Engineering Manager, Application Security

Discord Discord · Consumer · San Francisco, CA · Security Engineering

Engineering Manager for Application Security at Discord, focusing on leading a team to build and implement security tools, conduct secure design reviews, threat modeling, and ensure secure development practices across the company. The role involves scaling detection and remediation of vulnerabilities, partnering with product teams, and managing security projects.

What you'd actually do

  1. Lead a team of security engineers who will build and implement application security tools and services, perform secure design reviews and threat modeling, and provide guidance on secure development at Discord.
  2. Secure our code and development process from IDE to production.
  3. Scale detection and remediation of security vulnerabilities..
  4. Work with other Discord teams to limit security exposure to our users, while also shaking out security bugs before they enter production.
  5. Partner with Discord's product engineering and product management teams to champion new security features for our users.

Skills

Required

  • Engineering Management
  • Security Engineering
  • Application Security
  • Secure Design Reviews
  • Threat Modeling
  • Secure Development
  • Vulnerability Discovery
  • Vulnerability Remediation
  • AI Security practices
  • Cloud-based environments (GCP)
  • Roadmap development
  • Complex system security analysis
  • Python
  • Rust
  • Go

Nice to have

  • Modern and frequently used cryptographic primitives
  • Container orchestration technologies (Kubernetes)
  • Linux system administration
  • Common application vulnerabilities

What the JD emphasized

  • 3+ years of experience as an Engineering Manager
  • managed a team of 3+ Security Engineers
  • development-with-AI experience
  • good grasp of AI Security practices
  • experience leading multiple security projects with a cross-functional group
  • experience with tools used to automate vulnerability discovery and remediation
  • comfortable writing the roadmap
  • expert at reasoning about the security of complex systems