Skip to content
FigmaFigma

Strategic Program Manager, Information Security

Leads cross-functional information security programs, risk remediation, metrics, governance, and organizational engagement while partnering with security leadership and business stakeholders. Requires 5+ years of security program management experience and familiarity with major security frameworks and risk practices.

About the job

Responsibilities

  • Lead strategic security programs from planning through execution, coordinating priorities, dependencies, risks, and accountability across security and business teams.
  • Partner with teams across Figma to identify and address security risks, align stakeholders, and translate security priorities into practical guidance and action plans.
  • Define and track security program metrics, OKRs, risk registers, and reporting for leadership visibility into program health, priorities, and risk posture.
  • Coordinate remediation of security gaps with control owners, security specialists, and business stakeholders.
  • Design and implement scalable security practices, including policies, processes, operating models, and change management plans.
  • Drive security awareness and engagement through company-wide training, communications, and educational initiatives.
  • Support security leadership with strategic planning and portfolio management, leadership briefings, decision coordination, and follow-through.

Requirements

  • 5+ years of experience in security program management, security business partnership, or a related strategic information security role.
  • Experience leading complex, cross-functional security programs and developing program metrics, OKRs, risk registers, or dashboards.
  • Working knowledge of information security frameworks such as NIST CSF, SOC 2, or ISO 27001.
  • Ability to communicate security risks, priorities, and tradeoffs to technical and non-technical stakeholders, including senior leaders.
  • Experience developing or delivering security awareness, training, risk remediation, or change management initiatives.

Nice-to-haves

  • Experience supporting security or technical leadership in a chief of staff, business operations, or portfolio management capacity.
  • Knowledge of enterprise or quantitative risk management, including FAIR.
  • Experience with SOX ITGC, GDPR, NIS2, or other global regulatory frameworks.
  • Experience using AI, automation, or security tooling to improve reporting, workflows, or decision-making.
  • Security certifications such as CISA, CISSP, CISM, or CRISC.

Compensation and Benefits

  • Annual base salary range: $169,000–$296,000 USD.
  • Equity and benefits including health, dental, and vision coverage; retirement contributions; parental and family-planning support; mental health and wellness benefits; paid time off; paid sick leave; holidays; and an annual bonus plan for eligible non-sales roles.
  • Additional benefits may include recharge days, cell phone and home internet reimbursements, and lifestyle spending accounts.

Skills

Information Security, Security Program Management, Nist Csf, SOC 2, ISO 27001, Risk Management, Okrs, Risk Registers, Change Management, Security Awareness, Fair, Sox Itgc, GDPR, Nis2, Cissp

OpenAI

OpenAI

Washington, DC
Agent Standards Specialist, Global Affairs
$171k+/yrHybridTechnical Program Management

Leads external technical standards strategy for AI agent identity, authorization, discovery, provenance, and auditability. The role translates internal architecture and security controls into credible specifications, coordinates cross-functional approvals, and represents the company in standards forums and industry coalitions.

Scale AI

Scale AI

Washington, DC

Subcontracts Manager, Public Sector
$166k+/yrOn-site5+ YOETechnical Program Management

Manages subcontractor relationships and execution for complex Public Sector programs, integrating external deliverables into technical plans and schedules. The role requires 5+ years of program or subcontract management experience, strong systems integration fluency, and an active Top Secret clearance.

Scale AI

Scale AI

Colorado Springs, CO
Technical Program Manager , Public Sector
$166k+/yrOn-site5+ YOETechnical Program Management

Own technical execution for national security programs, translating operational needs into executable requirements and coordinating engineering, customer, and partner stakeholders through deployment and evaluation. The role requires 5+ years of technical delivery experience, strong software and AI/ML literacy, and an active TS/SCI clearance.

Baseten

Baseten

San Francisco, CA
Technical Program Manager, Model Performance
$165k+/yrHybridTechnical Program Management

Build and lead the Model Performance organization’s technical program framework, coordinating model releases, inference optimization, and cross-functional execution. The role requires deep technical program management experience and credibility with model-serving and performance engineering teams.

Stripe

Stripe

South San Francisco, CA

Technical Program Manager, Infrastructure
$173k+/yrRemote5+ YOETechnical Program Management

Leads large-scale, cross-functional infrastructure programs from definition through execution, partnering with engineering teams on technical design, delivery, and strategic decisions. Requires a bachelor’s degree and at least five years of experience in technical program management, software or systems engineering, and cloud infrastructure.