
Discord · San Francisco Bay Area
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly ever...
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but
there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming,
and we are focused on making it easier and more fun for people to hang out before, during, and after playing games.
Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it.
You'll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep
compliance moving. As we build, that's a mix of hands-on work today and the systems that shrink it over time, because we'd rather
automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You'll
partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something
teams have to fight.
that turns repeat questions into fast, near-self-service answers.
the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and
escalating the ones that need senior judgment.
requirements; where the gaps are; and how mature and effective our controls actually are.
design the integrations and workflows that collect evidence and check controls by default rather than by hand.
procedures; company-wide GRC communications; and security training delivered in plain language that people outside the field
can follow.
turn into day-to-day controls.
questionnaire response.
compliance work, not box-checking.
Candidates must reside in or be willing to relocate to the San Francisco Bay Area (Alameda, Contra Costa, Marin, Napa, San
Francisco, San Mateo, Santa Clara, Solano, and Sonoma counties). Relocation assistance may be available.
For this role, the Hiring Manager would like folks to be in the office 2 days a week.
The US base salary range for this full-time position is $144,000 to $162,000 + equity + benefits. Our salary ranges are determined
by role and level. Within the range, individual pay is determined by additional factors, including job-related skills, experience,
and relevant education or training. Please note that the compensation details listed in US role postings reflect the base salary
only, and do not include equity, or benefits.
Why Discord?
Discord plays a uniquely important role in the future of gaming. We're a multiplatform, multigenerational and multiplayer platform
that helps people deepen their friendships around games and shared interests, and helps developers build and grow their
businesses. We believe games give us a way to have fun with our favorite people, whether listening to music together or grinding
in competitive matches for diamond rank. Join us in our mission! Your future is just a click away!
Discord is committed to inclusion and providing reasonable accommodations during the interview process. We want you to feel set up
for success, so if you are in need of reasonable accommodations, please let your recruiter know.
Please see our Applicant and Candidate Privacy Policy for details regarding Discord’s collection and usage of personal information
relating to the application and recruitment process by clicking HERE.
[https://discord.com/terms/applicant-candidate-privacy-policy]
Vestiaire Collective is the leading global platform for desirable pre-loved fashion and a pioneer in transforming how people consume fashion. Our mission is simple: make circular fashion the norm, not the exception. Through technology, expertise, and a highly engaged global community, we enable millions of people to buy and sell fashion in a more sustainable way. Founded in Paris in 2009, Vestiaire Collective is now a globally scaled marketplace with offices in Paris, London, Berlin, New York, Singapore, and Ho Chi Minh City, and logistics hubs across Europe, Asia, and the US. Today, we are a team of around 600 people from over 50 nationalities, united by a shared ambition: to drive meaningful change in the fashion industry. Our values, Activism, Transparency, Dedication, Greatness, and Collective, shape how we build, collaborate, and grow every day. Please upload your CVs in English About the role : As a Senior Security Analyst at Vestiaire Collective, you will be part of our Security team. Your objective will be to provide a safe, secure, and trustworthy experience for our users, while safeguarding their privacy and personal data, as well as protecting our company assets and internal employees. Additionally, you will ensure compliance with regulatory requirements. This role is focused on security operations, risk, and assurance: you will be the person who keeps continuous watch over our security posture — monitoring and investigating alerts, driving vulnerabilities through to remediation, supporting incident response, and producing the evidence and metrics that demonstrate our security and compliance to auditors, regulators, and leadership. Reporting to the Head of Security, you will work alongside a talented team of security engineers and collaborate closely with engineering teams and other stakeholders such as legal, finance, and corporate IT. You will work daily with our security stack: Datadog (SIEM), SentinelOne (EDR), Upwind (CSPM), Cloudflare (WAF and Cloudflare One), and Grafana/Prometheus, on top of our AWS and GCP cloud environments. What you will do : Operate and continuously improve our security monitoring: triage and investigate alerts across our detection stack (Datadog SIEM, SentinelOne EDR, Cloudflare), tune detections to reduce noise, and escalate confirmed threats. Review and prioritize cloud security posture findings (Upwind CSPM) across our AWS and GCP environments, and drive misconfigurations through to resolution with the relevant teams. Own the vulnerability management lifecycle: consolidate findings from penetration tests, application security reviews, and our bug bounty program; validate and prioritize them; and drive remediation with engineering teams against defined SLAs. Triage incoming bug bounty submissions: reproduce and assess reported issues, determine severity, and coordinate fixes with the relevant code owners. Support incident response from detection to closure: first-line investigation, coordination during incidents, documentation, and post-incident follow-up actions. Support audit and assurance activities: prepare and maintain evidence for external audits, run periodic access reviews (joiners/movers/leavers, privileged access), and keep compliance documentation up to date. Contribute to security metrics and reporting: maintain and enrich the KPIs and dashboards (Grafana) we use to report our security posture to leadership. Assess third-party vendors and tools from a security and data-protection standpoint. Handle day-to-day security requests from across the company (reported phishing, the security inbox, employee questions) and deliver security awareness initiatives to promote a security-conscious culture. Who you are : Proven experience (3+ years) in a security analyst, SOC, or security operations role, preferably in a fast-paced startup/scaleup environment. Strong analytical and problem-solving abilities, rigorous documentation habits, and the ability to communicate clearly with both technical and non-technical stakeholders. Hands-on experience with SIEM and log analysis platforms (e.g., Datadog, Splunk, Elastic) for alert triage, threat detection, and investigation; familiarity with EDR tooling (e.g., SentinelOne, CrowdStrike) is a strong plus. Working familiarity with cloud environments (AWS and/or GCP) and cloud security fundamentals - enough to understand, prioritize, and follow up on CSPM and WAF findings. Solid understanding of vulnerability management and common application threats (e.g., OWASP Top 10) - enough to validate findings, assess real-world impact, and discuss remediation credibly with engineers. Understanding of compliance frameworks and regulations (e.g., ISO 27001, PCI DSS, SOC 2, GDPR, DSA), with the ability to translate requirements into practical controls, procedures, and audit evidence. Scripting or query skills (e.g., Python, SQL), for automating routine analysis and digging into data during investigations. Ability to adapt to a rapidly changing environment and manage multiple priorities. NICE TO HAVE: Bachelor's or Master's degree in Computer Science, Information Security, or a related field. Relevant certifications (e.g., CompTIA Security+/CySA+, GIAC GCIH/GCIA, CISA, ISO 27001 Lead Auditor/Implementer) are a plus. Our Tech Stacks includes Datadog SIEM Upwind CSPM Cloudflare (WAF, One) SentinelOne AWS, GCP Grafana, Prometheus Snowflake Tableau
YOUR MISSION As a Security Analyst, you oversee incoming security vulnerability reports from our researchers' community, while continuously sharpening your cybersecurity skills. All of this happens through dedicated interaction with the researcher's community and with the goal of offering the best possible service to both companies and researchers. WHAT YOU’LL BE DOING * Challenge and support both researchers and security teams using your entire security skillset. * Research, POC and evaluate reports that come in through our platform (make sure they're unique, concrete & actionable for our clients). * Handling escalations of tickets and researcher mediation. * Mentoring and coaching more junior team members. * Proactively flag tickets that present an escalation risk. * Track changes in the team’s workload and prioritize accordingly. * Assess the severity of reported issues in relation to how they can disrupt business, including the financial and managerial implications. * Familiarity with and ability to calculate CVSS ratings. * Review and provide feedback on reports in a constructive and supportive manner. * Motivate and engage security researchers to continuously outperform themselves. * Build a positive relationship with our community, and customers in close collaboration with success management. * Provide remediation advice and help customers make the most value out of received reports. * Proactively identify and solve issues, as well as accept and quickly respond to delegated work. * Communicate, document, and share your findings. * Stay updated on the latest malware and security threats. * Perform penetration tests and security validation on computer systems, networks and applications. * Create new testing methods to identify vulnerabilities. WHAT YOU’LL BRING * Outstanding interpersonal abilities, and strong written and verbal communication skills. * Fluent in English, both written and spoken. Dutch language skills is a big plus. * At least 2 years of relevant experience within pen testing, security testing, or vulnerability assessments. * Stress resistant & you can keep a clear focus on the resolution in an incident-context. * A strong understanding of the (Ethical) Hacker culture and the Bug Bounty community. * Attention to detail, analytical and problem-solving capabilities. * Able to independently find solutions to both technical and non-technical