CareerPlanGet AI match score →

Governance Risk and Compliance

US🌐 Remote💼 Full-time💰 $153,000–$153,000🗓 2026-06-06 → 2026-07-30

Core

Building and maintaining trust with users, regulators, and partners by strengthening security, managing risk, and ensuring compliance for Figma's platform.

Role type

GRC (Governance, Risk, and Compliance) professional

Builds

Security and compliance programs, risk frameworks, and customer trust initiatives

Domain

SaaS / Design collaboration tools / Cybersecurity & Compliance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Information security, compliance frameworks (SOC 2, ISO 27001, FedRAMP, SOX, GDPR), audit management, risk assessment, policy governance, GRC platforms, cross-functional stakeholder management

Preferred skills

Public company environment experience, FedRAMP authorization support, security certifications (CISA, CISSP, CISM, CRISC), GRC platform implementation (Vanta, Drata), scaling programs in high-growth environments

Technologies

SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, NIS2, PCI-DSS, Vanta, Drata

Responsibilities

Lead compliance programs across frameworks; manage external audits and certification activities; build and maintain risk and controls frameworks; conduct risk and gap assessments; improve control effectiveness and operational efficiency; implement and optimize GRC platforms; maintain security policies and governance processes; support customer trust initiatives

Seniority

Mid-Senior, hands-on IC

Rewrite
## Responsibilities - Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2 - Manage external audits and certification activities while partnering with auditors and assessors - Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications - Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders - Improve control effectiveness and operational efficiency through rationalization and process optimization - Implement and optimize GRC platforms that scale evidence collection and program management - Maintain security policies and governance processes that align with organizational risk objectives - Support customer trust initiatives, including security questionnaires, audits, and customer-facing security communications ## Roles We Hire For - **Compliance Management** - Lead compliance and certification programs across security and regulatory frameworks - Manage audit cycles, partner with external assessors, and drive audit readiness initiatives - Improve controls, processes, and evidence management practices across the organization - **Security Risk Management** - Build and maintain risk and controls frameworks that support Figma's security posture - Assess, prioritize, and communicate security risks across the business - Develop third-party risk management strategies and enterprise risk reporting programs - **Policy & Governance** - Manage the lifecycle of organizational security policies, standards, and procedures - Drive policy awareness and stakeholder engagement across the company - Ensure governance practices align with regulatory requirements and business objectives - **GRC Platforms & Enablement** - Select, implement, and optimize GRC platforms and supporting workflows - Scale evidence collection, reporting, and program management capabilities - Identify opportunities to automate and streamline GRC operations - **Customer Trust** - Support customer trust and business enablement activities across the sales lifecycle - Manage security knowledge bases, customer-facing documentation, and trust publications - Respond to customer security inquiries, audits, and questionnaires ## Requirements - We’d love to hear from you if you have: - Experience in compliance, risk management, governance, GRC tooling, or customer trust - Strong understanding of security frameworks and regulatory requirements - Ability to build programs, improve processes, and shape how Figma scales security and trust ## Benefits - This is a full time role that can be held from one of our US hubs or remotely in the United States.
Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Greenhouse ↗