Назад
5 дней назад

Strategic Program Manager (Information Security)

169 000 - 296 000$
Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Strategic Program Manager (Information Security): Building and scaling security programs, practices, and cross-functional partnerships across Figma with an accent on risk management, program metrics, and organizational adoption. Focus on coordinating remediation, designing operating models, and driving leadership visibility through OKRs, risk registers, and reporting.

Location: Remote in the United States or onsite at Figma's US hubs in San Francisco, CA, or New York, NY

Annual base salary: $169,000–$296,000 USD

Company

Figma provides a collaborative design platform that helps teams brainstorm, prototype, translate designs into code, and iterate with AI in real time.

What you will do

  • Lead strategic information security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability.
  • Partner with GRC, Security Operations, Security Engineering, Internal Audit, Legal, People, Product, Sales, and business teams to address security risks.
  • Define and track security metrics, OKRs, risk registers, dashboards, and leadership reporting.
  • Coordinate remediation of security gaps with control owners, security specialists, and business stakeholders.
  • Design scalable security policies, processes, operating models, and change management plans.
  • Drive security awareness through training, communications, educational initiatives, and leadership portfolio support.

Requirements

  • 5+ years of experience in security program management, security business partnership, or a related strategic information security role.
  • Experience leading complex, cross-functional security programs and developing metrics, OKRs, risk registers, or dashboards.
  • Working knowledge of information security frameworks such as NIST CSF, SOC 2, ISO 27001, or equivalent.
  • Ability to communicate security risks, priorities, and tradeoffs to technical and non-technical stakeholders, including senior leaders.
  • Experience delivering security awareness, training, risk remediation, or change management initiatives.

Nice to have

  • Experience supporting security or technical leadership through chief of staff, business operations, or portfolio management work.
  • Knowledge of enterprise or quantitative risk management, including FAIR.
  • Experience with SOX ITGC, GDPR, NIS2, or other public-company and global regulatory requirements.
  • Experience using AI, automation, or security tooling to improve reporting and workflows.
  • Security certifications such as CISA, CISSP, CISM, or CRISC.

Culture & Benefits

  • Full-time employment with remote work available within the United States or work from a US hub.
  • Equity, health, dental, and vision coverage, retirement benefits with company contributions, and paid time off.
  • Parental leave, reproductive and family planning support, mental health and wellness benefits, paid sick leave, and holidays.
  • Flexible PTO for eligible exempt employees, with possible recharge days, phone and home internet reimbursements, and lifestyle spending accounts.
  • Paid in-person onboarding is required; video interviews require cameras to remain on.

Hiring process

  • Video interviews require candidates to keep their cameras on.
  • In-person onboarding is required after hiring.
  • Reasonable accommodations are available during the application and interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →