Senior Platform Security Engineer
Discord · San Francisco Bay Area
About this role
**Senior Platform Security Engineer** Discord is focused on making it easier and more fun for people to hang out before, during, and after playing games—while keeping communications safe. Our Platform Security Engineering team protects the systems that power Discord, making the “secure way” the “easy way.” We’re looking for a **Senior Engineer** to advance this mission with a particular focus on **identity and access management**: who and what can access Discord’s systems, how they authenticate, and how access stays scoped to what’s actually needed. You’ll identify leveraged opportunities to reduce security risk across Engineering, then design and deliver technical solutions—shipping code, configuring cloud infrastructure, and operating services. --- ### What you’ll do - Own software engineering projects end-to-end on a highly autonomous, horizontally integrated team with a lot of leverage. *(This is a code-forward role!)* - Define what identity means for autonomous agents and other non-human actors at Discord (provisioning, scoping, authentication, authorization, and auditing), and create primitives to implement that vision. - Build and evolve **Access**, Discord’s employee authorization platform, to make permissions discoverable, role-based, least privilege, and self-serve. - Design and harden our **Zero Trust** architecture across human and service-to-service auth for Discord’s internal tooling. - Automate continuous permission right-sizing in the spirit of least privilege. - Develop and apply secure baselines for cloud identity, and help secure the software supply chain from dev environment through CI/CD into production. - Consult on risk assessments, architectural designs, threat models, code reviews, and more—pragmatically balancing security with business needs. ### Example projects - Integrate service-to-service and agent-to-service authentication and authorization as out-of-the-box features in Discord’s internal developer platform. - Build service identity provisioning using **PKI** and **mTLS** so services can authenticate each other without shared secrets. - Evaluate or extend infrastructure access tooling such as **Teleport** for short-lived, auditable access to hosts, databases, and internal systems. - Improve how secrets are issued, rotated, and scoped across infrastructure. --- ### What we look for - **5+ years** building and operating production systems or infrastructure - **3+ years** writing software in a general-purpose language (primarily **Python, TypeScript, Rust**) - **3+ years** securing systems with millions of users - Experience building or operating identity and access management systems (authentication, authorization, or access control at scale) - Understanding of modern authentication/authorization concepts (e.g., **RBAC, OAuth, OIDC, SSO, Zero Trust, mTLS, cloud IAM**) - Experience building in and securing **multi-cloud** environments (e.g., **GCP, Cloudflare, AWS**) - Experience designing and building software for customers (internal or external) beyond your immediate team ### Bonus points if you have… - Experience defining and orchestrating containers (e.g., **Kubernetes, Docker, Distroless, OCI**) - Familiarity with build and CI/CD technologies (e.g., **Terraform, Bazel, Buildkite**) - Provisioned/managed service and workload identity using **PKI**, including issuing and operating mTLS between services - Experience with Zero Trust platforms such as **Cloudflare Access** and **Teleport** - Experien
Listing freshness
CronJobs last confirmed this listing 21h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.