PB✓
PBridge

About this role

Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games.

Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep compliance moving. As we build, that's a mix of hands-on work today and the systems that shrink it over time, because we'd rather automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You'll partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something teams have to fight.

What you'll be doing

• Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers.

• Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment.

• Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are.

• Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand.

• Create the documentation that makes the program usable: internal guidance and updates to our policies, standards, and procedures; company-wide GRC communications; and security training delivered in plain language that people outside the field can follow.

What you should have

• 4+ years in security compliance, GRC, or a closely related field (security operations, IT risk, audit).

• Working familiarity with common frameworks (ISO 27001/27002, SOC 2, PCI DSS, GDPR/CPRA) and a sense of how their requirements turn into day-to-day controls.

• Hands-on experience operating compliance processes: evidence collection, control tracking, risk register upkeep, or security questionnaire response.

• An automation-first instinct. You reach for tooling, integrations, and repeatable workflows to replace manual, repetitive compliance work, not box-checking.

• Comfort living across tools (GRC platforms, ticketing, docs and wikis) and a habit of keeping data clean and organized.

• Clear w

Tired of applying one by one?

Our Career Success Team finds roles in the United States that fit you, tailors your CV to each, and submits the applications — tracked end to end. You just show up to interviews.

We apply, you interview →