Meta Security is looking for Security Engineer Interns with experience in threat modeling, TTP identification, and detection engineering. You'll work alongside Security Analysts, Software Engineers and Offensive Security Engineers to identify critical assets, assess the top risks, and evaluate and detect potential internal and external attacks against Meta systems. You will be working across engineering teams supporting Production and Corporate systems to develop detection and response automation leveraging both industry-standard and custom detection and response platforms. You'll generate detection ideas and implementations utilizing some of the world's largest datasets and build on top of hyper-scale data pipelines. This internship, starting Summer 2026, offers a wealth of challenging and technically stimulating security problems. We encourage self-starters and passionate security enthusiasts to apply and contribute to our mission.
Teams You May Join:
Work in cross-functional projects to improve our capabilities to effectively detect and respond to security incidents
Review security architecture of large-scale custom and commercial systems and independently propose logging, detection and prevention controls
Perform TTP-based Threat Modeling for a wide variety of assets including endpoints, mobile, servers, internal services, public & private cloud environments and networking equipment
Perform analysis against logs from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential threats and detection ideas
Build response workflows and actions that auto-resolve false positives and provide context scaling our ability to investigate
Support security incident response in a cross-functional environment and drive incident resolution for internal and external threats
Design and implement attack testing automation to validate detection coverage
Build logging pipelines using our custom datasets and infrastructure
Track threat clusters posing threats to Meta's infrastructure and employees
Improve the tooling of threat cluster tracking and intelligence data integration to existing systems and various intelligence feeds