San Francisco, CA

Salary
$196,000–$220,500from the description
Posted
Jul 31, 2026
Location
San Francisco, CA
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

This is a full-stack security engineering role on Discord's Application Security team, focused on protecting user accounts at scale. The engineer will design and build authentication and session security systems, partner with product teams to ship user-facing security features, and own the correctness and reliability of security-critical services. It suits an experienced engineer with deep hands-on knowledge of authentication standards and a track record of shipping production security controls.

Senior level · 5+ years · San Francisco-Oakland-Berkeley, CA · Full-time

Must have (3)
Python, Go, Java or Rust · 3+ yrsWebAuthn, Fido2 or PasskeysMFA
Nice to have (2)
Google Cloud, AWS or AzureC or C++

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 230 people in the San Francisco-Oakland-Berkeley, CA area plausibly meet what this posting asks for (information security analysts). range 120–300

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python51%MFA40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $165,879 (middle half $117,529–$206,125). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 1, 2026. It is a model, not a headcount.

Why we read it this way (9)

The SOC classification is a genuine toss-up: the role is framed as Application Security but the day-to-day work is predominantly full-stack software engineering (building authentication services, shipping user-facing features, writing security controls and frameworks). 15-1212 is chosen because the team is explicitly 'Application Security' and the scope centers on security outcomes, but 15-1252 is a strong runner-up given the heavy build-and-ship emphasis.

The 5+ years requirement is stated as 'securing production applications'; the 3+ years is tied specifically to a general-purpose programming language. Both are captured accordingly.

Python, Go, Java, and Rust are listed as interchangeable examples of a general-purpose language requirement — one skill with alternatives is used to represent this.

WebAuthn, passkeys, and FIDO2 are listed together as examples of the same authentication requirement and are treated as alternatives under WebAuthn.

Google Cloud is named as the company's platform but the posting explicitly accepts experience with other cloud platforms — marked preferred accordingly.

C and C++ appear only under 'Bonus points' and are marked preferred.

The posting states the role is 'US-based only' but does not specify a city; Discord is headquartered in San Francisco, CA, which is used as the metro.

The compensation range reflects base salary only; equity and benefits are additional per the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): session management, mobile app development.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