Staff Software Engineer, Platform Security

DiscordSan Francisco, CA
92d$248,000 - $279,000

About The Position

Discord is used by over 200 million people every month for many different reasons, but there’s one thing that nearly everyone does on our platform: play video games. Over 90% of our users play games, spending a combined 1.5 billion hours playing thousands of unique titles on Discord each month. Discord plays a uniquely important role in the future of gaming. We are focused on making it easier and more fun for people to talk and hang out before, during, and after playing games. Discord is about empowering people to find belonging. Trusted by millions to keep their communications out of the hands of evildoers, we depend on security and privacy for success. Our Platform Security Engineering team protects the people who create Discord and the systems they use to do it, making the “secure way” the “easy way.” We are looking for a Staff Security Engineer, reporting to the Platform Security Engineering Manager, to advance this mission through security expertise, software development, and operational excellence. You’ll articulate and pursue the most leveraged opportunities to reduce security risk across Engineering, bridging organizational boundaries to create secure and lovable “paved paths” for managing identities and access, shipping code, configuring cloud infrastructure, and operating services.

Requirements

  • 7+ years of experience building and operating production systems and infrastructure.
  • 5+ years of experience writing software in at least one general-purpose programming language (we mainly use Python and Rust).
  • 4+ years of experience securing systems with millions of users.
  • Experience as the tech lead for projects involving 3+ engineers and spanning multiple quarters.
  • Experience designing and building user-facing software for customers beyond your immediate team.
  • Experience securing cloud-based environments (e.g. GCP, Cloudflare).
  • Experience with technologies for defining and orchestrating containers (e.g. OCI, Docker, Distroless, Kubernetes).
  • Experience with build and CI/CD technologies (e.g. Bazel, Buildkite, Terraform).
  • Understanding of modern authentication and authorization protocols and concepts (e.g. RBAC, OAuth 2.0, OIDC/SAML, Zero Trust network architectures, mTLS).

Nice To Haves

  • A system to discover industry tools that can multiply your team’s impact.
  • Experience securing multi-cloud environments.
  • Experience developing and debugging distributed systems atop GCP and Cloudflare.
  • Experience building and operating a service mesh (e.g. Envoy, Istio).
  • Experience managing and securing VMs and bare-metal hosts (e.g. Linux, Salt).
  • Experience designing and applying Kubernetes security policies (e.g. OPA Gatekeeper, Kyverno).
  • Experience leading complex migrations or risk management programs across an engineering organization.

Responsibilities

  • Guide strategy and lead software engineering projects on a small, highly-autonomous, horizontally-integrated security team with a lot of leverage.
  • Consult on risk assessments, architectural designs, threat models, code reviews, and more—pragmatically balancing security with other business considerations.
  • Develop and apply best-in-class secure baselines for cloud and bare-metal resources.
  • Secure our first- and third-party software supply chains, from a developer’s laptop through version control and CI/CD and into production.
  • Build and own IAM systems that are user-friendly and promote least privilege.
  • Manage third-party vulnerabilities while supporting rapid growth for Product Engineering.
  • Partner cross-functionally for security monitoring and incident response.

Benefits

  • Equity
  • Comprehensive health benefits
  • Flexible work environment
  • Inclusion and reasonable accommodations during the interview process
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service