Meta's Infrastructure Security Monitoring (ISM) team is seeking an experienced engineer to help secure the infrastructure that connects over a billion users. You will be responsible for building, implementing and operationally supporting detections throughout our infrastructure. We are looking for a candidate with a passion for security and innovation, who will research and develop new solutions to help protect our infrastructure and our users. This candidate should thrive on identifying scalable detection opportunities, codifying their ideas and enjoy making life hard for the bad actors of the world. With focuses that range from large scale DDoS, detection, security tool development, defense against internal and external attacks there are great opportunities to push your skills further while having a significant impact.
Responsibilities
- Iterate security posture to better protect against attacks and detect new vectors
- Lead efforts to mitigate and investigate security incidents
- Utilize frameworks to develop and scale detection, mitigation and response automation tooling
- Evaluate and test new vendor and home-grown initiatives for security issues
- Mentor and evangelize security practices through cross functional work with engineering teams throughout Meta
- Keep Meta safe through active operation and defense of critical infrastructure
Minimum Qualifications
- Currently has, or is in the process of obtaining a Bachelor's degree in Computer Science, Computer Engineering, relevant technical field, or equivalent practical experience. Degree must be completed prior to joining Meta
- 3+ years of development experience in at least one programming language (Python, Go, etc.) with the ability to apply that to security tool development, automation, and overall programmatic solutions that will be used to defend infrastructure
- 1+ years of experience in offensive/defensive security or systems engineering
- Knowledge of network protocols (TCP/IP, computer networking, routing and switching) and Unix based systems
- Experience researching, building, and implementing defensive security systems that are used against internal and external attack vectors
- Experience designing and building out application, system and network security monitoring to aid in detection or forensic investigations Experience developing baselines and investigating anomalies in order to identify suspicious behavior
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Understanding of MITRE ATT&CK Framework and associated threat actor techniques
- Experience developing automation and utilizing frameworks to scale detection, mitigation or response tools
- Background in intrusion detection, security investigations, and incident response
- Experience threat hunting, i.e. using threat intel to proactively and iteratively investigate potential risks and finding suspicious behavior
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience mentoring and promoting industry security practices