Enterprise Application Security Engineer (Builder)
Job Description
Meta’s Enterprise Application Security team is building security tooling and automation that helps enterprise teams deliver applications and services with strong security, privacy, and data protection controls. As an Enterprise Application Security Engineer (Builder), you will help shift security detection and prevention earlier in the development lifecycle and establish guardrails that enable safe adoption of third-party AI applications and agentic workflows.
This onsite role is based in New York, NY and supports enterprise-scale delivery by designing controls that protect sensitive data continuously and at scale.
What you’ll do
- Conceive, design, develop, and improve security tooling, automation, and/or frameworks that enable enterprise teams at scale to ship applications and services with security controls aligned to evolving security, privacy, and data protection requirements
- Identify and eliminate recurring security problem classes by shifting detection and prevention left into development workflows
- Deliver just-in-time, actionable security guidance to enterprise application and service teams through activities such as code reviews, penetration tests, adversarial testing, threat modeling, and architecture design reviews
- Work with cross-functional teams to ensure security priorities are addressed and kept on track
- Design and build security controls and guardrails for safe enterprise adoption of third-party AI applications and agentic workflows, including controls that govern what automated systems can access and what data they can reach
- Build enforcement mechanisms that protect sensitive and highly confidential data stored in enterprise applications, operating continuously and at scale
Minimum qualifications
- B.S. or M.S. in Computer Science, Engineering, or a related technical discipline (or equivalent experience)
- 2+ years of experience developing production-level code in Python, PHP, Java, Ruby, Go, Rust, C/C++, or a similar language
- 2+ years of experience identifying and mitigating software security issues using Python, PHP, Java, Ruby, Go, Rust, C/C++, or a similar language, along with knowledge of best-practice secure code development
- Experience owning a component, feature, or system
- Experience building and securing enterprise-scale software, services, and infrastructure
- Experience communicating technical security findings and recommendations in writing to both technical and non-technical stakeholders
Technologies
- Python
- PHP
- Java
- Ruby
- Go
- Rust
- C/C++
Compensation and benefits
- $122,000/year to $181,000/year + bonus + equity + benefits
- Meta offers benefits
Preferred qualifications
- Experience developing software that enables or evaluates security controls in complex systems
- Demonstrated ability to integrate AI tools to optimize or redesign workflows and drive measurable impact (such as efficiency gains or quality improvements)
- Demonstrated ongoing AI skill development (such as prompt or context engineering, agent orchestration) and staying current with emerging AI technologies
- Experience fixing enterprise security problems across broad corporate boundaries using influence and relationships
- Experience designing, analyzing, and conducting threat model assessments of enterprise software and services
- Experience in penetration testing or red team operations
- Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)
- Experience automating application security controls in large-scale enterprise environments
- Experience adhering to and implementing responsible, ethical AI practices (such as risk assessment, bias mitigation, quality and accuracy reviews)
- Broad knowledge of the security domain, including security investigations, incident management, digital forensics, offensive security, vulnerability management, application security, and other security disciplines
Similar Jobs
A