Description
Discord's Legal team is expanding its Security GRC function and seeks a Security Analyst to manage and scale the program. The successful candidate will oversee daily operations, including questionnaires, risk tracking, analyses, tooling, and documentation to ensure compliance. They will collaborate with Security, Engineering, IT, and Legal teams to streamline compliance processes.
Responsibilities
- Manage the customer security questionnaire program from intake to response and develop a reusable answer library.
- Operate risk and control workflows, including triaging risks, tracking gap closures, and maintaining the risk register.
- Conduct GRC analyses to assess standards, procedures, and controls alignment with policies and framework requirements.
- Develop and maintain the GRC toolchain and automation, administering the GRC platform, ticketing, and knowledge bases.
- Create documentation, including internal guidance, policy updates, and security training.
Requirements
- 4+ years of experience in security compliance, GRC, or a related field.
- Hands-on experience with compliance processes, such as evidence collection, control tracking, and security questionnaire response.
- An automation-focused approach to compliance work.
- Proficiency with various tools, including GRC platforms, ticketing systems, and documentation tools.
- Excellent writing and communication skills.
- Ability to work cross-functionally and influence without authority.
Nice to Have
- Experience with a GRC platform.
- Knowledge of ISO 27701, ISO 42001, or AI compliance.
- Background in consumer technology, gaming, or online community platforms.
The role requires residing in or relocating to the San Francisco Bay Area. The position offers a salary range of $144,000 to $162,000, plus equity and benefits. The expected work arrangement involves being in the office 2 days a week.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/discord/jobs/8652553002