Own program financials and resourcing, and drive the strategy for automation and AI that scales assessment throughput without compromising defensibility.15+ years of experience in security risk management, technology risk, GRC, or a directly related discipline 8+ years of experience managing and developing teams, including experience managing managers or senior individual contributors with demonstrated progression into organizational leadership Demonstrated experience attracting talent, developing leadership pipelines, managing org health through growth or change Demonstrated experience owning a security or technology risk program end-to-end across multiple organizations, including methodology, operations, and reporting Demonstrated experience partnering with and presenting to executive leadership to shape organizational strategy, influence technical roadmaps, drive XFN alignment Experience partnering directly with a Central Security or infrastructure security organizations and engineering leaders as a second-line risk function Experience delivering assessments or reporting against external regulatory or certification regimes (e.g., EU regulatory frameworks, SOC 2, HIPAA, FDA, US Government requirements) Demonstrated experience with risk assessment and capability maturity frameworks (e.g., NIST CSF, CMMI, ISO 27001, FAIR or comparable quantification approaches) Experience building a risk assessment capability for AI systems, including AI-specific regulatory regimes (EU AI Act) or emerging AI risk frameworks Experience integrating first-line and second-line risk responsibilities, or consolidating risk functions across domains Experience embedding risk review into a fast-moving product development lifecycle Experience with quantitative risk modeling and unified risk quantification at enterprise scale Experience with cloud security risk governance in a large multi-cloud environment Experience applying automation and AI tooling to scale GRC operations Experience managing program resourcing, budget, and vendor or contingent workforce delivery Familiarity with EU regulatory frameworks including GDPR/DPIA, RED, DORA, NIS2, or the Cyber Resilience Act Relevant certifications (CISSP, CRISC, CISM, CISA) or an advanced degree in a related fieldMeta builds technologies that help people connect, find communities, and grow businesses. Serve as the program's primary partner to Central Security leadership, driving a unified approach to security risk management (tooling, process, and methodology), including absorbing in-flight work from 1LOD into the second line: negotiating scope, sequencing, and integration decisions, and establishing clear risk coverage ownership across the lines of defense.