Governance Risk and Compliance

Figma Figma · Enterprise · United States · Business Operations

Figma is seeking a Governance, Risk, and Compliance (GRC) professional to join their team. This role will focus on building and maintaining trust with users, regulators, and business partners by strengthening security, managing risk, and maintaining compliance. Responsibilities include leading compliance programs (SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, NIS2), managing audits, building risk frameworks, conducting assessments, optimizing GRC platforms, and supporting customer trust initiatives. The role requires experience in information security, compliance, or risk management, with a strong understanding of security and compliance frameworks and audit support.

What you'd actually do

  1. Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2
  2. Manage external audits and certification activities while partnering with auditors and assessors
  3. Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications
  4. Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders
  5. Implement and optimize GRC platforms that scale evidence collection and program management

Skills

Required

  • 4+ years of experience in information security, compliance, risk management, or a related field
  • Hands-on experience supporting security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC
  • Experience leading or supporting audits and partnering with external assessors
  • Demonstrated ability to conduct assessments, drive remediation efforts, and manage cross-functional initiatives
  • Exceptional written and verbal communication skills across technical, business, and executive audiences
  • Demonstrated ability to improve processes, manage competing priorities, and build strong cross-functional partnerships

Nice to have

  • Operated in a public company environment with SOX ITGC requirements
  • Supported FedRAMP authorization, SSP development, 3PAO coordination, or continuous monitoring activities
  • Earned security or risk certifications such as CISA, CISSP, CISM, or CRISC
  • Implemented or administered GRC platforms such as Vanta, Drata, or similar tools
  • Scaled security, compliance, or risk programs in a high-growth environment

What the JD emphasized

  • SOC 2
  • ISO 27001
  • FedRAMP
  • SOX ITGC
  • GDPR
  • NIS2
  • external audits
  • risk and controls frameworks
  • assessments
  • remediation efforts
  • GRC platforms