Skip to content
DiscordDiscordSan Francisco, CA

Threat Investigator

Lead complex investigations into violent extremist and threat actor networks on Discord. Develop detection and disruption strategies, collaborate with policy, engineering, and ML teams, and serve as a subject matter expert on evolving threats. Requires 5+ years in threat intelligence or investigations.

132k – 149k/yr
On-site5+ YOESecurity Engineering

About the role

What You'll Be Doing

  • Leading complex investigations into violent extremist and threat actor networks, developing and iterating on detection and disruption strategies across your investigative portfolio
  • Executing on roadmap projects, including cross-functional coordination with policy, engineering, and ML/AI teams, documentation of behavioral trends, and identification of scalable mitigation strategies
  • Leveraging investigative signals and subject matter expertise to inform threat prioritization decisions
  • Identifying emergence of novel harm behaviors, and gaps in Discord's detection, policy, and enforcement capabilities
  • Partnering with team program managers to develop and prioritize improvements to operational readiness
  • Serving as a subject matter resource for teammates, leadership, and cross-functional partners

What You Should Have

  • 5+ years of experience in threat intelligence, investigations, or incident management, with a track record of leading complex, multi-stakeholder cases independently
  • Deep expertise in at least one extremist or violent threat actor ecosystem, with the analytical flexibility to develop proficiency across new harm verticals as priorities shift
  • Demonstrated ability to define scope, propose solutions, and drive projects to completion in ambiguous, high-change environments with minimal oversight
  • Proficiency with data analysis tools, case management systems, and machine learning tooling to support network investigations and detection work
  • Strong written and verbal communication skills, including the ability to translate complex, sensitive topics for non-expert audiences, and experience producing cross-functional product requests, intelligence products, and engaging with law enforcement, government, or external partners
  • Collaborative approach to cross-functional work, with the ability to build consensus and coordinate across teams and time zones

Bonus Points

  • Additional language proficiency, particularly in languages relevant to high-harm threat actor communities
  • Experience translating investigative findings into clear, actionable insights for non-expert or executive audiences

The US base salary range for this full-time position is $132,000 to $148,500 + equity + benefits.

Skills

threat intelligenceinvestigationsIncident ManagementData AnalysisMachine Learningcase management systemsCross-Functional Coordination
Writer

Security engineer, detection and response

WriterSan Francisco, CA +2

Staff Detection and Response Engineer protecting Writer's AI infrastructure and models from threats like prompt injection, data poisoning, and model extraction. Build detections, automated response playbooks, lead incident response and proactive hunting across GPU clusters and training environments.

132k – 258k/yrHybrid5+ YOESecurity Engineering
NinjaTrader

GRC Engineer

NinjaTraderChicago, IL

Mid-level GRC Engineer building automation and tooling to scale compliance for SOC 2, ISO 27001, and SOX. Hands-on role combining scripting, audit coordination, risk management, and cross-functional partnership with engineering teams.

130k – 145k/yrHybrid3+ YOESecurity Engineering
Mercor

Security Engineer, Cloud Infrastructure

MercorSan Francisco, CA +1

Designs and implements cloud security architectures including multi-account AWS isolation, Kubernetes hardening, and CSPM with Wiz for enterprise tenant separation. Requires 5+ years in cloud/infrastructure security, IaC expertise, and production experience.

130k – 500k/yrHybrid5+ YOESecurity Engineering
Mercor

Security Engineer, Application Security

MercorSan Francisco, CA +1

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

130k – 500k/yrOn-site5+ YOESecurity Engineering
Coinbase

Insider Threat Analyst

CoinbaseUnited States

Insider Threat Analyst responsible for triaging alerts, conducting investigations, and mitigating insider risks using SIEM, UBA, and DLP tools. Requires 3+ years in security operations or investigations with strong cross-functional collaboration skills.

135k – 159k/yrRemote3+ YOESecurity Engineering