Asana · Warsaw

Security Engineer, Red Team

🏢 Asana📍 Warsaw🕐 Posted 78 days ago
⏱ Full-timeInfrastructure Engineering✅ Direct from employer ATS
Apply on Asana
ℹ️ Please note: This listing is sourced from a third-party job board. Jobnique is a job search platform and is not the employer for this role. The hiring company is Asana.

About this role

At Asana, security is foundational to our mission of helping humanity thrive by enabling the world’s teams to work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations

We’re looking for a security engineer to join our Security Red Team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by performing security reviews and penetration testing assessments of our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset

This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday

We offer a Contract of Employment (UoP) for our employees in Poland What you’ll achieve: Conduct security architecture reviews, threat modeling, and penetration testing for new features and services across our product and internal applications

Test software for application security vulnerabilities through various assessment methodologies, including penetration testing

Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal penetration tests, and automated security tooling

Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs

Investigate product security incidents as an incident subject matter expert, using logs and monitoring tools

Develop and deliver training to educate engineers on secure coding best practices and emerging threats

Stay informed of industry trends, emerging threats, and best practices to ensure that Asana’s security posture remains robust

Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management

Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software

About you: 5+ years of experience in application security, product security, penetration assessments, or software engineering with a security focus, with significant experience in security reviews and penetration testing

Strong software engineering background with experience in languages like Python, Javascript/Typescript or Scala Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS,

Apply on Asana