Manager, Security Operations

Figma Figma · Enterprise · United States · Business Operations

Manager for Security Operations at Figma, focusing on building and scaling security systems, processes, and tooling for detection and response. Responsibilities include owning the incident response program, automating workflows, improving SIEM/SOAR effectiveness, and building threat intelligence capabilities. Requires experience in security operations, incident response, and expertise with SIEM/SOAR technologies.

What you'd actually do

  1. Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement
  2. Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling
  3. Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity
  4. Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments
  5. Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps

Skills

Required

  • Security operations
  • Incident response
  • Security engineering
  • Automation
  • Scripting
  • APIs
  • SOAR
  • SIEM
  • Cloud-native environments
  • SaaS environments
  • Detection and response program development
  • Leadership
  • Stakeholder management

Nice to have

  • SOX
  • ISO 27001
  • SOC 2
  • FedRAMP
  • AI risk management frameworks
  • NIST AI RMF
  • OECD AI Principles
  • ISO 42001
  • AI-powered tools for security operations

What the JD emphasized

  • 7+ years of experience in security operations, incident response, or a related security engineering function
  • Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms
  • Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment
  • Demonstrated success building, scaling, or significantly improving a detection and response program
  • Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events