SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Figma is seeking a Strategic Program Manager for Information Security to drive strategic initiatives and build mature security practices across the organization. This role sits at the intersection of security leadership and cross-functional business teams, requiring close collaboration with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business stakeholders.
Key responsibilities include leading strategic security programs from planning through execution, managing portfolios, coordinating priorities, dependencies, and accountability across teams. You will partner with stakeholders to identify and address security risks, translate security priorities into actionable guidance, and design scalable security practices including policies, processes, and operating models. The role involves defining and tracking security program metrics, OKRs, risk registers, and dashboards that provide leadership visibility into program health and risk posture.
You will identify and coordinate remediation of security gaps by working with control owners and business stakeholders to drive issues to resolution. Additionally, you'll drive security awareness and engagement through company-wide training, communications, and educational initiatives. Supporting security leadership with strategic planning, portfolio management, leadership briefings, and follow-through on key commitments is also central to the role.
The ideal candidate has 5+ years of experience in security program management, security business partnership, or related strategic roles within information security. You should demonstrate experience leading complex, cross-functional security programs with measurable outcomes, working knowledge of frameworks like NIST CSF, SOC 2, or ISO 27001, and the ability to communicate security risks and tradeoffs to both technical and non-technical stakeholders including senior leaders. Experience developing security initiatives that drive organizational adoption—such as awareness programs, training, risk remediation, or change management—is highly valued.
This is a full-time role available from Figma's US hubs (San Francisco or New York) or remote within the United States.