Senior Platform Security Engineer

Discord

San Francisco (CA)

On-site

USD 196,000 - 245,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Discord seeks a Senior Engineer to advance Platform Security with a focus on identity and access management. You will own end-to-end security projects, define identity for human and non-human actors, and evolve an authorization platform to enforce least privilege and self-serve access.

Ideal candidates have 5+ years building production systems and 3+ years securing services for millions of users across multi-cloud environments, with strong scripting or programming skills in

Qualifications

  • 5+ years building and operating production systems or infrastructure.
  • 3+ years writing software in Python, TypeScript, or Rust.
  • 3+ years securing systems with millions of users.
  • Experience IAM: authentication, authorization, access control at scale.
  • Understanding OAuth/OIDC/SSO, RBAC, Zero Trust concepts.
  • Experience in multi-cloud environments (GCP, AWS, Cloudflare).

Responsibilities

  • Own software projects end-to-end on a highly autonomous team.
  • Define identity for autonomous agents and non-human actors.
  • Build and evolve Access, Discord's employee authorization platform.
  • Design and harden Zero Trust architecture for internal tooling.
  • Automate permission right-sizing following least privilege.
  • Develop secure cloud identity baselines and secure CI/CD pipelines.
  • Consult on risk assessments, designs, threat models, and code reviews.

Skills

Production systems
Python/TypeScript/Rust
IAM at scale
OAuth/OIDC/SSO
Multi-cloud

Tools

Kubernetes
Terraform
Teleport

Job description

Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games.

More broadly, Discord is about empowering people to find belonging in all kinds of communities, and those people trust us to keep their communications safe. Our Platform Security Engineering team protects the systems we use to create Discord, making the "secure way" the "easy way".

We're looking for a Senior Engineer to advance this mission through security expertise, software development, and operational excellence, with a particular focus on identity and access management: who and what can access Discord's systems, how they authenticate, and how access stays scoped to what's actually needed. You'll help identify leveraged opportunities to reduce security risk across Engineering, then design and deliver technical solutions: lovable "paved paths" for managing identities and access, shipping code, configuring cloud infrastructure, and operating services.

If you're a security engineer with a deep interest in identity and access management, who's eager to own technically and socially complex projects, and excited to improve security and privacy at Discord, read on!

What you'll do
  • Own software engineering projects end-to-end on a highly autonomous, horizontally integrated team with a lot of leverage. This is a code-forward role!
  • Define what identity means for autonomous agents and other non-human actors at Discord (how they're provisioned, scoped, authenticated, authorized, and audited). As the role of these actors grows, and create primitives to implement that vision.
  • Build and evolve Access, Discord's employee authorization platform, to make permissions discoverable, role-based, least privilege, and self-serve; check out our blog post to learn more!
  • Design and harden our Zero Trust architecture, spanning human and service-to-service auth*n for Discord’s internal tooling.
  • Automate continuous permission right-sizing in the spirit of least privilege.
  • Develop and apply secure baselines for cloud identity, and help secure our software supply chain from the dev environment through CI/CD and into production.
  • Consult on risk assessments, architectural designs, threat models, code reviews, and more, pragmatically balancing security with other business considerations.
Example projects
  • Integrate service-to-service and agent-to-service authentication and authorization as out-of-the-box features in Discord's internal developer platform.
  • Build out service identity provisioning using PKI and mTLS, so services can authenticate each other without shared secrets.
  • Evaluate or extend infrastructure access tooling such as Teleport for short-lived, auditable access to hosts, databases, and internal systems.
  • Improve how secrets are issued, rotated, and scoped across our infrastructure.
What we look for
  • 5+ years of experience building and operating production systems or infrastructure
  • 3+ years of experience writing software in a general-purpose programming language (we mainly use Python, TypeScript, and Rust)
  • 3+ years of experience securing systems with millions of users
  • Experience building or operating identity and access management systems: authentication, authorization, or access control at scale
  • Understanding of modern authentication and authorization concepts (e.g. RBAC, OAuth, OIDC, SSO, Zero Trust network architectures, mTLS, cloud IAM)
  • Experience building in and securing multi-cloud environments (e.g. GCP, Cloudflare, AWS)
  • Experience designing and building software for customers (internal or external) beyond your immediate team
Bonus points if you have…
  • Experience defining and orchestrating containers (e.g. via Kubernetes, Docker, Distroless, OCI)
  • Familiarity with build and CI/CD technologies (e.g. Terraform, Bazel, Buildkite)
  • Provisioned or managed service and workload identity using PKI, including issuing and operating mTLS between services
  • Experience with Zero Trust platforms such as Cloudflare Access and Teleport, for auditable access to apps, hosts, and internal systems
  • Experience with secrets management systems (e.g. Vault, or a cloud KMS or secrets manager), including rotation and least-privilege access to secrets
  • Developed and debugged distributed systems atop GCP, Cloudflare, and/or AWS
  • Led complex migrations or risk management programs across an engineering organization
  • Built or operated a service mesh (e.g. Envoy, Istio)
  • Managed and secured VMs or bare-metal hosts (e.g. Linux, Salt)
  • Practices to discover industry tools and knowledge that can multiply your team's impact

The US base salary range for this full-time position is $196,000 to $245,000 + equity + benefits. Our salary ranges are determined by role and level. Within the range, individual pay is determined by additional factors, including job-related skills, experience, and relevant education or training. Please note that the compensation details listed in US role postings reflect the base salary only, and do not include equity, or benefits.

Why Discord?

Discord plays a uniquely important role in the future of gaming. We're a multiplatform, multigenerational and multiplayer platform that helps people deepen their friendships around games and shared interests, and helps developers build and grow their businesses. We believe games give us a way to have fun with our favorite people, whether listening to music together or grinding in competitive matches for diamond rank.

Discord is committed to inclusion and providing reasonable accommodations during the interview process. We want you to feel set up for success, so if you are in need of reasonable accommodations, please let your recruiter know.

Please see our Applicant and Candidate Privacy Policy for details regarding Discord’s collection and usage of personal information relating to the application and recruitment process by clicking HERE.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Platform Security Engineer
Senior Platform Security Engineer

Triwill Group • San Francisco (CA), Northern (KY)

Hybrid
USD 196,000 - 245,000
Senior Platform Security Engineer
Senior Platform Security Engineer

Discord Inc. • San Francisco (CA)

On-site
USD 196,000 - 245,000
Senior Platform Security Engineer
Senior Platform Security Engineer

JobCubby • San Francisco (CA), Northern (KY)

Hybrid
USD 196,000 - 245,000
Senior Platform Security Engineer
Senior Platform Security Engineer

Jackalope Digital LLC • San Francisco (CA), Northern (KY)

Hybrid
USD 196,000 - 245,000
Engineering Manager, Platform Security
Engineering Manager, Platform Security

Discord Inc. • San Francisco (CA)

On-site
USD 248,000 - 310,000
Equity
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

Discord Inc. • San Francisco (CA)

On-site
USD 196,000 - 221,000
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

Discord • United States

On-site
USD 196,000 - 245,000
Equity
Relocation assistance
Benefits
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

BITKRAFT Ventures • San Francisco (CA)

On-site
USD 196,000 - 221,000
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

EngineersOfAI • San Francisco (CA)

On-site
USD 196,000 - 221,000
Equity
Benefits
Senior Software Engineer, Application Security
Senior Software Engineer, Application Security

Discord • San Francisco (CA)

On-site
USD 196,000 - 220,500