What are the responsibilities and job description for the Security Compliance Analyst III position at Meta?
Security Compliance Analyst
Job Description
BA/BS REQUIRED
Familiarity with compliance frameworks and regulatory requirements such as; NIST, ISO-2700, PCI Compliance, and other industry standards
Overview:
We are building a centralized and scalable controls management program within the Security Compliance team to support consistent risk identification and control validation across Meta. This team plays a critical role in ensuring our practices meet global regulatory expectations and effectively reduce risk across a dynamic, large-scale environment.
We are seeking a highly motivated and experienced Security Controls Testing Specialist to execute and evolve Meta’s control testing and management activities. The successful candidate will lead efforts to assess the design and operating effectiveness of key controls, identify areas for improvement, and contribute to the continuous advancement of our security posture. This role requires strong analytical skills, deep understanding of control frameworks, and the ability to collaborate with technical and non-technical teams in a fast-paced, global organization.
Ideal candidates will have a background in security audits, control assessments, or technical risk management, and a passion for driving meaningful improvements through structured, repeatable testing practices.
Responsibilities:
Plan, execute, and document testing of security controls to assess their design and operating effectiveness
Assist in the design and creation of new security controls
Define control testing scope, objectives, and procedures based on organizational risk and regulatory requirements
Conduct technical and procedural assessments across key control areas such as access management, data protection, logging/monitoring, and vulnerability management
Identify and document control observations/gaps, root causes, and potential risks
Collaborate with control owners to conduct walkthroughs, obtain evidence, and clarify control requirements
Evaluate technical evidence (e.g., configuration files, architecture diagrams, etc.) to determine areas of noncompliance or opportunities for improvement
Apply frameworks such as NIST 800-53, ISO 27001, and SOC 2 to evaluate control performance
Develop and maintain standardized testing templates, procedures, and reporting formats
Prepare detailed test results and control effectiveness reports for risk, compliance, and audit stakeholders
Support automation and continuous improvement of the control testing process
Stay current with emerging threats, regulatory changes, and security control best practices
Communicate findings clearly and professionally to both technical and non-technical stakeholders
Prepare and support the delivery of regular reporting on control testing results, trends, and risk insights for leadership and key stakeholders
Contribute to strategic initiatives that drive maturity, efficiency, and scalability of the security controls testing program
Minimum Qualifications:
BS or BA degree with 5+ years of experience in information security, cybersecurity, trust & safety, integrity, and/or other risk management, compliance, audit or assurance experience in a technology company
Familiarity with compliance frameworks and regulatory requirements such as; NIST, ISO-2700, PCI Compliance, and other industry standards
Experience conducting audits, control testing, compliance certifications or related compliance engagements
Communication experience, along with facilitation, analytical, leadership, delegation, and presentation skills.
Experience moving from strategy to execution and delivering tangible results.
Experience in consistently and effectively defending ideas and solutions.
Experience in effectively analyzing risk, compliance, and maturity within the context of business, and technology problems.
Problem solving and trouble-shooting experience.
Experience collaborating with multiple technical and non-technical teams to deliver successful programs / projects.
Foundation program management skills such as planning, organizing, pre-empting risks/blockers, communicating with stakeholders, to deliver successful programs / projects.
Preferred Qualifications:
Advanced degree and/or certification.
Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Los Angeles Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, qualified applicants will be considered for assignment with arrest and conviction records. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, meet client expectations, standards, and accompanying requirements, and safeguard business operations and company reputation.
This posting is for a contract assignment with Tundra Technical Solutions to provide services to Meta.
The pay range that Tundra in good faith reasonably expects to pay for this position is $42.91/hour - $53.64/hour.
Tundra’s benefits offering includes optional medical, dental, vision, retirement benefits, up to 15 Days PTO per annum and a New Child Benefit.
Tundra Technical Solutions is among North America’s leading providers of Staffing and Consulting Services. Our success and our clients’ success are built on a foundation of service excellence. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Unincorporated LA County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: client provided property, including hardware (both of which may include data) entrusted to you from theft, loss or damage; return all portable client computer hardware in your possession (including the data contained therein) upon completion of the assignment, and; maintain the confidentiality of client proprietary, confidential, or non-public information. In addition, job duties require access to secure and protected client information technology systems and related data security obligations.
The Meta CWX Program is enabled by a cutting-edge software platform called TalentNet that leads the contingent labor world for technology innovation. The software platform leverages Machine Learning and Artificial Intelligence to make sure the right people end up in the right job.
At Meta, we are constantly iterating, solving problems, and working together to connect people all over the world. That’s why it’s important that our workforce reflects the diversity of the people we serve. Hiring people with different backgrounds and points of view helps us make better decisions, build better products, and create better experiences for everyone.
We give people the power to build community and bring the world closer together. Our products empower more than 3 billion people around the world to share ideas, offer support, and make a difference.
This posting is for a contract assignment with Tundra Technical Solutions to provide services to Meta. Please note that this is not a full-time employment opportunity. Candidates selected for this role will be engaged as contractors for the specified duration of the project. For any inquiries regarding the terms of the contract or engagement, please contact Tundra Technical Solutions directly.
Salary : $43 - $54