Technical Program Manager, Security

Figma Figma · Enterprise · United States · Business Operations

This role is for a Technical Program Manager supporting the Security Operations team at Figma. The TPM will lead cross-functional programs related to security, compliance, and infrastructure initiatives, ensuring alignment, managing dependencies, and driving scalable solutions. While the company uses AI tools and considers AI risk, the core function of this role is program management within security, not direct AI/ML development.

What you'd actually do

  1. Own end-to-end program execution for security, compliance, and infrastructure initiatives—managing dependencies, milestones, risks, and reporting at a portfolio level
  2. Lead highly cross-functional programs, using strong project management skills to deliver complex initiatives in a collaborative and transparent way
  3. Drive project alignment by handling dependencies, guiding technical discussions, facilitating decision making, and ensuring the right conversations happen at the right time
  4. Influence outcomes by building trusted, strong partnerships across the organization
  5. Champion effective ways of working—finding the right balance of tools, structure & practices while continuously improving how we collaborate and deliver on our commitments

Skills

Required

  • 5+ years of program or project management experience in a cloud or SaaS environment supporting enterprise technology or security teams
  • Strong understanding of information security principles and controls, including data protection, access management, and application security
  • Ability to dive into technical details and apply that knowledge to drive alignment and solve complex challenges
  • Experience communicating complex security risks and tradeoffs to both technical and non-technical audiences
  • Proficiency with project management and collaboration tools (e.g., Asana, Google Workspace, Slack, Zoom, Notion, Figma) and the judgment to apply them effectively based on team needs

Nice to have

  • PMP & Scrum Certifications
  • Prior experience with identity and access management systems and practices, vendor security and technology governance processes, risk assessments, security investigations, detection and response operations, and incident response
  • Familiarity with security frameworks and standards such as ISO 27001, NIST, and SOC 2, and experience with ITGC frameworks
  • Familiarity with AI/ML risk considerations or AI risk frameworks (NIST AI RMF, OECD, ISO 42001)
  • Experience with using AI tools (e.g Claude Code, Claude Cowork, Open AI Codex, etc) to automate and scale manual processes and decision-making workflows

What the JD emphasized

  • security
  • compliance
  • infrastructure
  • risk
  • information security principles
  • security frameworks and standards