Security Engineer, Identity and Access Management (IAM)
Meta
**Summary:**
Facebook's security team is the central engine driving data and systems security at the company, supporting Facebook and all of its family of apps. The organization is responsible for preventing malicious actors from compromising our environment, detecting and responding to them before they do damage if they do, ensuring we are maintaining the protections we say we will, and engaging with the community to help those outside the company learn from the work we do. We work across all parts of the company, from the corporate infrastructure to production to external services, interfacing with nearly every team in the company.The Security Engineer should have prior experience with security policy, risk, and access management disciplines and be experienced in collaborating with cross-functional teams. This position will be responsible for identifying and enforcing solutions to control access to internal systems. An ideal candidate is someone that has technical knowledge of the broad aspects of information security, and is able to identify deficiencies in the access management space. This role specifically needs thorough conceptual understanding of the IAM concepts that can be applied to our internal IAM solutions. This role requires a broad mix of security, technical, coding and communication skills coupled with a inherent desire to learn. Some travel may be required.
**Required Skills:**
Security Engineer, Identity and Access Management (IAM) Responsibilities:
1. Design and implement systems that enhance the security of Facebook’s Identity & Access Management Systems
2. Build and maintain tools that improve the Identity and Access Management posture at Meta
3. Conduct design and code reviews Analyze and improve efficiency, scalability, and stability for assigned product area and/or systems
4. Identify and drive changes as needed for assigned codebase, product area and/or systems
5. Interface with other teams to incorporate their innovations and vice versa
6. Articulate security findings to internal to a variety of stakeholders, including both technical and non-technical stakeholders
7. Provide defensible recommendations on technical, physical and administrative control implementations based on findings while balancing the cost versus benefits
8. Participate in the development and oversight of corrective actions relating to security issues
9. Participate in cross-functional, team, and status review meetings
10. Recommend process improvement and strategic initiatives as related to security
**Minimum Qualifications:**
Minimum Qualifications:
11. Experience in writing custom scripts in Python/C++ and PHP/Hack
12. BSc in Computer Science related field, or equivalent experience
13. Experience building large-scale distributed systems or similar experience
14. 5+ years of software development experience
15. Experience in assessing security deficiencies in first-party/internal information systems and recommending mitigating controls
16. 5+ years of proven experience working on Information Security teams or conducting Information Security consulting engagements
17. Knowledge of evaluating systems architectural designs, data-flow diagrams and technical security implementations, particularly in context of access management in different geographical locations
18. Experience with developing security reporting and recommendations that are meaningful, defensible and actionable for a variety of audiences
19. Able of managing competing priorities and simultaneous projects in a fast paced environment with little supervision
20. Great communication skills - both written and verbal, interpersonal skills, and able of working cross-functionally with various teams
**Preferred Qualifications:**
Preferred Qualifications:
21. Good grasp of SOX, SOC2, NIST, PCI, ISO, and other security regulations
22. Demonstrated experience in analytical and problem-solving skills, including a basic understanding of data analysis techniques
23. Experience in the IAM domain in a cloud based infrastructure environment
24. Program and project management skills
**Industry:** Internet
Confirmar seu email: Enviar Email
Todos os Empregos de Meta