problems with no apparent answer (aggressive googling, stack overflow, etc). * Flexible working hours, willing to take part in a 24x7 support organization. * Positive service-oriented personality. * Proven technology skills. * Proficient with Mac, Windows, Linux. * OWASP top 10 knowledge. * Web application security knowledge. * Mobile application security knowledge. Nice to haves * Your very own bug bounty profile. * CEH, CPT, CEPT, CPEN, OSWE, OSWA, EWPT or EWPTX certificates are a plus. WHAT IS IN IT FOR YOU? ✅ Competitive salary ⏰ 40-hour work week ⛱️ 20 days of annual leave + 12 ADV days ✈️ 2-months work abroad policy ☕ Flex Income Plan (Cafetariaplan) ⛽ Company car and fuel card or Mobility budget ⭐ Top-notch hospitalisation and group insurance ♻️ Meal & Eco vouchers ⭕ Hybrid working model ⌨️ Initial home office budget ✍ Great training and yearly learning budget ⛹ Social activities and team outings ✨ Referral bonus ⚡ Great hardware and access to the best tools to be successful in your role ☎️ Mobile subscription contribution WHY JOIN US? Here are some great benefits of joining our team: * Cybersecurity is a great place to be! The security industry is fast-paced and continues to grow even during times of economic uncertainty. * We provide a clear career path and learning budget to help set you up for success. * Join a company that’s making a real impact. In addition to our sustainability goals, we empower ethical hackers from all backgrounds to earn a living. * Be yourself! Our international team celebrates individuality and places a strong focus on diversity and inclusion. * We are the proud winners of the Deloitte Rising Star award in 2020, the Deloitte Fast 50 award in 2021 and Security Innovation of the Year 2025 at the UK IT Industry awards. * We’re backed by top investors who are enabling us to grow internationally.
About Proton Join Proton and build a better internet where privacy is the default Proton was founded in 2014 by scientists from CERN on a simple truth: privacy is a fundamental human right. Since then, we’ve built the world’s largest encrypted email service (Proton Mail) and expanded into Proton VPN, Proton Drive, Proton Pass, and Proton Calendar—tools used by millions globally to protect their freedom, fight censorship, and keep their data safe. In some situations, Proton has literally helped save lives! We are profitable, independent (no VC control), and selectively hire from the top ~1% of applicants. Our 700+ team members across 50+ countries come from leading organizations and elite academic backgrounds. We move fast, keep hierarchy light, and prioritize impact over optics. If you want to do meaningful work with exceptionally high-caliber people, this is it. Join us and do work you can truly be proud of. Check our open-source projects here! Role Overview The Security Analyst will be at the frontline of protecting Proton’s global infrastructure. This role combines analytical threat investigation with practical security engineering, taking a role in running, tuning, and evolving our detection capabilities. You will bridge the gap between day-to-day security monitoring and proactive threat defense. Sitting within our security team, you will not only respond to alerts and manage incidents but actively design the rules, playbooks, and systems that catch attackers before they succeed. We value deep logical reasoning, data-driven intuition, and strong cross-functional communication. What you will do: Threat Detection & SIEM Engineering * Maintain, optimize, and enhance our core security monitoring toolkit (SIEM, sensors, etc.). * Design, build, and continuously refine meaningful alerts, transforming raw infrastructure events into high-fidelity detections. * Proactively identify malicious activities or blind spots within our network and infrastructure that our current toolsets might not cover. Incident Response & Monitoring * Monitor, triage, and deeply investigate security alerts covering all of Proton’s corporate infrastructure. * Own the containment and mitigation of potential security incidents, orchestrating quick and effective response actions. * Develop, document, and test rigorous incident response plans and actionable playbooks to streamline future workflows. Risk Mitigation & System Security * Analyze complex logs, endpoints, and network traffic to isolate anomalies, extract patterns, and identify emerging risks. * Collaborate with engineering teams to deploy and maintain secure architectures, applying server and system security best practices (e.g., OS hardening, strict access controls). * Contribute to continuous posture improvement by feeding operational findings back into security tooling and roadmaps. Governance * Support, advise, and guide the wider company on all security-related matters and emerging risks. * Participate in business process documentation, operational metric reporting, and the strategic automation of security tasks. * Promote a culture of strong IT security awareness and responsible user behavior across our distributed teams. Job requirements * Good logical reasoning, structure, and problem-solving skills. The ability to correlate diverse data sources, extract hidden patterns from massive volumes of data, and think like an attacker. * Solid understanding of system and network security best practices, including network ACLs, authentication mechanisms, and endpoint defense configurations. * Strong