Senior Privacy Engineer

Discord Discord · Consumer · San Francisco, CA · Core Tech Engineering

Senior Privacy Engineer role at Discord focused on building and operating systems for user data rights (collection, access, deletion), optimizing privacy programs, conducting risk assessments, and leading incident response. Requires experience in privacy/security engineering, production systems with legal requirements, programming languages, cloud environments, and privacy concepts/regulations.

What you'd actually do

  1. Build and operate the systems that enable data rights for our users across the data lifecycle, including collection, access, and deletion.
  2. Own end to end software development of new tools and scalable solutions to optimize the work of the Discord Privacy Program and enable teams to use user data effectively and responsibly in a complex cloud environment.
  3. Partner with cross-functional teams, including Engineering, Product, Data, and Legal to conduct risk assessments, code reviews, and ensure compliance with Discord’s Privacy Principles and regulatory requirements.
  4. Advocate for privacy-preserving solutions, act as a privacy subject matter expert across teams, and identify new opportunities to promote our privacy posture.
  5. Lead Privacy incident response efforts, including mitigating situations that may pose a risk to our Privacy Principles and providing assistance in incident response efforts outside of the privacy domain.

Skills

Required

  • 3+ years of work experience in Privacy or Security engineering or building production systems that meet legal requirements
  • 3+ years of experience in at least one general purpose programming language (e.g. Python, Rust, Typescript)
  • 3+ years of experience working in cloud-based environments (we use Google Cloud)
  • Experience with concepts and practices such as threat modeling, data lifecycle management, and data classification
  • Familiarity with privacy concerns that apply in an industry setting, including consent, deletion, and retention, and a basic understanding of regulations such as GDPR or CCPA
  • Experience with conducting reviews of system architecture and product feature specs and driving mitigations of data protection risk, deviations from privacy policies, and privacy dark patterns

Nice to have

  • Experience developing, operating, and debugging distributed systems
  • Experience with modern data platform infrastructure
  • Experience integrating internal systems with privacy and risk management platforms

What the JD emphasized

  • legal requirements
  • regulatory requirements
  • GDPR
  • CCPA