Manager, Security Operations
Lead Figma's security operations program, owning monitoring, incident response, SIEM/SOAR automation, and threat intelligence. Requires 7+ years in security operations or incident response with deep SIEM/SOAR expertise.
About the job
What you'll do at Figma:
- Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement
- Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling
- Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity
- Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments
- Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps
- Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs
- Partner with Legal, Privacy, and Communications teams to support breach notification and regulatory response obligations during significant security incidents
- Drive security operations strategy through vendor management, operational metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction
We'd love to hear from you if you have:
- 7+ years of experience in security operations, incident response, or a related security engineering function
- Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms
- Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment
- Demonstrated success building, scaling, or significantly improving a detection and response program
- Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events
Nice to have:
- Operated in a public company environment with SOX, ISO 27001, SOC 2, or FedRAMP requirements
- Applied AI risk management frameworks such as NIST AI RMF, OECD AI Principles, or ISO 42001
- Utilized AI-powered tools to automate security operations workflows and improve team efficiency
Skills
SIEM, Soar, Incident Response, Detection Engineering, Threat Intelligence, Scripting, APIs, IAM, Vulnerability Management, Dlp
Similar jobs
Security Engineering jobsBuild data pipelines, integrations, policy-as-code, and agentic AI workflows that automate security governance and continuous compliance. The role requires 7+ years of production software engineering experience plus expertise in LLMs, APIs, distributed data, and cloud infrastructure.
Own end-to-end security detection engineering, incident response, automation, and threat hunting across endpoint, identity, SaaS, and cloud environments. The role requires substantial hands-on experience with production detection logic, incident response, programming, and modern SIEM or detection pipelines.
The Senior GRC Analyst will manage security governance, risk, and compliance programs, including SOC 2 controls, risk assessments, vendor reviews, audits, and data governance. The role requires 8+ years of GRC experience, a bachelor’s degree, and familiarity with compliance platforms and SaaS environments.
This role defines, builds, and secures the internal platform supporting Front’s engineering, GTM, data, and AI tooling. It owns AWS and Snowflake infrastructure, paved-road delivery, observability, access controls, vulnerability management, incident response, compliance support, and AI-client security.
Build and operate foundational security services covering identity, authorization, secrets, and privileged access for an AI-powered enterprise platform. The role requires 5+ years of production software engineering experience and hands-on security infrastructure expertise.