We are looking for a well-rounded Security Engineer reporting to the Product Security Engineering Manager to join us in identifying, tracking, and resolving threats and vulnerabilities found in the Discord platform to help protect our users and employees. If you are an Engineer with the desire to find and solve complex technical challenges, work with other engineers in the Security and Product departments, a deep sense of curiosity to “find the problem, fix the problem”, and an endless desire to improve Discord, read on!
What you'll do Operate the Bug Bounty Program Validate and triage identified vulnerabilities. Work with teams across Engineering to solve reported problems Track remediation tasks across teams Write code to solve reported problems as necessary Build tools and processes with an emphasis on self-service, automation, and repeatability, to help identify and solve reported issues Who you are You have 2+ years experience securing production applications. You have 1+ years of experience with application security tooling and processes, including code review, static code analysis, penetration testing, or risk management. You have a working knowledge of Application Security concepts and best practices, particularly the OWASP Top 10. You have can program in at least one general purpose programming language (e.g. Python, Rust, or Node). Previous experience with Bug Bounty Programs (HackerOne, Bugcrowd, etc.)
#LI-Remote
The US base salary range for this full-time position is $159,000 to $175,000 + equity + benefits. Our salary ranges are determined by role and level. Within the range, individual pay is determined by additional factors, including job-related skills, experience, and relevant education or training. Please note that the compensation details listed in US role postings reflect the base salary only, and do not include equity, or benefits.