Security Compliance Analyst
San Francisco, CA • New York, NY • United States
Figma
Figma is the leading collaborative design tool for building meaningful products. Seamlessly design, prototype, develop, and collect feedback in a single platform.Figma is growing our team of passionate people on a mission to make design accessible to all. Born on the Web, Figma helps entire product teams brainstorm, design and build better products — from start to finish. Whether it’s consolidating tools, simplifying workflows, or collaborating across teams and time zones, Figma makes the design process faster, more efficient, and fun while keeping everyone on the same page. From great products to long-lasting companies, we believe that nothing great is made alone—come make with us!
As a Security Compliance Analyst at Figma, you will help the Manager, Security Compliance coordinate and manage the audit certification lifecycles for current and future compliance initiatives. You will drive our certification roadmaps based on customer requirements while ensuring committed assessments are delivered on schedule. This is a great opportunity to drive efficiencies, reduce process friction, and strategically scale our compliance programs to support a hyper growth company.
What you’ll do at Figma:
- Maintain existing Security Compliance Certifications and Frameworks (i.e. SOC 2 Type II, ISO 27001)
- Serve as a subject matter authority for applicable compliance standards and be a valued partner to the business and engineering teams in the implementation of the standards
- Gap assess new in-scope tools and new hosting regions/environments against existing controls and processes
- Help drive and improve Annual Operational Activities (i.e. Quarterly Privileged User Access Reviews)
- Implement and mature controls that scale and do not burden teams
- Refine Figma’s Common Control Framework through control rationalization efforts
- Configure compliance automation tooling to help achieve continuous monitoring and automated evidence collection for external audits
- Communicate progress, customer concerns, and issue resolution to management and team stakeholders.
- Align changes made to existing controls and processes to the Information Security and Data Privacy Policies
We'd love to hear from you if you have:
- 2+ years of security compliance or IT compliance experience
- Worked with various security compliance frameworks (including ISO 27001, SOC 2, and NIST)
- Familiarity with cloud computing/architecture such as AWS
- Conducted compliance gap assessments and worked cross-functionally to remediate any identified issues
- Led or supported external audits
While not required, it’s an added plus if you also have:
- Planned, coordinated, and prioritized multiple sophisticated projects to completion
- Experience with control rationalization and drafting control narratives
- Demonstrated experience establishing work relationships across multi-disciplinary teams (including Security, Engineering, Legal, IT, and HR)
Pay Transparency Disclosure
If based in Figma’s San Francisco or New York hub offices, this role has the annual base salary range stated below.
Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information.
Figma offers equity to employees, as well a competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave & reproductive or family planning support, mental health & wellness benefits, generous PTO, company recharge days, a learning & development stipend, a work from home stipend, and cell phone reimbursement. Figma also offers sales incentive pay for most sales roles. Figma’s compensation and benefits are subject to change and may be modified in the future. You may view our Pay Transparency Policy by clicking on the corresponding link.
Annual Base Salary Range (SF/NY Hub):$122,000—$215,000 USDAt Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.
We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities.
Examples of accommodations include but are not limited to:
- Holding interviews in an accessible location
- Enabling closed captioning on video conferencing
- Ensuring all written communication be compatible with screen readers
- Changing the mode or format of interviews
By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with the applicable candidate section of Figma's Privacy Policy.
Tags: Audits Automation AWS Cloud Compliance ISO 27001 Monitoring NIST Privacy SOC SOC 2
Perks/benefits: Career development Cell phone stipend Competitive pay Equity / stock options Health care Home office stipend Parental leave Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.