Description
Figma is growing our team of creatives and builders on a mission to make design accessible to all.
Figma’s Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across the organization.
This is a fast-moving role that will help build and mature security practices and partnerships across the organization, working closely with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business teams as a trusted security partner.
Responsibilities
- Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams
- Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans
- Define and track security program metrics, OKRs, risk registers, and reporting that give leadership visibility into program health, priorities, and risk posture
- Identify and coordinate the remediation of security gaps by partnering with control owners, security specialists, and business stakeholders to drive issues to resolution
- Design and implement scalable security practices, including policies, processes, operating models, and change management plans that support long-term adoption
- Drive security awareness and engagement through company-wide training, communications, and educational initiatives in partnership with teams across Figma
- Support security leadership with strategic planning and portfolio management, including preparing leadership briefings, coordinating decisions, and driving follow-through on key commitments
Requirements
- 5+ years of experience in security program management, security business partnership, or a related strategic role within information security
- Demonstrated experience leading complex, cross-functional security programs from planning through execution, including developing program metrics, OKRs, risk registers, or dashboards that provide leadership visibility into performance and risk
- Working knowledge of information security frameworks and practices, such as NIST CSF, SOC 2, ISO 27001, or equivalent frameworks
- Demonstrated ability to communicate security risks, priorities, and tradeoffs to both technical and non-technical stakeholders, including senior leaders
- Experience developing or delivering security initiatives that drive organizational adoption, such as security awareness, training, risk remediation, or change management initiatives
Nice to Have
- Experience supporting security or technical leadership in a chief of staff, business operations, or portfolio management capacity
- Knowledge of enterprise or quantitative risk management practices, including methodologies such as FAIR
- Experience with security and compliance requirements in a public company environment, including SOX ITGC, or with global regulatory frameworks such as GDPR or NIS2
- Experience using AI, automation, or security tooling to improve reporting, information gathering, workflows, or decision-making
- Security certifications such as CISA, CISSP, CISM, CRISC, or equivalent
Benefits
- Health, dental, and vision coverage
- Retirement benefits with company contributions
- Parental leave and reproductive or family planning support
- Mental health and wellness benefits
- Paid time off
- Company recharge days
- Cell phone and home internet reimbursements
- Lifestyle spending accounts
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/figma/jobs/6144522004