Meta Security Engineering Manager (M1) Interview Experience
Meta · Engineering Manager
I was a little complacent because I’m already ex-Meta, and the surprising feedback was that my project retrospective was only leaning toward hire because I answered a constructive feedback question like they were asking for praise. I cleared the loop, discussed numbers and joining date, and then the offer got put on hold because of the hiring freeze.
Interview process
I first cleared the loop for a different Meta EM role and, while I was waiting in team matching, they opened an M1 security role and asked me to do the delta interviews for that. For the security path, the structure was recruiter screen, two technical screens, and then a six-round final loop covering security system design, security depth, coding, career motivation, people management, and project retrospective. The technical rounds were not the hardest part for me because the coding was pretty easy and the design rounds were very framework-driven. The rounds that mattered most were people management and project retrospective, and I actually got more push there because the examples had to map cleanly to the signal. I cleared the loop, and am waiting on next steps.
Interview rounds · 3
- 1
Recruiter screen
BehavioralThe recruiter call felt like a fit and red-flag screen, not a commercial conversation. I was not asked about money at all. It was mostly about whether Meta was actually a real match for how I like to work.
Q1. Why do you want to join Meta, and what actually motivates you about it?
How they answeredI framed my answer around intrinsic motivation, not perks or comp. I talked about liking fast-moving, ambiguous environments and working across a lot of teams, because that is very Meta. I also walked through the kinds of projects I had led so they could see the transferable management and technical judgment. My read was they were screening for obvious red signals and for whether I would actually fit the culture.
Follow-up questions- How do you work in ambiguity and with a lot of cross-team collaboration?
- What projects have you done that show transferable skills for this role?
- 2
Phone screen
CodingSystem DesignTechnicalBefore the loop I had the standard two technical screens. One was coding and one was system design. My sense was they were checking whether I had enough signal to go into the full loop, and at Meta these two screens are standard for EMs.
Q1. Solve two easy coding problems in CoderPad.
How they answeredThe coding screen was LeetCode-easy level, not graphs or trees. It was in the two-sum, three-sum, simple cipher kind of category. They cared less about trickiness and more about whether I could understand it fast, code cleanly, and talk through unit tests and corner cases. The bar felt like having the right framework and coding mindset rather than doing something super algorithmically hard.
Follow-up questions- What edge cases would you test?
Q2. How would you design security for something like Stripe?
How they answeredI treated it as a security design and threat-modeling discussion, not a generic architecture round. I broke the system into components, mapped likely threats using STRIDE, and then talked through the protections I would put around each area. After that I extended it to Meta scale, which is where they wanted to see whether I could think beyond a textbook answer. The interviewer seemed to care that I could connect a real framework to a real system.
Follow-up questions- What threats would you model with STRIDE?
- How would you protect against those threats?
- How would you scale it to Meta scale?
- 3
Final / onsite round
System DesignTechnicalCodingBehavioralPeople ManagementProject ManagementCross-FunctionalThe final loop was six 45-minute rounds: security system design, security domain knowledge, coding, career and experience behavioral, people management, and project retrospective. Since it was a security EM loop, Meta kept the common EM lenses like coding and design but added niche security depth. The technical parts were manageable. The rounds that really needed prep were project retrospective and people management because they were very signal-driven and the examples had to match the question exactly.
Q1. Assume you are building an e-commerce site like Amazon. What security threats do you see, and how would you handle them?
How they answeredI approached it by listing the major components first, then doing threat modeling across them. I used STRIDE to organize the threats instead of free-styling, and then I mapped concrete protections to each area. The important part was showing I could think through real attack surfaces, not just say generic security words. Once that was clear, I expanded the design for Meta scale, where the interviewer wanted to see whether the controls and architecture would still hold up.
Follow-up questions- How would you apply STRIDE to that design?
- How would this change at Meta scale?
Q2. If you were building facebook.com, how would you define identity and access management for it?
How they answeredI answered it as an open-ended domain-depth question. I talked through identity and access management as a core production control, then expanded into how I would handle incidents when something goes wrong. The point was to show depth, process awareness, and judgment in a very broad scenario. My read was that they wanted to see whether I had real domain experience and could operate through multiple lenses, not just recite best practices.
