Green Card Governance Risk And Compliance Jobs
Governance, risk, and compliance roles qualify for EB-2 and EB-3 green card sponsorship through PERM labor certification when employers demonstrate no qualified U.S. workers are available. GRC professionals with advanced degrees in finance, law, or risk management typically pursue EB-2, while experienced analysts without graduate credentials often qualify under EB-3 skilled worker.
Find Green Card Governance Risk And Compliance JobsOverview
Showing 5 of 54+ Governance Risk And Compliance jobs










See all 54+ Governance Risk And Compliance Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Governance Risk And Compliance roles.
Get Access To All Jobs
INTRODUCTION
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth. We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust.
ROLE AND RESPONSIBILITIES
Roles we hire for on this team:
* Compliance Management
- Lead compliance and certification programs across security and regulatory frameworks
- Manage audit cycles, partner with external assessors, and drive audit readiness initiatives
- Improve controls, processes, and evidence management practices across the organization
- Security Risk Management
- Build and maintain risk and controls frameworks that support Figma's security posture
- Assess, prioritize, and communicate security risks across the business
-
Develop third-party risk management strategies and enterprise risk reporting programs
-
Policy & Governance
- Manage the lifecycle of organizational security policies, standards, and procedures
- Drive policy awareness and stakeholder engagement across the company
-
Ensure governance practices align with regulatory requirements and business objectives
-
GRC Platforms & Enablement
- Select, implement, and optimize GRC platforms and supporting workflows
- Scale evidence collection, reporting, and program management capabilities
-
Identify opportunities to automate and streamline GRC operations
-
Customer Trust
- Support customer trust and business enablement activities across the sales lifecycle
- Manage security knowledge bases, customer-facing documentation, and trust publications
- Respond to customer security inquiries, audits, and questionnaires
This is a full time role that can be held from one of our US hubs or remotely in the United States.
What you'll do at Figma:
Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2
Manage external audits and certification activities while partnering with auditors and assessors
Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications
Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders
Improve control effectiveness and operational efficiency through rationalization and process optimization
Implement and optimize GRC platforms that scale evidence collection and program management
Maintain security policies and governance processes that align with organizational risk objectives
Support customer trust initiatives, including security questionnaires, audits, and customer-facing security communications
BASIC QUALIFICATIONS
We’d love to hear from you if you have:
4+ years of experience in information security, compliance, risk management, or a related field
Hands-on experience supporting security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC
Experience leading or supporting audits and partnering with external assessors
Demonstrated ability to conduct assessments, drive remediation efforts, and manage cross-functional initiatives
Exceptional written and verbal communication skills across technical, business, and executive audiences
Demonstrated ability to improve processes, manage competing priorities, and build strong cross-functional partnerships
PREFERRED QUALIFICATIONS
While it’s not required, it’s an added plus if you also have:
Operated in a public company environment with SOX ITGC requirements
Supported FedRAMP authorization, SSP development, 3PAO coordination, or continuous monitoring activities
Earned security or risk certifications such as CISA, CISSP, CISM, or CRISC
Implemented or administered GRC platforms such as Vanta, Drata, or similar tools
* Scaled security, compliance, or risk programs in a high-growth environment
At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.
COMPENSATION
Pay Transparency Disclosure
If based in Figma’s San Francisco or New York hub offices, this role has the annual base salary range stated below. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information.
Annual Base Salary Range: $153,000—$296,000 USD
Figma offers equity to employees, as well a competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave & reproductive or family planning support, mental health & wellness benefits, generous PTO, company recharge days, a learning & development stipend, a work from home stipend, and cell phone reimbursement. Figma also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Figma’s compensation and benefits are subject to change and may be modified in the future.
At Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.
We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities. Examples of accommodations include but are not limited to:
Holding interviews in an accessible location
Enabling closed captioning on video conferencing
Ensuring all written communication be compatible with screen readers
Changing the mode or format of interviews
To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding.
By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with Figma's Candidate Privacy Notice.
See all 54+ Green Card Governance Risk And Compliance Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Green Card Governance Risk And Compliance Jobs.
Get Access To All JobsTips for Finding Green Card Sponsorship in Governance Risk And Compliance
Credential your specialized certifications before applying
CISA, CRISC, CISM, and CFE designations strengthen your PERM case by demonstrating specialized qualifications beyond a standard degree. Document each certification with official transcripts and issuing-body letters before your employer opens the labor certification process.
Target employers with dedicated compliance functions
Banks, insurance carriers, healthcare networks, and publicly traded manufacturers maintain standalone GRC teams and routinely sponsor foreign workers. Employers with formal compliance programs are far more likely to have HR infrastructure that understands PERM filings.
Search sponsoring employers using Migrate Mate
Filter Migrate Mate by GRC job titles and green card sponsorship history to find employers who have filed PERM applications for compliance roles, saving weeks of manual research into DOL disclosure data.
Verify the prevailing wage tier before accepting an offer
Your employer must pay at least the DOL-determined prevailing wage for your specific SOC code and location. Use OFLC Wage Search to look up the Level I through Level IV wage bands for your GRC title before salary negotiations close.
Clarify the employer job description matches PERM requirements
PERM job postings must state the minimum requirements actually needed for the role, not inflated credentials. A mismatch between what your employer lists and what USCIS expects for EB-2 advanced-degree professionals can trigger an audit before your I-140 is filed.
Understand how concurrent filing affects your timeline
If your priority date is current for your country of birth, your employer can file the I-140 and your I-485 adjustment of status simultaneously, cutting months off the wait for work authorization while your green card processes.
Green Card Governance Risk And Compliance: Frequently Asked Questions
Do governance, risk, and compliance roles qualify for EB-2 or EB-3 green card sponsorship?
Most GRC positions qualify under EB-2 when the role requires an advanced degree in a field like finance, law, accounting, or information security. Roles filled by professionals with a bachelor's degree plus five or more years of specialized experience typically qualify under EB-3. Your employer's attorney determines the category based on the actual minimum requirements of the position, not your personal credentials.
How does PERM green card sponsorship differ from H-1B for a compliance professional?
PERM sponsorship leads to permanent residency rather than a temporary status, and EB-3 green cards have no annual lottery. The tradeoff is time: PERM labor certification alone takes six months to a year before the I-140 petition is even filed. H-1B visa approval can happen in weeks and provides immediate work authorization, but it caps out at six years without a green card in progress.
What does the PERM labor certification process require from a GRC employer?
Your employer must conduct a good-faith recruitment campaign, including job postings, newspaper ads, and internal notice, proving no qualified U.S. worker was available. For GRC roles, DOL scrutinizes whether the posted minimum requirements are genuinely necessary and whether the offered wage meets the prevailing wage for that specific compliance SOC code and work location.
Where can I find employers who sponsor green cards for compliance and risk roles?
Migrate Mate lets you search specifically for GRC positions where employers have a documented history of PERM filings, so you're not applying blind. Financial institutions, healthcare systems, and government contractors are frequent sponsors because their regulatory obligations create ongoing demand for compliance professionals that can't always be filled domestically.
Can my priority date affect how long it takes to get a green card in a GRC role?
Yes. Your priority date is set when USCIS receives your I-140 petition, and how long you wait for a green card depends entirely on your country of birth and the monthly Visa Bulletin cutoff dates. Most countries other than India and China see relatively short waits at EB-3, but Indian-born GRC professionals can face multi-year backlogs regardless of how quickly the PERM process finishes.