waypointjobs

Meta

Director, Security Risk Program

northern, KY

Check who can apply and the requirements below before continuing.

About this opportunity

Meta lists this Director, Security Risk Program opportunity in northern, Kentucky. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Meta's Security Risk Program (SRP) is the second-line function accountable for how Meta identifies, assesses, quantifies, and reports its security risk posture — to executive leadership, the Board, external auditors, and global regulators. The program delivers Global Security Risk Assessments (regulatory and commercial), Capability Maturity & Effectiveness (CME) evaluations, AI risk assessments, cloud security risk governance and assessment, unified risk intelligence and quantification, and board and regulatory reporting.

We are looking for a Director of Security Risk Program to lead this portfolio through a period of significant expansion. The role owns four program pillars and 38+ resources (FTE and contingent workforce), and is accountable for several strategic mandates: standing up Meta's security risk assessment capability for AI and product launches, evolving Meta’s cloud security risk capability, and building a comprehensive security risk intelligence picture across all three lines of defense, to support leadership decision-making and resource prioritization.

Success in this role is defined as much by influence as by ownership. The Director sits at the intersection of Central Security leadership, Risk Org PM and Eng, Legal Partners, and Meta's product organizations — translating engineering and product reality into a defensible risk position. This is a role for a risk leader who is equally credible in front of a regulator, a Board committee, and an engineering leader whose roadmap they are trying to shape.

The ideal candidate is a proven risk leader, with a background in Security, and an effective cross-organization collaborator and communicator who can distill complex regulatory positions for both technical and executive audiences. They have experience navigating ambiguity, defining structure in evolving problem spaces, and delivering results in rapidly changing product areas; they are skilled at leading a team, developing and driving high-level strategy, and — equally — personally executing on critical workstreams, including program planning and stakeholder coordination. They can sift through complex information, distill key insights, and elevate critical data to drive informed decisions at every level, from the working team to senior leadership.

15+ years of experience in security risk management, technology risk, GRC, or a directly related discipline

8+ years of experience managing and developing teams, including experience managing managers or senior individual contributors with demonstrated progression into organizational leadership

Demonstrated experience attracting talent, developing leadership pipelines, managing org health through growth or change

Demonstrated experience owning a security or technology risk program end-to-end across multiple organizations, including methodology, operations, and reporting

Demonstrated experience partnering with and presenting to executive leadership to shape organizational strategy, influence technical roadmaps, drive XFN alignment

Experience partnering directly with a Central Security or infrastructure security organizations and engineering leaders as a second-line risk function

Experience delivering assessments or reporting against external regulatory or certification regimes (e.g., EU regulatory frameworks, SOC 2, HIPAA, FDA, US Government requirements)

Demonstrated experience with risk assessment and capability maturity frameworks (e.g., NIST CSF, CMMI, ISO 27001, FAIR or comparable quantification approaches)

Experience building a risk assessment capability for AI systems, including AI-specific regulatory regimes (EU AI Act) or emerging AI risk frameworks

Experience integrating first-line and second-line risk responsibilities, or consolidating risk functions across domains

Experience embedding risk review into a fast-moving product development lifecycle

Experience with quantitative risk modeling and unified risk quantification at enterprise scale

Experience with cloud security risk governance in a large multi-cloud environment

Experience applying automation and AI tooling to scale GRC operations

Experience managing program resourcing, budget, and vendor or contingent workforce delivery

Familiarity with EU regulatory frameworks including GDPR/DPIA, RED, DORA, NIS2, or the Cyber Resilience Act

Relevant certifications (CISSP, CRISC, CISM, CISA) or an advanced degree in a related field

#J-18808-Ljbffr

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

AMN Healthcare

WhatJobs

Gastroenterologist

pensacola, FL

See pay details in description

Job Description & Requirements Gastroenterologist StartDate: ASAP Pay Rate: $ - $ A highly respected healthcare organization with over 60 y…

Listing review due 2026-10-07View job

AMN Healthcare

WhatJobs

Neurologist

yuma, AZ

See pay details in description

Job Description & Requirements Neurologist StartDate: ASAP Available Shifts: M-F no call Pay Rate: $ - $ AMN Healthcare has partnered with a …

Listing review due 2026-10-07View job

AMN Healthcare

WhatJobs

OBGYN-Wisconsin

baldwin, WI

Base Salary: $390,000

Job Description & Requirements OBGYN-Wisconsin StartDate: ASAP Pay Rate: $ OB/GYN Opportunity – Western Wisconsin  Just East of the Twin C…

Listing review due 2026-10-07View job