Security Engineer, Vulnerability Management - Meta
New York, NY
About the Job
The Meta Security Organization is seeking a passionate and experienced Security Engineer to help us mature Meta’s security posture through our vulnerability management program. Our team strives to go beyond identifying vulnerabilities by preventing security problems during the development process to eliminate entire classes of vulnerabilities.Do you have experience analyzing vulnerabilities and building vulnerability management programs? Can you identify when a vulnerability is critical enough to require real-time security response?Have you partnered with cross-functional partners to measure and improve how to identify, fix, and prevent vulnerabilities? Does the idea of having a meaningful and measurable impact on the security of one of the world's largest infrastructures, which serves billions of people, sound exciting to you? Well, good news, we need your help!
RESPONSIBILITIES
Security Engineer, Vulnerability Management Responsibilities:
MINIMUM QUALIFICATIONS
Minimum Qualifications:
PREFERRED QUALIFICATIONS
Preferred Qualifications:
RESPONSIBILITIES
Security Engineer, Vulnerability Management Responsibilities:
- Analyze vulnerabilities to determine the real impact to our systems and applications, incorporating threat intelligence.
- Drive solutions that enable high fidelity vulnerability contextualization, tracking, and remediation.
- Influence what areas of the vulnerability pipeline would most benefit from automation to improve operational efficiency and influence the team to prioritize the work.
- Dive into large datasets to identify strategic opportunities for security posture improvement.
- Influence the Meta-wide vulnerability management strategy, collaborating with partners to deliver multi-year roadmaps, while coaching and supporting team members.
- Provide rapid-response vulnerability analysis for active zero-days and participate in regular on-call vulnerability management rotation.
MINIMUM QUALIFICATIONS
Minimum Qualifications:
- B.S. or M.S. in Computer Science or related field, or equivalent experience
- 10+ years of experience in identifying security vulnerabilities, issues, risks, and developing mitigation plans.
- 6+ years of experience in network, system, or software architecture: design, implementation, support, and evaluation of security-focused tools and services.
- Technical and process subject matter expert regarding vulnerability management operations and company-wide programs to address the risk at scale.
- Experience developing and delivering information on vulnerability operations and management program status for leadership.
- Experience leading and managing complex cross-functional programs.
- Experience responding to both external and insider threats.
- Coding/scripting experience in one or more general purpose languages.
PREFERRED QUALIFICATIONS
Preferred Qualifications:
- Experience generating automated metrics to measure service and program effectiveness and consistency.
- Experience making contributions to the security or privacy community (public research, blogging, presentations, etc.).
- Background in malware analysis, digital forensics, intrusion detection, and/or threat intelligence.
- Broad knowledge across the security domain.
- Experience with attacker tactics, techniques, and procedures.
Source : Meta