Strategic Program Manager, Information Security

Figma · San Francisco, CA • New York, NY • United States · Business Operations · listed August 19, 2026

The shape of it

Seniority
Manager
Experience asked
5+ years
Where
Not stated
Stated pay
$169,000 – $296,000 USD
Requirements listed
5
Length
1,028 words

In the posting’s own words

To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding.

What it asks for · 5

  • 5+ years of experience in security program management, security business partnership, or a related strategic role within information security
  • Demonstrated experience leading complex, cross-functional security programs from planning through execution, including developing program metrics, OKRs, risk registers, or dashboards that provide leadership visibility into performance and risk
  • Working knowledge of information security frameworks and practices, such as NIST CSF, SOC 2, ISO 27001, or equivalent frameworks
  • Demonstrated ability to communicate security risks, priorities, and tradeoffs to both technical and non-technical stakeholders, including senior leaders
  • Experience developing or delivering security initiatives that drive organizational adoption, such as security awareness, training, risk remediation, or change management initiatives

Also a plus

  • Experience supporting security or technical leadership in a chief of staff, business operations, or portfolio management capacity
  • Knowledge of enterprise or quantitative risk management practices, including methodologies such as FAIR
  • Experience with security and compliance requirements in a public company environment, including SOX ITGC, or with global regulatory frameworks such as GDPR or NIS2
  • Experience using AI, automation, or security tooling to improve reporting, information gathering, workflows, or decision-making
  • Security certifications such as CISA, CISSP, CISM, CRISC, or equivalent

What the job covers

  • Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams
  • Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans
  • Define and track security program metrics, OKRs, risk registers, and reporting that give leadership visibility into program health, priorities, and risk posture
  • Identify and coordinate the remediation of security gaps by partnering with control owners, security specialists, and business stakeholders to drive issues to resolution
  • Design and implement scalable security practices, including policies, processes, operating models, and change management plans that support long-term adoption
  • Drive security awareness and engagement through company-wide training, communications, and educational initiatives in partnership with teams across Figma
  • Support security leadership with strategic planning and portfolio management, including preparing leadership briefings, coordinating decisions, and driving follow-through on key commitments

Tools and skills named

Security & compliance
  • Security31×
  • Audit
  • GDPR
  • Regulatory
  • Risk management
  • SOC 2
Product & design
  • Figma7×
Operations & finance
  • Program management2×
Go to market
  • Partnerships
Ways of working
  • Cross-functional

Words the posting leans on

  • security28×
  • program9×
  • risk9×
  • business6×
  • experience6×
  • leadership6×
  • management6×
  • design5×
  • drive5×
  • initiatives5×
  • strategic5×
  • practices4×
  • priorities4×
  • frameworks3×
  • growing3×
  • information security3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Figma

every open role at Figma

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Figma on August 19, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.