JobBobsReal-time global job discoveryLive

Manager, Security Operations

Figma · San Francisco, CA • New York, NY • United States · 2026-06-05

executiveRemote
Apply on the employer's site

About this role

<div class="content-intro"><p>Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us!</p></div><p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions.</p> <p class="font-claude-response-body break-words whitespace-normal leading-[1.7]">This is a full time role that can be held from one of our US hubs or remotely in the United States. </p> <h4 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>What you'll do at Figma:</strong></h4> <ul class="[li_&]:mb-0 [li_&]:mt-1 [li_&]:gap-1 [&:not(:last-child)_ul]:pb-1 [&:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3"> <li class="font-claude-response-body whitespace-normal break-words pl-2">Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Partner with Legal, Privacy, and Communications teams to support breach notification and regulatory response obligations during significant security incidents</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Drive security operations strategy through vendor management, operational metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction</li> </ul> <h4 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>We'd love to hear from you if you have:</strong></h4> <ul class="[li_&]:mb-0 [li_&]:mt-1 [li_&]:gap-1 [&:not(:last-child)_ul]:pb-1 [&:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3"> <li class="font-claude-response-body whitespace-normal break-words pl-2">7+ years of experience in security operations, incident response, or a related security engineering function</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Demonstrated success building, scaling, or significantly improving a detection and response program</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events</li> </ul> <h4 class="font-claude-response-body break-words whitespace-normal leading-[1.7]"><strong>While it's not required, it's an added plus if you also have:</strong></h4> <ul class="[li_&]:mb-0 [li_&]:mt-1 [li_&]:gap-1 [&:not(:last-child)_ul]:pb-1 [&:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3"> <li class="font-claude-response-body whitespace-normal break-words pl-2">Operated in a public company environment with SOX, ISO 27001, SOC 2, or FedRAMP requirements</li> <li class="font-claude-response-body whitespace-normal break-words pl-2">Applied AI risk management…

Skills asked for

Similar jobs

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.