Staff Software Engineer, Platform Security

11 Minutes ago • 7 Years + • $248,000 PA - $279,000 PA
Cyber Security

Job Description

Discord is seeking a Staff Security Engineer for its Platform Security Engineering team in the San Francisco Bay Area. This role involves advancing security through expertise, software development, and operational excellence, focusing on reducing security risk across Engineering. The engineer will guide strategy, lead software projects, consult on risk assessments, develop secure baselines for cloud resources, secure software supply chains, build IAM systems, manage vulnerabilities, and partner for security monitoring and incident response. The ideal candidate has a passion for security, deep curiosity, and experience with complex projects, aiming to create secure and user-friendly solutions.
Good To Have:
  • System to discover industry tools that can multiply your team’s impact.
  • Experience securing multi-cloud environments.
  • Developed and debugged distributed systems atop GCP and Cloudflare.
  • Built and operated a service mesh (e.g., Envoy, Istio).
  • Managed and secured VMs and bare-metal hosts (e.g., Linux, Salt).
  • Designed and applied Kubernetes security policies (e.g., OPA Gatekeeper, Kyverno).
  • Led complex migrations or risk management programs across an engineering organization.
Must Have:
  • Guide strategy and lead software engineering projects on a small, highly-autonomous security team.
  • Consult on risk assessments, architectural designs, threat models, and code reviews.
  • Develop and apply best-in-class secure baselines for cloud and bare-metal resources.
  • Secure first- and third-party software supply chains, from developer laptop through CI/CD to production.
  • Build and own user-friendly IAM systems that promote least privilege.
  • Manage third-party vulnerabilities while supporting rapid growth for Product Engineering.
  • Partner cross-functionally for security monitoring and incident response.
  • 7+ years of experience building and operating production systems and infrastructure.
  • 5+ years of experience writing software in at least one general-purpose programming language (Python, Rust).
  • 4+ years of experience securing systems with millions of users.
  • Experience as a tech lead for projects involving 3+ engineers and spanning multiple quarters.
  • Experience designing and building user-facing software for customers beyond your immediate team.
  • Experience securing cloud-based environments (e.g., GCP, Cloudflare).
  • Experience with technologies for defining and orchestrating containers (e.g., OCI, Docker, Distroless, Kubernetes).
  • Experience with build and CI/CD technologies (e.g., Bazel, Buildkite, Terraform).
  • Understanding of modern authentication and authorization protocols and concepts (e.g., RBAC, OAuth 2.0, OIDC/SAML, Zero Trust network architectures, mTLS).
Perks:
  • Equity
  • Benefits
  • Opportunity to work on a multiplatform, multigenerational, and multiplayer platform.
  • Help people deepen their friendships around games and shared interests.
  • Committed to inclusion and providing reasonable accommodations during the interview process.

Add these skills to join the top 1% applicants for this job

risk-management
talent-acquisition
game-texts
oauth
incident-response
linux
rust
service-mesh
terraform
ci-cd
docker
kubernetes
python
multiplayer

Discord is used by over 200 million people every month for many different reasons, but there’s one thing that nearly everyone does on our platform: play video games. Over 90% of our users play games, spending a combined 1.5 billion hours playing thousands of unique titles on Discord each month. Discord plays a uniquely important role in the future of gaming. We are focused on making it easier and more fun for people to talk and hang out before, during, and after playing games.

Discord is about empowering people to find belonging. Trusted by millions to keep their communications out of the hands of evildoers, we depend on security and privacy for success. Our Platform Security Engineering team protects the people who create Discord and the systems they use to do it, making the “secure way” the “easy way.”

We are looking for a Staff Security Engineer, reporting to the Platform Security Engineering Manager, to advance this mission through security expertise, software development, and operational excellence. You’ll articulate and pursue the most leveraged opportunities to reduce security risk across Engineering, bridging organizational boundaries to create secure and lovable “paved paths” for managing identities and access, shipping code, configuring cloud infrastructure, and operating services.

If you are a security engineer with a passion for security and privacy, deep curiosity, eagerness to own technically and socially complex projects, and a strong desire to improve Discord, read on!

What you'll do

  • Guide strategy and lead software engineering projects on a small, highly-autonomous, horizontally-integrated security team with a lot of leverage. This is a code-forward role!
  • Consult on risk assessments, architectural designs, threat models, code reviews, and more—pragmatically balancing security with other business considerations.
  • Develop and apply best-in-class secure baselines for cloud and bare-metal resources.
  • Secure our first- and third-party software supply chains, from a developer’s laptop through version control and CI/CD and into production.
  • Build and own IAM systems that are user-friendly and promote least privilege.
  • Manage third-party vulnerabilities while supporting rapid growth for Product Engineering.
  • Partner cross-functionally for security monitoring and incident response.

Example Projects

Who you are

  • You have 7+ years of experience building and operating production systems and infrastructure.
  • You have 5+ years of experience writing software in at least one general-purpose programming language (we mainly use Python and Rust).
  • You have 4+ years of experience securing systems with millions of users.
  • You have been the tech lead for projects involving 3+ engineers and spanning multiple quarters.
  • You have designed and built user-facing software for customers beyond your immediate team.
  • You have experience securing cloud-based environments (e.g. GCP, Cloudflare).
  • You have experience with technologies for defining and orchestrating containers (e.g. OCI, Docker, Distroless, Kubernetes).
  • You have experience with build and CI/CD technologies (e.g. Bazel, Buildkite, Terraform).
  • You understand modern authentication and authorization protocols and concepts (e.g. RBAC, OAuth 2.0, OIDC/SAML, Zero Trust network architectures, mTLS).

Bonus points

  • You have a system to discover industry tools that can multiply your team’s impact.
  • You have experience securing multi-cloud environments.
  • You have developed and debugged distributed systems atop GCP and Cloudflare.
  • You have built and operated a service mesh (e.g. Envoy, Istio).
  • You have managed and secured VMs and bare-metal hosts (e.g. Linux, Salt).
  • You have designed and applied Kubernetes security policies (e.g. OPA Gatekeeper, Kyverno).
  • You have led complex migrations or risk management programs across an engineering organization.

The US base salary range for this full-time position is $248,000 to $279,000 + equity + benefits. Our salary ranges are determined by role and level. Within the range, individual pay is determined by additional factors, including job-related skills, experience, and relevant education or training. Please note that the compensation details listed in US role postings reflect the base salary only, and do not include equity, or benefits.

Why Discord?

Discord plays a uniquely important role in the future of gaming. We're a multiplatform, multigenerational and multiplayer platform that helps people deepen their friendships around games and shared interests. We believe games give us a way to have fun with our favorite people, whether listening to music together or grinding in competitive matches for diamond rank. Join us in our mission! Your future is just a click away!

Discord is committed to inclusion and providing reasonable accommodations during the interview process. We want you to feel set up for success, so if you are in need of reasonable accommodations, please let your recruiter know.

Please see our Applicant and Candidate Privacy Policy for details regarding Discord’s collection and usage of personal information relating to the application and recruitment process by clicking HERE._

Set alerts for more jobs like Staff Software Engineer, Platform Security
Set alerts for new jobs by Discord
Set alerts for new Cyber Security jobs in United States
Set alerts for new jobs in United States
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