Skip to content
DiscordDiscordSan Francisco, CA

Security Analyst

Security Analyst responsible for running Discord's customer security questionnaire program, operating risk and control workflows, performing GRC analyses, building GRC toolchain automation, and creating compliance documentation. Requires 4+ years in security compliance/GRC with familiarity in major frameworks and an automation-first mindset.

144k – 162k/yr
Hybrid4+ YOESecurity Engineering

About the role

What you'll be doing

  • Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers.
  • Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment.
  • Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are.
  • Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand.
  • Create the documentation that makes the program usable: internal guidance and updates to our policies, standards, and procedures; company-wide GRC communications; and security training delivered in plain language that people outside the field can follow.

What you should have

  • 4+ years in security compliance, GRC, or a closely related field (security operations, IT risk, audit).
  • Working familiarity with common frameworks (ISO 27001/27002, SOC 2, PCI DSS, GDPR/CPRA) and a sense of how their requirements turn into day-to-day controls.
  • Hands-on experience operating compliance processes: evidence collection, control tracking, risk register upkeep, or security questionnaire response.
  • An automation-first instinct. You reach for tooling, integrations, and repeatable workflows to replace manual, repetitive compliance work, not box-checking.
  • Comfort living across tools (GRC platforms, ticketing, docs and wikis) and a habit of keeping data clean and organized.
  • Clear writing, with a knack for turning dense requirements into guidance people actually use.
  • Ability to work across teams and influence without authority in a fast-moving environment with competing priorities.

Bonus points

  • Hands-on experience with a GRC platform.
  • Exposure to ISO 27701, ISO 42001, or emerging AI compliance work.
  • Background in consumer technology, gaming, or online community platforms.

Compensation

The US base salary range for this full-time position is $144,000 to $162,000 + equity + benefits.

Skills

GRCISO 27001SOC 2pci dssGDPRcpraRisk Managementcompliance automationsecurity questionnairesrisk registergrc platformsticketing systems
OnePay

Corporate Security Engineer, IAC & Automation

OnePayUnited States

Corporate Security Automation Engineer leading design, implementation, and optimization of security infrastructure using IaC (Terraform), automation, endpoint protection, DLP, and ZTNA in a fast-scaling fintech. Requires 5+ years IT experience with 3+ in enterprise cloud security, scripting, and security frameworks.

140k – 165k/yr
Remote5+ YOESecurity Engineering
Datadog

Security Engineer 2 - Cyber Threat Intelligence

DatadogNew York, NY

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

140k – 195k/yr
HybridSecurity Engineering
Voltus

Security Engineer

VoltusUnited States

Security Engineer building detections, security automation, and infrastructure security on AWS while managing SOC 2 and ISO 27001 compliance. Requires 4-7 years experience with strong AWS and IaC skills.

140k – 160k/yr
Remote4+ YOESecurity Engineering
Panopto

Security Engineer

PanoptoUnited States

Security Engineer embeds security into development lifecycle, conducts threat modeling, builds automated scanning in AWS CI/CD pipelines, leads incident response, and implements compliance controls like ISO 27001. Requires 5+ years experience, AWS mastery, coding in C#/Python, and automation skills.

140k – 150k/yr
Remote5+ YOESecurity Engineering
Scale AI

Infrastructure Security Engineer, Public Sector

Scale AINew York, NY +2

Infrastructure Security Engineer securing large-scale cloud environments, Kubernetes clusters, and infrastructure-as-code (Terraform) for the Public Sector team. Requires active Top Secret clearance, infrastructure security experience, and proficiency in cloud, Kubernetes, and scripting languages.

149k – 342k/yr
On-site5+ YOESecurity Engineering