Governance Risk And Compliance Jobs in California
Governance Risk And Compliance jobs in California represent one of the most active markets in the country, concentrated in financial services, technology, healthcare, and defense contracting across a seniority range from analyst and associate through chief compliance officer. San Francisco, Los Angeles, and San Diego are the primary hiring hubs, where major employers such as Wells Fargo, Kaiser Permanente, and Qualcomm maintain substantial compliance and risk functions. The most in-demand specialties include enterprise risk management, regulatory compliance for fintech and biotech, and cybersecurity governance. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 6+ Governance Risk And Compliance jobs











INTRODUCTION
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth. We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust.
ROLE AND RESPONSIBILITIES
Roles we hire for on this team:
- Compliance Management:
- Lead compliance and certification programs across security and regulatory frameworks
- Manage audit cycles, partner with external assessors, and drive audit readiness initiatives
-
Improve controls, processes, and evidence management practices across the organization
-
Security Risk Management:
- Build and maintain risk and controls frameworks that support Figma's security posture
- Assess, prioritize, and communicate security risks across the business
-
Develop third-party risk management strategies and enterprise risk reporting programs
-
Policy & Governance:
- Manage the lifecycle of organizational security policies, standards, and procedures
- Drive policy awareness and stakeholder engagement across the company
-
Ensure governance practices align with regulatory requirements and business objectives
-
GRC Platforms & Enablement:
- Select, implement, and optimize GRC platforms and supporting workflows
- Scale evidence collection, reporting, and program management capabilities
-
Identify opportunities to automate and streamline GRC operations
-
Customer Trust:
- Support customer trust and business enablement activities across the sales lifecycle
- Manage security knowledge bases, customer-facing documentation, and trust publications
- Respond to customer security inquiries, audits, and questionnaires
This is a full time role that can be held from one of our US hubs or remotely in the United States.
What you'll do at Figma:
- Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2
- Manage external audits and certification activities while partnering with auditors and assessors
- Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications
- Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders
- Improve control effectiveness and operational efficiency through rationalization and process optimization
- Implement and optimize GRC platforms that scale evidence collection and program management
- Maintain security policies and governance processes that align with organizational risk objectives
- Support customer trust initiatives, including security questionnaires, audits, and customer-facing security communications
BASIC QUALIFICATIONS
We’d love to hear from you if you have:
- 4+ years of experience in information security, compliance, risk management, or a related field
- Hands-on experience supporting security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC
- Experience leading or supporting audits and partnering with external assessors
- Demonstrated ability to conduct assessments, drive remediation efforts, and manage cross-functional initiatives
- Exceptional written and verbal communication skills across technical, business, and executive audiences
- Demonstrated ability to improve processes, manage competing priorities, and build strong cross-functional partnerships
PREFERRED QUALIFICATIONS
While it’s not required, it’s an added plus if you also have:
- Operated in a public company environment with SOX ITGC requirements
- Supported FedRAMP authorization, SSP development, 3PAO coordination, or continuous monitoring activities
- Earned security or risk certifications such as CISA, CISSP, CISM, or CRISC
- Implemented or administered GRC platforms such as Vanta, Drata, or similar tools
- Scaled security, compliance, or risk programs in a high-growth environment
At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.
COMPENSATION
If based in Figma’s San Francisco or New York hub offices, this role has the annual base salary range stated below. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information.
- Annual Base Salary Range: $153,000—$296,000 USD
Figma offers equity to employees, as well a competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave & reproductive or family planning support, mental health & wellness benefits, generous PTO, company recharge days, a learning & development stipend, a work from home stipend, and cell phone reimbursement. Figma also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Figma’s compensation and benefits are subject to change and may be modified in the future.
At Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.
We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities. Examples of accommodations include but are not limited to:
- Holding interviews in an accessible location
- Enabling closed captioning on video conferencing
- Ensuring all written communication be compatible with screen readers
- Changing the mode or format of interviews
To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding.
By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with Figma's Candidate Privacy Notice.
See All 6 Governance Risk And Compliance Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find JobsGovernance Risk And Compliance Jobs by City in California
Where California roles are concentrated, by current openings.
Governance Risk And Compliance Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring
- Decagon1

- DocuSign1

- Figma1

- Ivalua1

- Revolution Medicines1

Top Industries Hiring
- Technology & Software5
- Biotechnology & Pharmaceuticals1
What California Employers Look For
The qualifications that appear most often in governance risk and compliance jobs across California.
- Bachelor's degree in business, finance, law, or a related field required
- Certified Compliance and Ethics Professional or CISA certification strongly preferred
- Three or more years of experience in risk, audit, or regulatory compliance functions
- Working knowledge of California-specific regulations including CCPA and DFPI requirements
- Demonstrated experience conducting risk assessments, audits, or internal control reviews
- Familiarity with frameworks such as COSO, ISO 31000, or NIST for governance programs
Governance Risk And Compliance Jobs in California: Frequently Asked Questions
How do you become a governance risk and compliance in California?
Most governance risk and compliance roles in California require at minimum a bachelor's degree in business administration, finance, accounting, law, or a related field. From there, employers consistently favor candidates who hold recognized credentials such as the Certified Compliance and Ethics Professional designation, the Certified Internal Auditor certification, or ISACA's CISA or CRISC for technology-focused roles. California's large regulated industries, including banking supervised by the Department of Financial Protection and Innovation and healthcare oversight under DHCS, create strong demand for professionals who understand state-specific regulatory frameworks alongside federal requirements.
Which companies hire governance risk and compliances in California?
Employers hiring governance risk and compliances in California right now include Decagon, DocuSign, and Figma, based on current listings on Migrate Mate as of June 2026. California's dense concentration of publicly traded technology companies, major banks, and large health systems means governance risk and compliance hiring tends to be broad and consistent throughout the year.
Which California cities have the most governance risk and compliance jobs?
San Francisco, Redwood City, and San Francisco Bay Area have the most governance risk and compliance openings in California. San Francisco leads due to its concentration of financial services firms, fintech startups, and technology companies with extensive regulatory obligations, while Los Angeles draws volume from entertainment, healthcare, and aerospace, and San Diego's strength in biotech and defense contracting sustains steady demand for compliance professionals in those sectors.
Are there remote governance risk and compliance jobs in California?
Yes, and more than most fields. About 67% of governance risk and compliance openings tied to California are remote or hybrid as of June 2026, reflecting that much of the work involves policy review, documentation, risk assessments, and regulatory analysis that can be done without a fixed office. Policy development, third-party risk management, and compliance monitoring roles tend to be the most consistently available in remote or hybrid formats.
How can I get hired as a governance risk and compliance in California with little or no experience?
The most realistic entry path is moving from an adjacent role in internal audit, legal operations, finance, or IT security into a compliance analyst or junior risk associate position. Large California employers including major Bay Area technology companies, Kaiser Permanente, and the larger regional banks regularly post associate compliance and risk analyst roles that are structured for candidates with a relevant degree but limited direct experience. Earning an entry-level credential such as the CAMS for financial crime or the CompTIA Security Plus for cybersecurity governance noticeably strengthens applications, as does any internship or co-op experience with a California-regulated industry.
Where can I find and apply to governance risk and compliance jobs in California?
You can find and apply to governance risk and compliance jobs in California on Migrate Mate, which lists current California openings across industries and seniority levels. Find the roles that fit your background and apply directly.
See All 6 Governance Risk And Compliance Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Jobs