Cloud Security GRC Specialist
Meta's Security Governance, Risk and Compliance function (Security GRC) serves as the primary hub for Security risk management and compliance across the company, providing support to Meta and its family of apps. Within Security GRC, the Cloud Security GRC function is a horizontal capability providing guidance and direction to first line teams in making Meta's Cloud platforms secure, available and compliant.At Meta, we understand the significance of security, data protection, and privacy for the billions of people who use our services. We are committed to ensuring compliance with applicable laws and regulations such as the General Data Protection Regulation (GDPR), the European Electronic Communications Code (EECC), the Network and Information Security Directive (NIS2), and others, while enabling the business to rapidly and securely use appropriate Cloud solutions.We are currently seeking highly experienced and motivated information security professionals to join our Cloud Security Function to continue to develop Cloud Security GRC capabilities. This role is critical in driving change and ensuring compliance with these and other obligations. As part of this role, you will collaborate closely with engineers, analysts, technical program managers, business stakeholders, legal teams, and risk & compliance teams across the Meta organization.You will bring a comprehensive understanding of various aspects of information security and the ability to apply this knowledge to solve problems at scale. This role demands a blend of business and technical acumen, proven communication skills, and a keen desire to learn.Our goal is to make Meta the premier place to work for governance, risk, compliance, security, and integrity professionals.
Cloud Security GRC Specialist Responsibilities:
- Lead significant programs of work across various levels of cross-functional (XFN) teams in Cloud Security and Cloud GRC areas
- Collaborate with team members and stakeholders to understand or identify defined work problems and program goals, obtain prioritized deliverables, and discuss program impact
- Design, implement, and/or assess security controls and frameworks
- Implement maturity frameworks across multiple programs factoring in emerging regulations and proactive detection of risks
- Assess and document emerging regulatory impact on established policy and control frameworks
- Identify, communicate, and collaborate with relevant stakeholders within one or more teams to drive impact and work toward mutual goals
- Establish learnings, best practices, standardized frameworks and tools across GRC and related teams
- Develop detailed program/project plans in partnership with cross-functional teams
- Identify opportunities for information sharing, process improvement and automation
- Support business travel on an as needed basis (up to 10%)
Want more jobs like this?
Get jobs in Washington, DC delivered to your inbox every week.

- 7+ years experience in information security and/or technology risk including one or more domains (e.g., access management, vulnerability management, change management, business continuity, application security, asset management)
- Demonstrable familiarity with key Cloud Security, Risk Management and Compliance concepts
- 4+ years of experience in hands on security, with at least one of the major CSPs (AWS, GCP, Azure)
- Experience in a GRC function overseeing Cloud implementations at scale
- Experience in designing and implementing control frameworks
- Experience in assessing security deficiencies in information systems and recommending mitigating controls in a corporate environment
- Familiarity with compliance frameworks and regulatory requirements such as NIST, CSA CCM, ISO-27001, ISO27018, SOC2, GDPR, EECC, eDP, NIS2, and other relevant structures
- Bachelor's Degree in Computer Science, Information Systems, Engineering, Cybersecurity or related field or equivalent experience
- Security industry qualification (CISSP, CISM, CISA or similar)
- Cloud-specific Cloud Certifications (CCSP, AWS Certified Security Specialist, CCSK, etc.)
- Master's Degree in Computer Science, Information Systems, Engineering, Cybersecurity or related field
Meta builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. People who choose to build their careers by building with us at Meta help shape a future that will take us beyond what digital connection makes possible today-beyond the constraints of screens, the limits of distance, and even the rules of physics.
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
$153,000/year to $209,000/year + bonus + equity + benefits
Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate, monthly rate, or annual salary only, and do not include bonus, equity or sales incentives, if applicable. In addition to base compensation, Meta offers benefits. Learn more about benefits at Meta.
Perks and Benefits
Health and Wellness
- Health Insurance
- Health Reimbursement Account
- Dental Insurance
- Vision Insurance
- Life Insurance
- Short-Term Disability
- Long-Term Disability
- FSA
- FSA With Employer Contribution
- HSA
- HSA With Employer Contribution
- Fitness Subsidies
- On-Site Gym
- Mental Health Benefits
Parental Benefits
- Birth Parent or Maternity Leave
- Non-Birth Parent or Paternity Leave
- Fertility Benefits
- Adoption Assistance Program
- Family Support Resources
Work Flexibility
- Flexible Work Hours
- Remote Work Opportunities
- Hybrid Work Opportunities
Office Life and Perks
- Commuter Benefits Program
- Casual Dress
- Happy Hours
- Snacks
- Some Meals Provided
- Company Outings
- On-Site Cafeteria
- Holiday Events
Vacation and Time Off
- Paid Vacation
- Unlimited Paid Time Off
- Paid Holidays
- Personal/Sick Days
- Sabbatical
- Leave of Absence
Financial and Retirement
- 401(K)
- 401(K) With Company Matching
- Pension
- Company Equity
- Performance Bonus
- Relocation Assistance
- Financial Counseling
Professional Development
- Learning and Development Stipend
- Promote From Within
- Mentor Program
- Shadowing Opportunities
- Access to Online Courses
- Lunch and Learns
- Internship Program
Diversity and Inclusion
Company Videos
Hear directly from employees about what it is like to work at Meta.