At Asana, security is foundational to our mission of helping teams work together effortlessly. Our Security organization protects Asana’s employees, users, and customers by proactively addressing threats, enabling secure product development, and embedding security into the fabric of how we operate. We partner closely with Engineering, Product, IT, Legal, and Compliance to build and maintain trust at scale
We are seeking an Engineering Manager, Security to lead and grow our Security Engineering organization as Asana continues to grow globally. This role is pivotal in translating high-level security strategy into technical reality, ensuring our infrastructure is resilient by design and our internal security tooling is world-class
This is a leadership role with accountability for people management, technical mentorship, and the delivery of high-impact security initiatives across a complex, high-growth SaaS environment
This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements
What you’ll achieve Lead and mentor a multi-disciplinary engineering team, fostering a culture of technical excellence, psychological safety, and high accountability
Own the security engineering roadmap, ensuring high-quality delivery and measurable risk reduction through effective prioritization
Drive recruiting efforts to attract top-tier talent and establish clear, ambitious career paths for your team
Champion a high-performance environment where security rigor acts as a catalyst for innovation rather than a bottleneck to velocity
Collaborate with Product and Engineering teams to embed security requirements directly into system designs and development workflows
Oversee complex design reviews, providing pragmatic guidance to ensure Asana’s infrastructure and features are inherently secure
Champion a high-performance environment where security rigor acts as a catalyst for innovation rather than a bottleneck to velocity
About you 8+ years of experience in security or software engineering, including 3+ years of experience directly managing high-performing engineering teams
A strong background in software engineering with the ability to participate in deep-dive design reviews and provide technical direction on architecture and code
Deep understanding of modern security domains, including application security (OWASP), cloud-native architecture, and identity frameworks (OAuth, OIDC, SAML)
Hands-on experience with security controls