Назад
4 дня назад

Senior Platform Security Engineer

196 000 - 245 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Platform Security Engineer (Identity and Access Management): Building secure identity, authorization, and access-management platforms for Discord's internal systems with an accent on Zero Trust architecture, cloud identity, and least-privilege automation. Focus on defining identity for autonomous agents, implementing service-to-service authentication with PKI and mTLS, and hardening software supply chains across CI/CD and production.

Location: San Francisco Bay Area, United States

Salary: $196,000–$245,000 US base salary per year, plus equity and benefits

Company

Discord is a multiplatform gaming and community platform that helps people connect around shared interests and enables developers to build and grow their businesses.

What you will do

  • Own end-to-end software engineering projects focused on platform security and identity management.
  • Define identity, provisioning, authentication, authorization, and auditing for autonomous agents and other non-human actors.
  • Build and evolve Discord's employee authorization platform with discoverable, role-based, least-privilege, and self-service permissions.
  • Design and harden Zero Trust architecture for human and service-to-service authentication across internal tooling.
  • Automate continuous permission right-sizing and develop secure cloud identity baselines.
  • Secure the software supply chain from development environments through CI/CD and production, while advising on threat models, architecture, risk assessments, and code reviews.

Requirements

  • 5+ years of experience building and operating production systems or infrastructure.
  • 3+ years of software development experience in a general-purpose language, particularly Python, TypeScript, or Rust.
  • 3+ years of experience securing systems serving millions of users.
  • Experience building or operating identity and access management systems at scale.
  • Understanding of RBAC, OAuth, OIDC, SSO, Zero Trust architectures, mTLS, and cloud IAM.
  • Experience securing multi-cloud environments such as GCP, Cloudflare, or AWS, and designing software for internal or external customers.

Nice to have

  • Experience with Kubernetes, Docker, Distroless, OCI, Terraform, Bazel, or Buildkite.
  • Experience provisioning service and workload identities with PKI and operating mTLS between services.
  • Experience with Cloudflare Access, Teleport, Vault, cloud KMS, or secrets managers.
  • Experience with distributed systems, service meshes, Linux, Salt, virtual machines, or bare-metal hosts.
  • Experience leading complex migrations or organization-wide risk management programs.

Culture & Benefits

  • Work on security and privacy for a platform used by millions of daily active users.
  • Collaborate across engineering through a highly autonomous and horizontally integrated team.
  • Equity and employee benefits are included in the compensation package.
  • Reasonable accommodations are available during the interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →