Security Engineer

Figma

San Francisco, CA

JOB DETAILS
SKILLS
Applications Security, Artificial Intelligence (AI), Cloud Applications, Cloud Computing, Communication Skills, Computer Security, Data Management, Debugging Tools, Engineering, Establish Priorities, Identity Data Management, Incident Response, Information Technology & Information Systems, Interpersonal Skills, Machine Tool, Operations Security (OPSEC), Penetration Testing, Product Reviews, Prototyping, Risk Management, Risk Modeling, Scalable System Development, Security Analysis, Security Attacks, Security Consulting, Security Infrastructure, Software Engineering, Technical/Engineering Design, Threat Modeling
LOCATION
San Francisco, CA
POSTED
2 days ago

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether youre brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If youre excited to shape the future of design and collaboration, join us!

As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are hiring for multiple teams within Security Engineering: AI Security, Platform Security, Product Security, and Anti-Abuse. This is a remote first role. 

You will partner closely with teams across the company and focus on systemic security improvements and risk reduction. You will also participate in operational security responsibilities like security reviews, consulting, vulnerability triage, and security incident response.

Examples of what you may work on across teams:

AI Security

• Perform technical security assessments, code audits, and design reviews for new AI infrastructure, platforms, and products.

• Design and develop technical solutions to secure AI models, tooling, debugging workflows, and data pipelines.

• Advocate for secure practices across Figma’s AI infrastructure, platforms, and data systems.

• Build the next generation of internal AI-powered access insights and security tooling.

• Help run penetration testing and offensive security exercises against Figma’s AI infrastructure, platforms, and products.

Platform Security

• Perform technical security assessments, code audits, and design reviews for changes to Figma’s cloud and corporate infrastructure.

• Design and develop solutions to prevent or mitigate cloud and corporate security risks.

• Advocate for secure practices within Figma’s cloud and corporate infrastructure.

• Build platforms and tooling to detect and respond to infrastructure and corporate security threats.

Product Security

• Perform technical security assessments, code audits, and design reviews for new product features.

• Design and develop solutions to prevent or mitigate product security vulnerabilities.

• Advocate for secure development practices across Figma’s products and services.

• Help run penetration testing, offensive security exercises, and support our bug bounty program.

• Help respond to product security incidents.

Anti-Abuse

• Design and build technical systems to prevent spam, fraud, and abuse.

• Partner closely with product teams to identify and address potential abuse vectors.

• Develop new signals and improve the use of existing signals to detect abusive behavior.

• Help respond to spam, fraud, and abuse incidents.

This is a full-time role that can be held from one of our US hubs or remotely in the United States.

We’d love to hear from you if you have:

• 5+ years of proven engineering experience working in either a Security Engineering or a Software Engineering role. In the case of the latter, some security experience is preferred.

• Strong security judgment in threat modeling and risk prioritization and/or strong technical judgment in designing and building maintainable, scalable systems.

• Proficiency in at least one general-purpose coding language.

• Strong communication and interpersonal skills, with demonstrated experience collaborating across functions.

While not required, it’s an added plus if you also have:

• Subject matter expertise in Application Security, Cloud Security, Corporate Security, Data Access Governance, and/or IAM (Identity and Access Management).

• Demonstrated ability to make hard prioritization decisions in security controls.

At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.

About the Company

F

Figma