Skip to content
FigmaFigma

Security Engineer

Security Engineer drives security improvements across Figma's AI, platform, product, and anti-abuse teams through assessments, tooling development, threat detection, and incident response. Requires 5+ years engineering experience, strong security judgment, and proficiency in a general-purpose language.

About the job

Responsibilities

AI Security:

  • Perform technical security assessments, code audits, and design reviews for new AI infrastructure, platforms, and products.
  • Design and develop technical solutions to secure AI models, tooling, debugging workflows, and data pipelines.
  • Advocate for secure practices across Figma's AI infrastructure, platforms, and data systems.
  • Build internal AI-powered access insights and security tooling.
  • Help run penetration testing and offensive security exercises against AI infrastructure.

Platform Security:

  • Perform technical security assessments, code audits, and design reviews for cloud and corporate infrastructure changes.
  • Design and develop solutions to prevent or mitigate cloud and corporate security risks.
  • Advocate for secure practices within cloud and corporate infrastructure.
  • Build platforms and tooling to detect and respond to infrastructure and corporate security threats.

Product Security:

  • Perform technical security assessments, code audits, and design reviews for new product features.
  • Design and develop solutions to prevent or mitigate product security vulnerabilities.
  • Advocate for secure development practices across products and services.
  • Help run penetration testing, offensive security exercises, and support bug bounty program.
  • Help respond to product security incidents.

Anti-Abuse:

  • Design and build technical systems to prevent spam, fraud, and abuse.
  • Partner with product teams to identify and address potential abuse vectors.
  • Develop new signals and improve existing signals to detect abusive behavior.
  • Help respond to spam, fraud, and abuse incidents.

Requirements

  • 5+ years of proven engineering experience in Security Engineering or Software Engineering (with some security experience preferred).
  • Strong security judgment in threat modeling and risk prioritization and/or strong technical judgment in designing and building maintainable, scalable systems.
  • Proficiency in at least one general-purpose coding language.
  • Strong communication and interpersonal skills, with demonstrated experience collaborating across functions.

Nice-to-Haves

  • Subject matter expertise in Application Security, Cloud Security, Corporate Security, Data Access Governance, and/or IAM (Identity and Access Management).
  • Demonstrated ability to make hard prioritization decisions in security controls.

Skills

Threat Modeling, Code Audits, Design Reviews, Penetration Testing, Cloud Security, IAM, Application Security, Python, JavaScript, Go

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

Vannevar

Vannevar

United States

Application Security Engineer
$160k+/yrRemote5+ YOESecurity Engineering

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.