InterviewHack.ai

Security Analyst

Discord · San Francisco Bay Area

Apply on company site
<div class=&quot;content-intro&quot;><p>Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: <strong>play video games.</strong> Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games.</p></div><p>Discord s Legal team is growing its Security GRC function, and we re looking for a Security Analyst to help run and scale it. You ll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep compliance moving. As we build, that s a mix of hands-on work today and the systems that shrink it over time, because we d rather automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You ll partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something teams have to fight.</p> <h3>What you ll be doing</h3> <ul> <li>Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers.</li> <li>Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You ll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment.</li> <li>Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are.</li> <li>Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand.</li> <li>Create the documentation that makes the program usable: internal guidance and updates to our policies, standards, and procedures; company-wide GRC communications; and security training delivered in plain language that people outside the field can follow.</li> </ul> <h3>What you should have</h3> <ul> <li>4+ years in security compliance, GRC, or a closely related field (security operations, IT risk, audit).</li> <li>Working familiarity with common frameworks (ISO 27001/27002, SOC 2, PCI DSS, GDPR/CPRA) and a sense of how their requirements turn into day-to-day controls.</li> <li>Hands-on experience operating compliance processes: evidence collection, control tracking, risk register upkeep, or security questionnaire response.</li> <li>An automation-first instinct. You reach for tooling, integrations, and repeatable workflows to replace manual, repetitive compliance work, not box-checking.</li> <li>Comfort living across tools (GRC platforms, ticketing, docs and wikis) and a habit of keeping data clean and organized.</li> <li>Clear writing, with a knack for turning dense requirements into guidance people actually use.</li> <li>Ability to work across teams and influence without authority in a fast-moving environment with competing priorities.</li> </ul> <h3>Bonus points</h3> <ul> <li>Hands-on experience with a GRC platform.</li> <li>Exposure to ISO 27701, ISO 42001, or emerging AI compliance work.</li> <li>Background in consumer technology, gaming, or online community platforms.</li> </ul> <p><span style=&quot;font-family: helvetica, arial, sans-serif; font-size: 12pt;&quot;><em>Candidates must reside in or be willing to relocate to the San Francisco Bay Area (Alameda, Contra Costa, Marin, Napa, San Francisco, San Mateo, Santa Clara, Solano, and Sonoma counties). Relocation assistance may be available.</em></span></p> <p><span style=&quot;font-family: h

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.