SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Figma is seeking a Federal Compliance Manager to lead FedRAMP authorization and compliance efforts for the design platform. In this role, you will serve as a key bridge between product engineering, security, legal, and government stakeholders to ensure Figma meets federal cloud security standards.
You will own the documentation and implementation of FedRAMP control requirements, analyze security assessments (penetration testing, vulnerability scans), and manage Plans of Action and Milestones (POAM) reporting for authorizing agencies. Key responsibilities include collaborating across legal, sales, product, and enterprise teams; preparing for internal and external audits; identifying and escalating technical and program risks; and maintaining technical documentation such as the System Security Plan (SSP).
You will guide internal teams on FedRAMP and security framework implementation, communicate specific security and configuration requirements to cloud and application teams, and contribute to cross-department security initiatives. The role requires deep expertise in security controls, cloud architecture, and federal compliance processes.
Required qualifications: 5+ years of hands-on IT auditing and/or compliance experience; recent, concentrated work with the FedRAMP Framework; previous experience leading a Cloud Service Provider through FedRAMP ATO; SaaS-based audit and compliance experience; and familiarity with cloud computing environments (e.g., AWS).
Desired qualifications include understanding of security domains (application security, infrastructure, incident response), hands-on cloud computing experience, established connections in the FedRAMP industry, and familiarity with international regulatory compliance frameworks.
This is a full-time role based in San Francisco or New York, with remote work available within the United States.