Manager, Security Operations

Figma · San Francisco, CA • New York, NY • United States · Business Operations · listed June 5, 2026

The shape of it

Seniority
Manager
Experience asked
7+ years
Where
Not stated
Stated pay
$185,000 – $296,000 USD
Requirements listed
5
Length
997 words

In the posting’s own words

At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.

What it asks for · 5

  • 7+ years of experience in security operations, incident response, or a related security engineering function
  • Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms
  • Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment
  • Demonstrated success building, scaling, or significantly improving a detection and response program
  • Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events

Also a plus

  • Operated in a public company environment with SOX, ISO 27001, SOC 2, or FedRAMP requirements
  • Applied AI risk management frameworks such as NIST AI RMF, OECD AI Principles, or ISO 42001
  • Utilized AI-powered tools to automate security operations workflows and improve team efficiency

What the job covers

  • Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement
  • Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling
  • Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity
  • Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments
  • Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps
  • Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs
  • Partner with Legal, Privacy, and Communications teams to support breach notification and regulatory response obligations during significant security incidents
  • Drive security operations strategy through vendor management, operational metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction

Tools and skills named

Security & compliance
  • Security15×
  • IAM
  • Regulatory
  • Risk management
  • SOC 2
Product & design
  • Figma8×
Go to market
  • SaaS
Operations & finance
  • Vendor management
Ways of working
  • Cross-functional

Words the posting leans on

  • security15×
  • response11×
  • detection6×
  • security operations6×
  • experience4×
  • incident response4×
  • platform4×
  • program4×
  • workflows4×
  • build3×
  • design3×
  • excited3×
  • improve3×
  • management3×
  • soar3×
  • automate security2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Figma

every open role at Figma

How this page was made

An automated read of a public job posting, fetched August 30, 2026 and last changed by Figma on July 22, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.