The opportunity
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI.
What you'll do
Own Figma's security monitoring and incident response program, from detection: engineering through post-incident review and continuous improvement
Build and automate security operations workflows, including alert triage,: enrichment, investigation, and response actions using SOAR and custom tooling
Develop and maintain incident response run books, escalation procedures, and: communication plans for security events of varying severity
Lead incident response preparedness initiatives, including tabletop: exercises, red team engagements, and response capability assessments
Improve the effectiveness of our SIEM and SOAR platforms by reducing noise,: increasing signal fidelity, and closing detection coverage gaps
Build and operationalize threat intelligence capabilities to identify: adversary behaviors, prioritize investments, and strengthen detection and response programs
What they're looking for
- Partner with Legal, Privacy, and Communications teams to support breach: notification and regulatory response obligations during significant security incidents
- Drive security operations strategy through vendor management, operational: metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction
- + years of experience in security operations, incident response, or a related security engineering function
- Hands-on experience building and automating detection and response workflows: using scripting, APIs, or security automation platforms