Enterprise Application Security Engineer (Builder)
Meta New York, New York, United States · $122K–$181K/yr
Software Development · 10,001+ employees
About the role
You will design and develop security tooling and automation to identify and eliminate security vulnerabilities across enterprise applications. Additionally, you will collaborate with cross-functional teams to implement security guardrails for AI applications and protect sensitive data at scale.
What they look for
Requirements
Candidates must have a bachelor's or master's degree in a technical field and at least 2 years of experience in software development and security mitigation. Proficiency in languages such as Python, Java, or Go and experience in securing enterprise-scale infrastructure are required.
Benefits
Full description
Meta's Enterprise Application Security team is seeking a security engineer with proven experience identifying weaknesses and crafting creative solutions to eliminate those weaknesses at scale. We secure and harden the enterprise applications Meta runs on, both first-party and third-party, and we protect the sensitive data they hold. We don't just identify and help fix security vulnerabilities, we go beyond by preventing security problems before they exist.
Our scope includes securing how Meta adopts third-party AI applications and agentic workflows across the enterprise, a high-priority area with significant visibility across the company. You will be expected to collaborate technically with developers and engineers across large organizations, and you will be relied upon to provide application and infrastructure teams with the security expertise necessary to build the secure enterprise that underpins Meta.
Responsibilities
- Conceive, design, develop and improve effective security tooling, automation and/or frameworks that enable enterprise teams at scale to deliver applications and services with appropriate security controls to meet evolving requirements for security, privacy, and data protection
- Identify and eliminate classes of security problems by shifting detection and prevention left into the development workflow
- Provide just-in-time, actionable, technical security guidance to enterprise application and service teams through code reviews, penetration tests, adversarial testing, threat modeling, architecture design reviews, and other security activities
- Collaborate with cross-functional teams to ensure security work is being prioritized and addressed
- Design and build security controls and guardrails that allow the safe adoption of third-party AI applications and agentic workflows across the enterprise, including controls governing what automated systems can access and what data they can reach
- Protect sensitive and highly confidential data held in enterprise applications by building enforcement mechanisms that operate continuously and at scale
Minimum Qualifications
- B.S. or M.S in Computer Science, Engineering, or related technical discipline, or equivalent experience
- 2+ years of work experience developing production-level code in Python, PHP, Java, Ruby, Go, Rust, C/C++, or similar language
- 2+ years of work experience identifying and mitigating security issues in software (Python, PHP, Java, Ruby, Go, Rust, C/C++ or similar language) and knowledge of best practice secure code development
- Experience owning a particular component, feature or system
- Experience building and securing enterprise-scale software, services, and infrastructure
- Experience communicating technical security findings and recommendations in writing to technical and non-technical stakeholders
Preferred Qualifications
- Experience developing software that enables or evaluates security controls in complex systems
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Experience fixing enterprise security problems across broad corporate boundaries using influence and relationships
- Experience in designing, analyzing and conducting threat model assessments of enterprise software and services
- Experience in penetration testing or red team operations
- Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)
- Experience automating application security controls in large-scale enterprise environments
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Broad knowledge of the security domain, which may include security investigations, incident management, digital forensics, offensive security, vulnerability management, application security, and other security disciplines
$122,000/year to $181,000/year + bonus + equity + benefits
Similar roles
-
Senior Cybersecurity Analyst
Tlingit Haida Tribal Business Corporation Falls Church, Virginia, United States · $91K–$124K/yr
-
Compiler Security Engineer - C/C++, Languages & Runtimes
Apple Cupertino, California, United States
-
Application Security Engineer
Yum! United States · $107K–$146K/yr
-
Instructional Assistant (Cybersecurity)
Per Scholas Los Angeles, California, United States · $44K/yr
-
Security Engineer - Networking
Tapestry Mountain View, California, United States · $174K–$255K/yr
-
Cybersecurity Rotational Program - June 2027
Staples Business Framingham, Massachusetts, United States