Security Analyst
IT
San Francisco, CA, USA
USD 144k-162k / year + Equity
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games.
Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep compliance moving. As we build, that's a mix of hands-on work today and the systems that shrink it over time, because we'd rather automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You'll partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something teams have to fight.
What you'll be doing
- Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers.
- Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment.
- Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are.
- Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand.
- Create the documentation that makes the program usable: internal guidance and updates to our policies, standards, and procedures; company-wide GRC communications; and security training delivered in plain language that people outside the field can follow.
What you should have
- 4+ years in security compliance, GRC, or a closely related field (security operations, IT risk, audit).
- Working familiarity with common frameworks (ISO 27001/27002, SOC 2, PCI DSS, GDPR/CPRA) and a sense of how their requirements turn into day-to-day controls.
- Hands-on experience operating compliance processes: evidence collection, control tracking, risk register upkeep, or security questionnaire response.
- An automation-first instinct. You reach for tooling, integrations, and repeatable workflows to replace manual, repetitive compliance work, not box-checking.
- Comfort living across tools (GRC platforms, ticketing, docs and wikis) and a habit of keeping data clean and organized.
- Clear writing, with a knack for turning dense requirements into guidance people actually use.
- Ability to work across teams and influence without authority in a fast-moving environment with competing priorities.
Bonus points
- Hands-on experience with a GRC platform.
- Exposure to ISO 27701, ISO 42001, or emerging AI compliance work.
- Background in consumer technology, gaming, or online community platforms.
Candidates must reside in or be willing to relocate to the San Francisco Bay Area (Alameda, Contra Costa, Marin, Napa, San Francisco, San Mateo, Santa Clara, Solano, and Sonoma counties). Relocation assistance may be available.
For this role, the Hiring Manager would like folks to be in the office 2 days a week.
The US base salary range for this full-time position is $144,000 to $162,000 + equity + benefits. Our salary ranges are determined by role and level. Within the range, individual pay is determined by additional factors, including job-related skills, experience, and relevant education or training. Please note that the compensation details listed in US role postings reflect the base salary only, and do not include equity, or benefits.
Why Discord?
Discord plays a uniquely important role in the future of gaming. We're a multiplatform, multigenerational and multiplayer platform that helps people deepen their friendships around games and shared interests, and helps developers build and grow their businesses. We believe games give us a way to have fun with our favorite people, whether listening to music together or grinding in competitive matches for diamond rank. Join us in our mission! Your future is just a click away!
Discord is committed to inclusion and providing reasonable accommodations during the interview process. We want you to feel set up for success, so if you are in need of reasonable accommodations, please let your recruiter know.
Please see our Applicant and Candidate Privacy Policy for details regarding Discord’s collection and usage of personal information relating to the application and recruitment process by clicking HERE.
