SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 144,000 - 162,000 / annual
Discord's Legal team is expanding its Security Governance, Risk, and Compliance (GRC) function and seeks a Security Analyst to own and scale the program's day-to-day operations. You will manage the questionnaires, risk tracking, analyses, tooling, and documentation that drive compliance forward. The role balances hands-on execution today with building systems that automate controls over time, reducing manual compliance work.
Key responsibilities include: running the customer security questionnaire program end-to-end, from intake through response, and building a reusable answer library to accelerate repeat inquiries; operating risk and control workflows by triaging incoming risks, tracking gap closure, maintaining the risk register, and serving as the first point of contact for partner teams; conducting GRC analyses to assess how standards, procedures, and controls align with policies and frameworks, identify gaps, and evaluate control maturity; building and maintaining the GRC toolchain and automation, including platform administration, ticketing, knowledge bases, and integrations that collect evidence and check controls by default; and creating clear documentation—internal guidance, policy updates, company-wide communications, and security training—that makes the program accessible to non-specialists.
You should bring 4+ years in security compliance, GRC, security operations, IT risk, or audit. You need working familiarity with common frameworks (ISO 27001/27002, SOC 2, PCI DSS, GDPR/CPRA) and hands-on experience operating compliance processes: evidence collection, control tracking, risk register maintenance, or security questionnaire response. An automation-first mindset is essential—you reach for tooling, integrations, and repeatable workflows to replace manual work rather than accepting box-checking. You are comfortable working across multiple tools (GRC platforms, ticketing systems, documentation wikis) and maintaining clean, organized data. Strong writing skills are critical; you can translate dense requirements into actionable guidance. You influence across teams without direct authority in a fast-moving environment with competing priorities.
Bonus experience includes hands-on GRC platform administration, exposure to ISO 27701, ISO 42001, or emerging AI compliance frameworks, and background in consumer technology, gaming, or online community platforms.