Security Policy and Compliance Analyst

Facebook is seeking an experienced Security Policy and Compliance Analyst to join our team. This position will be responsible for understanding and supporting the design Facebook’s organizational, procedural and technological security controls within the context of the global regulatory frameworks applicable to our business. The position will also help codify these controls in supporting documentation and explain them to internal and external stakeholders. The Security Policy and Compliance Analyst will be someone that has a passion for implementing innovative security controls that mitigate risk to the company, empower Facebook’s culture of rapid innovation, and help demonstrate Facebook’s dedication to security to the world. This role requires a mix of broad, business and technical acumen, the ability to inspire and influence decisions pertaining to regulatory standards, and a polished ability to communicate with key internal stakeholders.
Security Policy and Compliance Analyst Responsibilities
  • Help demonstrate Facebook’s commitment to security to external stakeholders
  • Understand technical implementation details necessary to identify and assess security risks and recommend mitigating controls
  • Participate in the development and oversight of required corrective action plans relating to security compliance issues
  • Support business relationships with the internal and external security auditors and regulators
  • Identify, research and evaluate new compliance requirements and ensure they are incorporated into Facebook’s security policy framework
  • Support the communication of policies, procedures, and plans to internal stakeholders regarding security and compliance best practices around applicable laws, regulations and controls
  • Support the identification, validation and remediation of information technology controls required by Irish Data Protection Act, Federal Trade Commission, Sarbanes-Oxley, Payment Cardholder Information Data Security Standards (PCI DSS), regulations governing personally identifiable information (PII), and other applicable regulatory compliance frameworks
  • Data Security Standards (PCI DSS), regulations governing personally identifiable information (PII), SOC2 and SOC3 trust principles, and other applicable regulatory compliance frameworks
  • Partner with internal teams to ensure successful security programs that align with compliance requirements
  • Understand the security needs of internal and external stakeholders around external business partners and maintain a process that meets stakeholder needs
  • Manage daily activities and functions of the external business partner management program
  • Coordinate and drive business partner security assessment activities for both inbound and outbound relationships
  • Lead assessments of business partner security risk, develop mitigation plans, and work with internal stakeholders to assign monitoring responsibility. Prepare and complete annual risk assessments and assist with regulatory and accreditation audit preparation as needed
  • Support business partner selection on significant sourcing decisions and reassess security risk for business partners prior to contract renewals
Minimum Qualifications
  • 2+ years experience in information security compliance
  • 2+ years experience supporting compliance programs within the technology space
  • 2+ years experience in security controls across all security domains such as access management, encryption methods, vulnerability management, network security, etc.
Preferred Qualifications
  • In-depth experience of data security frameworks and regulatory standards, including PCI, GAPP, SSAE16-SOC2, ISO27001/2, and SOX
  • Proven communication skills
  • Experience with developing security and compliance reporting for a variety of audiences, including executive management
  • Demonstrated leadership skills with experience working effectively across various levels
  • Experience developing and submitting audit and compliance reports to governing bodies, legal entities, and/or external authorities
  • Experienced in processes for assessing and designing internal controls for large scale organizations
  • Experience assessing security risk for large scale organizations. Specific experience in cloud services organizations
  • Certifications in one or more of the following areas preferred: CISSP, CISA, CISM, GISO, GCIH, CIPP
  • Bachelors in business/technology
About the Facebook company
Facebook’s mission is to give people the power to build community and bring the world closer together. Through our family of apps and services, we’re building a different kind of company that connects billions of people around the world, gives them ways to share what matters most to them, and helps bring people closer together. Whether we’re creating new products or helping a small business expand its reach, people at Facebook are builders at heart. Our global teams are constantly iterating, solving problems, and working together to empower people around the world to build community and connect in meaningful ways. Together, we can help people build stronger communities — we’re just getting started.
Facebook is committed to providing reasonable support (called accommodations) in our recruiting processes for candidates with disabilities, long term conditions, mental health conditions or who are neurodivergent, and to candidates with sincerely held religious beliefs or requiring pregnancy related support. If you need support, please reach out to
(Colorado only*) Minimum salary of $135,000/year + bonus + equity + benefits
*Note: Disclosure as required by sb19-085(8-5-20)

More Information

Apply for this job

Leave your thoughts

Share this job