SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Figma is seeking a Security Engineer to identify and drive impactful security improvements across the company's product, platform, and IT systems. This is a remote-first, full-time role with the option to work from US hubs (San Francisco or New York) or remotely within the United States.
You will partner closely with cross-functional teams to focus on systemic security improvements and risk reduction. The role spans multiple security domains: AI Security, Platform Security, Product Security, and Anti-Abuse.
In AI Security, you'll perform technical security assessments and code audits for AI infrastructure, design solutions to secure AI models and data pipelines, advocate for secure practices, build AI-powered security tooling, and conduct penetration testing exercises.
In Platform Security, you'll assess cloud and corporate infrastructure changes, design solutions to mitigate infrastructure risks, advocate for secure practices, and build detection and response platforms for infrastructure threats.
In Product Security, you'll conduct security assessments for new features, design vulnerability mitigation solutions, advocate for secure development practices, run penetration tests and bug bounty support, and respond to product security incidents.
In Anti-Abuse, you'll design systems to prevent spam and fraud, partner with product teams on abuse vectors, develop detection signals, and respond to abuse incidents.
You'll also participate in operational security responsibilities including security reviews, consulting, vulnerability triage, and incident response.
Required: 5+ years of engineering experience in Security Engineering or Software Engineering (with some security experience preferred). Strong security judgment in threat modeling and risk prioritization, and/or strong technical judgment in designing scalable systems. Proficiency in at least one general-purpose coding language. Strong communication and collaboration skills.
Preferred: Subject matter expertise in Application Security, Cloud Security, Corporate Security, Data Access Governance, or IAM. Demonstrated ability to prioritize security controls effectively.