Federal Compliance Manager

Figma · San Francisco, CA • New York, NY • United States · Business Operations · listed August 28, 2026

The shape of it

Seniority
Manager
Experience asked
5+ years
Where
Not stated
Stated pay
$153,000 – $245,000 USD
Requirements listed
5
Length
953 words

In the posting’s own words

As the Federal Compliance Manager, you will collaborate with internal stakeholders and product engineering teams to document and implement control requirements, ensuring adherence to Figma's FedRAMP cloud security standards. Responsibilities include supporting the analysis and remediation of security control implementation review, penetration testing, and vulnerability scan results as well as contributing to Plans of Action and Milestones (POAM) reporting for authorizing agencies.

What it asks for · 5

  • 5+ years of hands-on experience in IT auditing and/or compliance
  • Recent hands-on concentration of work with FedRAMP Framework
  • Previous experience leading a Cloud Service Provider through a FedRAMP ATO process
  • SaaS-based audit and compliance experience
  • Experience working with technologies hosted via cloud computing environments (e.g., AWS)

Also a plus

  • Understanding of security domains, including application security, infrastructure and cloud security, incident response, and security compliance and certifications
  • Hands-on experience with cloud computing technologies
  • Established connections in the FedRAMP industry and with various government agencies
  • Familiarity with other international regulatory compliance

What the job covers

  • Engage with cross-functional collaborators across legal, sales, product/enterprise teams, 3PAO, sponsoring agency, and FedRAMP PMO
  • Analyze information from disparate teams to tackle complex issues, manage risks, and resolve problems
  • Assist in analyzing and preparing for both internal and external audits
  • Identify and escalate technical and program risks to relevant stakeholders, tracking resolution through to closure
  • Collaborate on developing automated capabilities for evidence collection, control validation, and process execution
  • Maintain technical documentation (e.g., System Security Plan or SSP) with expertise in security controls, audits, technical architecture, operational processes, and security protocols
  • Guide internal teams on FedRAMP and security framework implementation, flagging downstream impacts to product roadmaps and organizational processes
  • Identify and communicate specific security and configuration requirements to cloud, application, and enterprise teams

Tools and skills named

Security & compliance
  • Security13×
  • Audit2×
  • Regulatory2×
  • Penetration testing
Product & design
  • Figma6×
Ways of working
  • Cross-functional
  • Technical writing
  • Testing
Cloud & infra
  • AWS
Go to market
  • SaaS

Words the posting leans on

  • security13×
  • cloud6×
  • experience6×
  • fedramp6×
  • compliance5×
  • control4×
  • audits3×
  • design3×
  • excited3×
  • internal3×
  • product3×
  • technical3×
  • agencies2×
  • cloud computing2×
  • cloud security2×
  • collaborate2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Figma

every open role at Figma

How this page was made

An automated read of a public job posting, fetched August 30, 2026 and last changed by Figma on August 28, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.