Strategic Program Manager, Information Security
Figma's Information Security team is growing and looking for a Strategic Program Manager to drive strategic initiatives and engagement across the organization. This is a fast-moving role that will help build and mature security practices and partnerships across the organization, working closely with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business teams as a trusted security partner. You will work closely with security leadership to design programs, manage portfolios, and drive results that scale with our growing business. If you thrive on taking initiative, finding clarity in ambiguity, and driving impactful programs and relationships, we'd love to hear from you!
This is a full time role that can be held from one of our US hubs or remotely in the United States.
What you'll do at Figma:
Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams
Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans
Define and track security program metrics, OKRs, risk registers, and reporting that give leadership visibility into program health, priorities, and risk posture
Identify and coordinate the remediation of security gaps by partnering with control owners, security specialists, and business stakeholders to drive issues to resolution
Design and implement scalable security practices, including policies, processes, operating models, and change management plans that support long-term adoption
Drive security awareness and engagement through company-wide training, communications, and educational initiatives in partnership with teams across Figma
Support security leadership with strategic planning and portfolio management, including preparing leadership briefings, coordinating decisions, and driving follow-through on key commitments
We'd love to hear from you if you have:
5+ years of experience in security program management, security business partnership, or a related strategic role within information security
Demonstrated experience leading complex, cross-functional security programs from planning through execution, including developing program metrics, OKRs, risk registers, or dashboards that provide leadership visibility into performance and risk
Working knowledge of information security frameworks and practices, such as NIST CSF, SOC 2, ISO 27001, or equivalent frameworks
Demonstrated ability to communicate security risks, priorities, and tradeoffs to both technical and non-technical stakeholders, including senior leaders
Experience developing or delivering security initiatives that drive organizational adoption, such as security awareness, training, risk remediation, or change management initiatives
While it's not required, it's an added plus if you also have:
Experience supporting security or technical leadership in a chief of staff, business operations, or portfolio management capacity
Knowledge of enterprise or quantitative risk management practices, including methodologies such as FAIR
Experience with security and compliance requirements in a public company environment, including SOX ITGC, or with global regulatory frameworks such as GDPR or NIS2
Experience using AI, automation, or security tooling to improve reporting, information gathering, workflows, or decision-making
Security certifications such as CISA, CISSP, CISM, CRISC, or equivalent
At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.
Pay Transparency Disclosure
Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location.
Figma offers equity to employees, as well as a competitive package of additional benefits, including health, dental, and vision coverage; retirement benefits with company contributions; parental leave and reproductive or family planning support; mental health and wellness benefits; and paid time off. Figma provides paid sick leave, holidays, and other leave benefits in compliance with applicable federal, state, and local laws, including the requirements of the Washington Minimum Wage Act and related regulations. Exempt employees are eligible for employer‑provided paid flexible PTO in addition to flexible paid sick leave. PTO is subject to manager approval. Additional benefits may include company recharge days, cell phone and home internet reimbursements, and a number of lifestyle spending accounts. Figma also offers sales incentive compensation for most sales roles and an annual bonus plan for eligible non-sales roles. All compensation and benefits are subject to applicable plan terms and may be modified by Figma at any time, consistent with applicable law.
Annual Base Salary Range:
$169,000—$296,000 USD