Technical Program Manager, Security
Job description
About the role
Figma is on the lookout for a Technical Program Manager to bolster its Security Operations team. In this role, you will oversee cross-departmental initiatives aimed at enhancing the security posture of the organization while effectively managing risk. Your focus will be on establishing scalable operational practices that can adapt to the evolving security landscape. You will own the end-to-end execution of security and compliance initiatives, ensuring that critical milestones are met, risks are proactively identified, and status is communicated with clarity and precision. This position requires you to spearhead cross-functional projects by facilitating deep technical discussions and aligning security, engineering, and product teams toward shared objectives. You will cultivate strategic partnerships across the organization to drive favorable security outcomes and foster a pervasive culture of security awareness. Furthermore, you will define, refine, and enhance internal workflows and collaboration practices to improve efficiency, effectiveness, and overall program health. Ultimately, you will articulate complex security risks and technical trade-offs to a diverse array of stakeholders, ensuring that all parties achieve a clear understanding and can participate in informed decision-making processes.
Key facts
What you'll do
- Oversee the complete execution of security, compliance, and infrastructure projects, ensuring that milestones are met, risks are identified, and progress is reported effectively.
- Spearhead cross-functional projects by facilitating technical discussions and ensuring alignment across various teams.
- Cultivate partnerships throughout the organization to drive favorable security outcomes and foster a culture of security awareness.
- Define, refine, and enhance internal workflows and collaboration practices to improve efficiency and effectiveness.
- Articulate security risks and technical trade-offs to a variety of stakeholders, ensuring clear understanding and informed decision-making.
- Develop and implement strategies to monitor and assess security compliance across the organization.
- Collaborate with engineering and product teams to integrate security best practices into the development lifecycle.
- Lead post-incident reviews to identify lessons learned and implement improvements to prevent future occurrences.
- Establish and maintain rigorous program schedules, tracking dependencies, blockers, and status to ensure timely delivery of security initiatives.
- Translate high-level business security goals into actionable technical plans that can be executed by cross-functional teams.
- Coordinate resources and prioritize tasks to manage multiple security programs concurrently without compromising quality or compliance standards.
- Implement metrics and key performance indicators to measure the success and maturity of security programs over time.
- Act as the central communication hub for security-related programs, consolidating information and distributing clear, concise updates to leadership and stakeholders.
- Drive the adoption of security tooling and automation to streamline processes and reduce manual overhead across the security lifecycle.
- Support the development of security playbooks, runbooks, and governance documentation to ensure consistency and compliance.
Requirements
- A minimum of 5 years of experience in program or project management, particularly in a cloud or SaaS environment that supports enterprise technology or security teams.
- A solid understanding of information security principles, including but not limited to data protection, access management, and application security.
- Strong analytical skills to dissect technical details and address complex challenges effectively.
- Proven ability to convey security risks to both technical and non-technical audiences in an understandable manner.
- Familiarity with collaboration tools such as Asana, Google Workspace, Slack, Zoom, Notion, and Figma is essential.
- Excellent communication and interpersonal skills to foster collaboration across teams.
- Demonstrated experience managing programs that involve strict deadlines and high-stakes security requirements.
- Ability to operate effectively in a fast-paced environment with ambiguous problems and evolving priorities.
Nice to have
- Professional certifications such as PMP or Scrum Master would be advantageous.
- Experience in areas like identity and access management, vendor security, technology governance, risk assessments, security investigations, or incident response is a plus.
- Knowledge of security frameworks such as ISO 27001, NIST, SOC 2, and ITGC would be beneficial.
- Familiarity with AI and ML risk frameworks, including NIST AI RMF, OECD, or ISO 42001, is a plus.
- Experience utilizing AI tools like Claude Code, Claude Cowork, or Open AI Codex for workflow automation would be advantageous.
Practical notes
- The compensation package includes a base salary, equity options, and a comprehensive benefits package that covers health, dental, vision, retirement contributions, and paid time off.
- During video interviews, candidates are required to keep their cameras on to facilitate better communication.
- New hires must attend in-person onboarding sessions to integrate into the company culture effectively.
- Figma is committed to inclusivity and provides reasonable accommodations for applicants with disabilities; inquiries regarding accommodations can be directed to accommodations-ext@figma.com.
This role at Figma presents an for a driven individual to make a significant impact on the security landscape of a leading design platform. If you are about security and have the requisite experience, we encourage you to apply and join our mission to empower creativity through secure collaboration.