working knowledge of Linux-based operating systems, their architectural security components, system calls, and mechanisms like SELinux. * Familiarity with modern malware techniques, attacker tactics (TTPs), and how to translate this threat intelligence directly into actionable SIEM rulesets. * Sound understanding of networking protocols, web technologies, and detection mechanics (eg. EDR, IDS/IPS). * Intermediate-to-advanced proficiency in Python (or similar languages) for scripting, parsing, and automation tasks. * Excellent written and spoken English, paired with strong communication and organizational skills to collaborate smoothly across different teams. * A deep belief in digital privacy. Preferred qualifications * Proven experience (ideally 3-4 years) in a cybersecurity or operations context. * Hands-on experience working with Elastic stack, Vector, or other tools used in large-scale log analysis. * Experience utilizing data analysis tools (such as Jupyter, Pandas) to hunt for anomalies. * Practical knowledge of securing and analyzing containerized workloads (Docker, Kubernetes) and Cloud infrastructure environments. * Experience in leveraging and integrating Threat Intelligence into security workflows. * An industry-recognized security certification is considered a strong asset. Success in This Role * The SIEM environment is highly tuned, resulting in a demonstrable reduction in false positives and a significant increase in high-value, actionable alerts. * Security incidents are quickly contained, thoroughly investigated, and translated into resilient long-term containment strategies and playbooks. * Threat detection coverage expands smoothly to secure new infrastructure, products, and cloud microservices. What We Offer * Work that Matters: millions of people trust Proton with their privacy. We answer only to our users — not advertisers, not investors with conflicting agendas, not governments. The work you do here is real, and the impact is measurable. (read more about our impact here) * Stock Options: at Proton, we all have the opportunity to be owners of the company. From day one, you have a real stake in what we're building. When Proton wins, you win. * Technology: you'll get the right hardware and the right software you need to do your best work. * Learning & Development: we invest in your growth because sharp people make us better. Proton is one of the fastest ways to accelerate your career because you'll be thrown into real challenges, with real ownership, from day one. * Employee Benefits: your wellbeing isn't an afterthought. We offer strong health coverage, solid retirement options, generous leave, and wellness support so you can bring your best self to work every day * In-Person Collaboration: Amazing things happen when passionate, smart, and purposeful people get together in the same room. With offices across Geneva, Zürich, Barcelona, London and more, you'll spend most of your time collaborating face-to-face with people who genuinely care about what they're building * Food: Lunch and snacks are on us every day in our offices so you can focus on the work and not on what's for lunch. * Transport: getting to the office shouldn't cost you. We cover public transport, bike allowances, or parking, whichever works for you. * Flexible Working: you own your schedule. Set hours that work for you and your team — because outcomes matter more than when the clock says you started. Our Commitment to Diversity and Inclusion At Proton, we believe diversity drives innovation and strengthens our mission to provide privacy as a default for all. We are committed to fostering an inclusive environment where all individuals, regardless of race, ethnicity, gender, age, sexual orientation, physical ability, or socio-economic background, feel valued and empowered. We strive to create equal opportunities, promote open dialogue, and support continuous learning to ensure every voice is heard and respected. If you need any extra support or reasonable adjustments during the hiring process, please let your talent partner know. Candidate Privacy Notice When you apply for a position, refer a candidate, or are considered for a role at Proton Technologies AG (Proton, we, us, or our), your information is stored in Greenhouse, in accordance with their Service Privacy Policy. This information is used to evaluate your suitability for the posted position. We also retain this information for consideration for future roles that you may apply for or that we believe may align with your background and skills. If we no longer have a legitimate business need to process your information, we will either delete or anonymize it. Should you have any inquiries about how we use or manage your information, or if you wish to access, correct, or delete your data, please contact our privacy team at careers@proton.ch. Proton does not accept unsolicited resumes from any sources other than directly from candidates. We will not pay a fee for any placement resulting from an unsolicited offer, even if the candidate is subsequently hired by Proton. To learn more about our privacy policy, please visit our privacy policy page. Compensation range Paris: 38.000 - 62.000 gross annually* Other locations: Compensation will be discussed during the interview process *Final compensation will be determined based on the candidate's qualifications, skills, and previous experience #LI-Onsite