Figma, a leading web-based design platform, is seeking a Security Engineer to join their team in either San Francisco or New York, with remote work options available in the United States. This role offers a competitive salary range of $149,000 to $350,000 USD, along with comprehensive benefits including health, dental, vision insurance, and more.
The position requires 5+ years of security team experience and focuses on identifying and driving impactful projects to enhance the security of Figma's product, platform, and IT systems. As a Security Engineer, you'll be responsible for performing technical security assessments, developing security solutions, and advocating for secure practices throughout the organization. The role involves working with various teams across the company to implement systemic security improvements and risk reduction strategies.
Key responsibilities include conducting code audits, design reviews, and security assessments to identify potential vulnerabilities and attack vectors. You'll also play a crucial role in managing the company's pen-testing initiatives and bug bounty program. The ideal candidate should have strong expertise in systems security (Linux/Unix/Mac), AWS security, Cloud SaaS Security, or web application security, along with proficiency in at least one general-purpose programming language.
Figma offers a collaborative environment where security professionals can make a significant impact on product security while working with cutting-edge design and collaboration tools. The company provides a comprehensive benefits package, including equity, retirement contributions, parental leave, mental health support, and various stipends for professional development and remote work setup.
This role presents an excellent opportunity for security professionals who want to work at the intersection of design technology and security, helping to protect and enhance one of the most innovative design platforms in the industry. The position offers both technical challenges and the opportunity to influence security practices across a growing organization.