1

Compliance Risk Jobs in California (NOW HIRING)

Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales ...

Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales ...

Lead compliance and risk management projects across Shared Services * Interpret and manage regulatory requirements (CPUC, FERC, OEIS, CAISO) * Support compliance documentation, controls, audits, and ...

New

next page

Showing results 1-20

Compliance Risk information

What are some common challenges faced by professionals in Compliance Risk roles, and how can they be addressed?

Professionals in Compliance Risk often face the challenge of keeping up with constantly evolving regulations and ensuring that internal practices remain aligned with legal requirements. Balancing the need for rigorous controls while supporting business operations can also be demanding, as compliance measures must not hinder productivity. To address these challenges, ongoing education, collaboration with legal and business units, and leveraging technology for monitoring and reporting are essential strategies. Building strong communication channels across teams helps ensure compliance is integrated seamlessly throughout the organization.

What are the key skills and qualifications needed to thrive as a Compliance Risk professional, and why are they important?

To thrive as a Compliance Risk professional, you need a strong understanding of regulatory frameworks, risk assessment, and compliance procedures, usually supported by a degree in law, finance, or a related field. Familiarity with compliance management systems, GRC (Governance, Risk, and Compliance) software, and industry certifications such as CRCM or CAMS is often expected. Attention to detail, analytical thinking, and effective communication are crucial soft skills for identifying risks and ensuring organizational adherence to regulations. These skills are essential for minimizing legal exposure, maintaining ethical standards, and safeguarding the organization's reputation.

What is compliance risk?

Compliance risk refers to the potential for legal or regulatory sanctions, financial loss, or reputational damage that an organization can face if it fails to comply with laws, regulations, or internal policies. Businesses must identify, assess, and manage compliance risks to operate within the boundaries set by governing bodies. Effective compliance risk management helps organizations avoid penalties and ensures that they maintain trust with customers and stakeholders.

What is the difference between Compliance Risk vs Compliance Analyst?

AspectCompliance RiskCompliance Analyst
Primary FocusIdentifying and managing potential compliance risks within an organizationMonitoring, reviewing, and ensuring adherence to compliance policies and regulations
Required CredentialsRisk management certifications, compliance trainingCertifications like CCEP, CAMS, or similar compliance certifications
Work EnvironmentRisk management teams, compliance departments, consulting firmsCorporate compliance departments, financial institutions, healthcare organizations
Industry UsageUsed across industries to assess and mitigate compliance risksCommonly employed in industries with strict regulatory requirements

While Compliance Risk focuses on identifying and mitigating potential compliance issues proactively, Compliance Analysts primarily monitor and ensure ongoing adherence to regulations. Both roles are essential in maintaining organizational compliance but differ in scope and responsibilities.

What cities in California are hiring for Compliance Risk jobs? Cities in California with the most Compliance Risk job openings:

Governance Risk and Compliance

Figma

San Francisco, CA • On-site, Remote

Other

Posted 21 days ago


Job description

Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth.

We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust.

Roles we hire for on this team:

  • Compliance Management
    • Lead compliance and certification programs across security and regulatory frameworks
    • Manage audit cycles, partner with external assessors, and drive audit readiness initiatives
    • Improve controls, processes, and evidence management practices across the organization
  • Security Risk Management
    • Build and maintain risk and controls frameworks that support Figma's security posture
    • Assess, prioritize, and communicate security risks across the business
    • Develop third-party risk management strategies and enterprise risk reporting programs
  • Policy & Governance
    • Manage the lifecycle of organizational security policies, standards, and procedures
    • Drive policy awareness and stakeholder engagement across the company
    • Ensure governance practices align with regulatory requirements and business objectives
  • GRC Platforms & Enablement
    • Select, implement, and optimize GRC platforms and supporting workflows
    • Scale evidence collection, reporting, and program management capabilities
    • Identify opportunities to automate and streamline GRC operations
  • Customer Trust
    • Support customer trust and business enablement activities across the sales lifecycle
    • Manage security knowledge bases, customer-facing documentation, and trust publications
    • Respond to customer security inquiries, audits, and questionnaires

This is a full time role that can be held from one of our US hubs or remotely in the United States. 

What you'll do at Figma:
  • Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2
  • Manage external audits and certification activities while partnering with auditors and assessors
  • Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications
  • Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders
  • Improve control effectiveness and operational efficiency through rationalization and process optimization
  • Implement and optimize GRC platforms that scale evidence collection and program management
  • Maintain security policies and governance processes that align with organizational risk objectives
  • Support customer trust initiatives, including security questionnaires, audits, and customer-facing security communications

We'd love to hear from you if you have:

  • 4+ years of experience in information security, compliance, risk management, or a related field
  • Hands-on experience supporting security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC
  • Experience leading or supporting audits and partnering with external assessors
  • Demonstrated ability to conduct assessments, drive remediation efforts, and manage cross-functional initiatives
  • Exceptional written and verbal communication skills across technical, business, and executive audiences
  • Demonstrated ability to improve processes, manage competing priorities, and build strong cross-functional partnerships

While it's not required, it's an added plus if you also have:

  • Operated in a public company environment with SOX ITGC requirements
  • Supported FedRAMP authorization, SSP development, 3PAO coordination, or continuous monitoring activities
  • Earned security or risk certifications such as CISA, CISSP, CISM, or CRISC
  • Implemented or administered GRC platforms such as Vanta, Drata, or similar tools
  • Scaled security, compliance, or risk programs in a high-growth environment

At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you're excited about this role but your past experience doesn't align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.