Manager, Security Operations
Figma · San Francisco, CA • New York, NY • United States · Business Operations · listed June 5, 2026
The shape of it
Seniority
Manager
Experience asked
7+ years
Where
Not stated
Stated pay
$185,000 – $296,000 USD
Requirements listed
5
Length
997 words
In the posting’s own words
At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.
What it asks for · 5
- 7+ years of experience in security operations, incident response, or a related security engineering function
- Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms
- Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment
- Demonstrated success building, scaling, or significantly improving a detection and response program
- Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events
Also a plus
- Operated in a public company environment with SOX, ISO 27001, SOC 2, or FedRAMP requirements
- Applied AI risk management frameworks such as NIST AI RMF, OECD AI Principles, or ISO 42001
- Utilized AI-powered tools to automate security operations workflows and improve team efficiency
What the job covers
- Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement
- Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling
- Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity
- Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments
- Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps
- Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs
- Partner with Legal, Privacy, and Communications teams to support breach notification and regulatory response obligations during significant security incidents
- Drive security operations strategy through vendor management, operational metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction
Tools and skills named
Security & compliance
- Security15×
- IAM
- Regulatory
- Risk management
- SOC 2
Product & design
- Figma8×
Go to market
- SaaS
Operations & finance
- Vendor management
Ways of working
- Cross-functional
Words the posting leans on
- security15×
- response11×
- detection6×
- security operations6×
- experience4×
- incident response4×
- platform4×
- program4×
- workflows4×
- build3×
- design3×
- excited3×
- improve3×
- management3×
- soar3×
- automate security2×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Figma
- Account Executive, Emerging Enterprise (Berlin, Germany)Berlin, Germany
- Account Executive, EnterpriseSan Francisco, CA • New York, NY • United States
- Account Executive, Enterprise (Bengaluru, India)Bengaluru, India
- Account Executive, Enterprise (Berlin, Germany)Berlin, Germany
- Account Executive, Enterprise, Mandarin Speaking (Singapore)Singapore
- Account Executive, Enterprise (Paris, France)Paris, France