採用
Benefits & Perks
•401(k) matching
•Competitive salary and equity package
•Team events and activities
•Comprehensive health, dental, and vision insurance
•Equity
•Healthcare
Required Skills
PostgreSQL
JavaScript
Python
Security Engineer, Red Team
WarsawApply now
At Asana, security is foundational to our mission of helping humanity thrive by enabling the world’s teams to work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.
We’re looking for a security engineer to join our Security Red Team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by performing security reviews and penetration testing assessments of our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset.
This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday.
We offer a Contract of Employment (UoP) for our employees in Poland
What you’ll achieve:- Conduct security architecture reviews, threat modeling, and penetration testing for new features and services across our product and internal applications.
-
Test software for application security vulnerabilities through various assessment methodologies, including penetration testing.
-
Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal penetration tests, and automated security tooling.
-
Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
-
Investigate product security incidents as an incident subject matter expert, using logs and monitoring tools.
-
Develop and deliver training to educate engineers on secure coding best practices and emerging threats.
-
Stay informed of industry trends, emerging threats, and best practices to ensure that Asana’s security posture remains robust.
-
Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management.
-
Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software.
About you:- 5+ years of experience in application security, product security, penetration assessments, or software engineering with a security focus, with significant experience in security reviews and penetration testing.
-
Strong software engineering background with experience in languages like Python, Javascript/Typescript or Scala
-
Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection
-
Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management.
-
Proven experience performing security design reviews and threat modeling for complex applications, as well as conducting comprehensive penetration tests.
-
Excelling communication skills for collaborating effectively with both technical and non-technical partners.
-
A pragmatic and collaborative mindset, with a passion for building defenses against real-world attacks and enabling other engineers to do their best, most secure work.
What we offer:- Generous, transparent and fair compensation system (base salary and generous Restricted Stock Unit for Asana Inc.)
-
Contract of Employment (with 50% tax deductible costs for author’s rights usage for Engineers)
-
Health insurance with dental and travel coverage (Lux Med)
-
Lunch catering on the days that you work from the office
-
Career growth budget
-
Home office setup budget
-
Gym/Fitness reimbursement
-
Fertility healthcare and family-forming support with Carrot
-
Mental health support in Modern Health
-
Group life insurance
-
Mac Books with all necessary accessories
For this role, the estimated base salary range is between 25,604 - 35,854 PLN gross monthly on the contract of employment (UoP). The actual base salary will vary based on various factors and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base compensation range for this role may be modified.
Our total compensation consists of base salary and equity (RSUs).
#appsec #securityengineer
About us
Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.
[Join Asana’s Talent Network](https: //www.gem.com/form?formID=fbcdec8c-3442-43b9-9b45-d2b5f4ea25db) to stay up to date on job opportunities and life at Asana.
By clicking "Submit Application," you acknowledge and agree to [Asana's Global Job Applicant /m/7b98ac66e485a481/original/Asana-Global-Candidate-Privacy-Notice-December-18-2023-English-docx.pdf).
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Security Engineer - Third party Assurance
Cloudflare · Hybrid; In-Office

SENIOR SECURITY ENGINEER - PRODUCT SECURITY
Snowflake · PL-Warsaw

Product Security Engineer
Databricks · United States

Security Operations Engineer, Detection and Response Team
Notion · Hyderabad, India

Security Controller
Palantir · London, United Kingdom
About Asana

Asana
PublicWork on big ideas, without the busywork.
1,001-5,000
Employees
San Francisco whose flagship Asana service
Headquarters
$1.5B
Valuation
Reviews
3.4
15 reviews
Work Life Balance
4.0
Compensation
3.5
Culture
3.8
Career
3.2
Management
2.5
45%
Recommend to a Friend
Pros
Strong collaborative work culture and environment
Competitive compensation packages with high TC offers
Good product and mission-driven work
Cons
Leadership instability with CEO changes and executive departures
Recent layoffs and organizational uncertainty
Poor interview experience and recruiting process
Salary Ranges
635 data points
Junior/L3
L2
L3
L4
L5
L6
Mid/L4
Junior/L3 · Business Intelligence Analyst
1 reports
$198,950
total / year
Base
$173,000
Stock
-
Bonus
-
$198,950
$198,950
Interview Experience
7 interviews
Difficulty
2.9
/ 5
Duration
14-28 weeks
Offer Rate
14%
Experience
Positive 14%
Neutral 72%
Negative 14%
Interview Process
1
Application Review
2
Recruiter Screen
3
Technical Phone Screen
4
Onsite/Virtual Interviews
5
Team Matching
6
Offer
Common Questions
Coding/Algorithm
Technical Knowledge
Behavioral/STAR
System Design
Culture Fit
News & Buzz
Has The Slide In Asana (ASAN) Created A Potential Valuation Opportunity? - Yahoo Finance Singapore
Source: Yahoo Finance Singapore
News
·
5w ago
Asana (NYSE:ASAN) Hits New 1-Year Low - Here's Why - MarketBeat
Source: MarketBeat
News
·
5w ago
Asana stock hits 52-week low at $10.59 - Investing.com
Source: Investing.com
News
·
5w ago
Am I overpaying for Asana?
I’ve been using Asana for about a year now for a small remote team, mostly marketing and ops. We’re on the Premium plan and it’s around $10.99 per user monthly. I like the UI and timeline view, but lately I’m wondering if I’m just paying for stuff we don’t fully use. We mainly do task lists, some
·
5w ago
·
6
·
26