Technology Risk Audit Manager
Discord
- Location
- San Francisco Bay Area
- Work model
- On-Site
- Level
- Mid
- Salary
- $180k – $202.5k/yr
- H-1B history
- 6 approvals (FY2023)
- Posted
- 2h ago
Skills
About this role
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games.
Discord's Internal Audit team exists to demonstrate effective risk management, process optimization, and adherence to relevant regulations — through a mix of independent assurance and advisory work that helps teams strengthen our overall control environment. This Technology Risk Audit Manager role owns the technical side of that mission — IT SOX/ITGC, system controls, and domains centered around consumer trust — that protect hundreds of millions of our users worldwide. You'll have the opportunity to help build our internal audit function from the ground up: shaping the frameworks and processes with an AI-native approach from day one, rather than bolting AI on after the fact. Your first few months will focus on learning Discord's financial-reporting systems landscape, understanding the company's GRC program structure, and evaluating AI-powered testing solutions — setting the foundation for a function that's built to scale as Discord grows toward enterprise readiness. This person will report to the Vice President of Internal Audit.
What You'll Be Doing
• Lead IT SOX/ITGC strategy and continuous improvement across financial-reporting-relevant systems
• Extend risk and controls assessment and assurance into consumer trust domains such as privacy, security, and trust & safety
• Partner with the Engineering organization to ensure proper access controls, segregation of duties, change management, and CI/CD integrity are in place
• Guide control design through system implementations, migrations, and platform changes
• Manage teams and projects related to IT controls and technical audits, including external contractors and/or internal teammates
• Apply AI/automation tools to improve audit testing efficiency, anomaly detection, and control monitoring
• Track remediation, coordinate with external auditors, and report to senior leadership
What you should have
• Bachelor's degree in Information Systems, Computer Science, Accounting, or related field (or equivalent practical experience)
• 8+ years in IT audit, risk management, or controls, spanning both financial (SOX/ITGC) and consumer trust domains (security, privacy, or trust & safety a plus)
• Deep ITGC fundamentals — access management, change management, computer operations, and SDLC controls
• SOX/ICFR knowledge and independent risk assessment methodology — able to scope an audit, identify key risks, and design test procedures rather than execute a checklist
• Framework fluency across COSO, COBIT, and NIST CSF, applied appropriately by context
• Proven external audit/co-source coordination experience, with a track record of driving remediation action plans through to closure
• Hands-on experience applying AI or automation tools to audit processes, and strong communication skills translating technical risk for non-technical stakeholders
Bonus points
• Consumer facing platform technology risk experience
• Subscription and/or Ad Tech experience
• Experience auditing homegrown systems and/or tools
• AI governance experience
• Third-party/vendor risk depth
• Data privacy regulatory fluency
• DevSecOps / CI-CD pipeline controls
• CISA, CISSP, or CPA credential
Candidates must reside in or be willing to relocate to the San Francisco Bay Area (Alameda, Contra Costa, Marin, Napa, San