Follow-up questions- How would you handle security incidents and incident response in a cloud production environment?
Q3. Solve a variant of 3Sum.
How they answeredThe final coding round had two easy questions in a short window, basically around 30 to 35 minutes total before leaving time for Q&A. One of mine was a different version of 3Sum. I coded quickly in CoderPad, then the interviewer pushed on corner cases like all zeros or odd inputs, and in my case also asked me to check a compilation issue. They do expect you to talk through tests and cardinal cases, not just write the happy-path code.
Follow-up questions- What happens if all the values are zero?
- What happens on null or empty input?
- Can you check why this is not compiling?
Q4. What are you doing now, what is exciting about it, and why Meta?
How they answeredThis round was really about intrinsic motivation. I made sure my answer was not about free food or money. I talked about what genuinely excites me in the work and tied that to Meta's scale and mission, especially the idea of building things that help communities and groups. My sense was they were checking whether I would still care about the work itself once I joined, not whether I could say the company was impressive.
Follow-up questions- If you could change something that is not working, what would you change?
Q5. Tell me about a time you really screwed up with a team.
How they answeredThis was the curveball in people management. The interviewer explicitly said to treat it as a curveball and asked for a real example where I had screwed up. I was caught off guard and needed time to think, because it is much harder than giving a polished leadership story. The signal they were probing was humility, transparency, and whether I can openly accept mistakes, learn from them, and not get defensive.
Follow-up questions- How did it impact execution?
- What did you learn from it?
Q6. How do you handle low performers and high performers?
How they answeredFor low performers, I said I first try to understand the real reason for the performance issue, then give direct feedback, support, and a fair chance to improve. If it still is not working, I said sometimes separation is best for the individual, team, and company, and I can speak to that process directly. For high performers, I said the answer is not just giving them more work. I gave an example of giving a strong engineer bigger-scope challenges that actually motivated them instead of burning them out.
Follow-up questions- Tell me about a turnaround case.
- Tell me about a case where you had to let someone go.
- How do you motivate a high performer without burning them out?
Q7. Tell me about a project you led and how you defined success.
How they answeredIn project retrospective, the interviewer cared a lot about whether I could connect the project to company goals and define success clearly. I talked about setting explicit metrics, knowing how to monitor them, and not waiting six months to find out whether the project worked. I also explained how I would break a large project into smaller cadences like two-week sprints and manage dependencies and stakeholders across teams. That round was really about execution discipline, not storytelling style.
Follow-up questions- How did you align the project with company objectives?
- What metrics did you define and how did you monitor them?
- How did you break the work into execution cadences?
- How did you manage stakeholder communication and dependencies?
Q8. Tell me about a project where you got constructive feedback.
How they answeredThis is the one where I fumbled a bit. I did not listen carefully enough and I answered it more like a question about praise, when the interviewer was actually asking about criticism. The recruiter later told me that came through in the feedback, and I agreed with it. My hindsight is that this round is very signal-specific, so you have to listen to the wording carefully and choose the exact example that matches the lens they are testing.
Follow-up questions- What would you have done differently?
Tips from the candidate
I would definitely prep coding and system design, but I would not over-index on them just because they feel more concrete. For this loop, I would spend real time mapping stories to signals for project retrospective and people management, especially metrics, stakeholder communication, constructive feedback, low performers, high performers, and times I genuinely messed up. I would also listen very carefully to the wording of the question, because I lost signal once by answering praise when they were actually asking for criticism. If I had to give one simple piece of advice, it is this: go in with crisp examples and do not assume your general experience will carry you.
Company culture
My biggest Meta-specific read is that they are still extremely signal-driven. For EMs, they care a lot more than people assume about cultural fit, project execution, and people management, not just coding and system design. In security, they also add extra domain rounds because they do not treat it like a generic EM hire. Process-wise, they have changed from the old bootcamp model to team matching before offer, and my understanding is that the old bootcamp could take 6 to 8 weeks and they were effectively paying candidates during that period. Also, headcount feels real tight right now because I was through the loop, had positive feedback, and still haven't gotten an offer.