Other Required:NoneJob Family:Information SecurityJob Qualifications:Skills:Information Technology Security, Remediation, Vulnerability ManagementCertifications:NoneExperience:5 + years of related experienceUS Citizenship...


  • washington, United States Serigor Inc Full time

    Job Title: Apps and Server Vulnerability Engineer (Onsite)Location: Washington, DCDuration:12 Months+Job Description:We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to join our team. The ideal candidate will be responsible for performing comprehensive security assessments of web applications, mobile...


  • Washington, United States Serigor Inc Full time

    Job Title: Apps and Server Vulnerability Engineer (Onsite)Location: Washington, DCDuration:12 Months+Job Description:We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to join our team. The ideal candidate will be responsible for performing comprehensive security assessments of web applications, mobile...


  • Washington, United States h3 Technologies Full time

    Job Title: Apps and Server Vulnerability Engineer (Onsite) Location: Washington, DC Duration: 12 Months+ Additionally, please send me scanned copies of your consultant's Driver's License, H1B copy, i94, and travel history to this email. Job Description: We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to...


  • Washington, United States Coalfire Federal Full time

    Cybersecurity Specialist - Vulnerability ManagementCoalfire Federal is a leading cybersecurity consultancy that provides independent and tailored advice, assessments, technical testing, and a full suite of cybersecurity engineering services to Federal agency customers. With an unparalleled client list and deep customer relationships with leading cloud and...


  • Washington, United States VISTRADA Full time

    Job Posting: Security System Engineer (Junior/Intermediate/Senior Level) Vistrada is currently seeking highly skilled and motivated Security System Engineers to join our esteemed team. As a Security System Engineer, you will play a crucial role in identifying and mitigating vulnerabilities, ensuring the secure integration and operation of systems, and...

  • Security Engineer

    4 weeks ago


    Washington, United States Expedite Technology Solutions LLC Full time

    Education: Bachelor's Clearance Required: Public Trust Role Title Security Engineer Start Date for assignment 06/12/2024 End Date for assignment 03/25/2025 # of Resources Needed 2 Hours per Week 40 Job Description This work is Sold Unsold Specialization : Technical Skills : Skill Years/Level of Experience Amazon Web Services (AWS) Security P2 -...


  • Washington, DC, United States Serigor Inc Full time

    Job Title:Apps and Server Vulnerability Engineer (Onsite)Location:Washington, DCDuration:12 Months+Job Description:We are looking for a talented and experienced Application and Server Vulnerability Assessment Engineer to join our team. The ideal candidate will be responsible for performing comprehensive security assessments of web applications, mobile...


  • Washington, United States Global Solutions Consulting (GSC) Full time

    Job DescriptionJob DescriptionPosition Title: Senior Application Security EngineerLocation: Washington, DC (Hybrid)Job Requirements:Strong written and verbal communication skills· Must have GitLab CI/CD pipeline experience· Assist in the development and implementation of the DevSecOps strategy to include the definition and goals of the over-arching...


  • Washington, United States SourcePro Search, LLC Full time

    Our top rated global client is looking for an experienced Senior Application Security Engineer for their Washington, DC office. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This position collaborates with business units, project management, and...

  • Security Engineer

    3 weeks ago


    Washington, United States GLO Comms Full time

    Overview: A leading global provider of information and analytics in the real estate sector is seeking Security Engineers to join an innovative team. This position focuses on ensuring the security of web applications and offers both onsite and remote opportunities, ranging from Associate to Lead Architect levels.Responsibilities:Develop and maintain a...


  • Washington, United States META Full time

    Summary: Meta's Product Security team is seeking a passionate hacker who derives purpose in life by revealing potential weaknesses and then crafting creative solutions to eliminate those weaknesses. Your skills will be the foundation of security initiatives that protect the security and privacy of over two billion people. You will be relied upon to provide...