Security Assurance Engineer

Warsaw

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

Asana

Work anytime, anywhere with Asana. Keep remote and distributed teams, and your entire organization, focused on their goals, projects, and tasks with Asana.

View all jobs at Asana

Apply now Apply later

At Asana, security is foundational to our mission of helping humanity thrive by enabling the world’s teams to work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.

We’re looking for an Application Security Engineer to join our R&D Security team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with product and infrastructure teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by building secure-by-default frameworks, eliminating entire classes of vulnerabilities, and championing a security-first mindset.

This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. 

We offer a Contract of Employment (UoP) for our employees in Poland

What you’ll achieve

  • Partner with product engineering teams throughout the entire development lifecycle, from design to deployment, to ensure security is built in.
  • Conduct security architecture reviews, threat modeling, and code reviews for new features and services.
  • Develop, implement, and maintain secure-by-default frameworks and libraries that empower engineering teams to build secure systems easily.
  • Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal testing, and automated security tooling.
  • Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
  • Investigate product security incidents as an incident subject matter expert, using logs and monitoring tools.
  • Develop and deliver training to educate engineers on secure coding best practices and emerging threats.
  • Stay informed of industry trends, emerging threats, and best practices to ensure that Asana’s security posture remains robust.
  • Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management.
  • Join a collaborative R&D Security team composed of specialists in product, application, infrastructure and detection and response, all working together to help engineering teams design and ship secure software.

About you

  • 3+ years of experience in application security, product security, or software engineering with a security focus.
  • Strong software engineering background with experience in languages like Python, Javascript/Typescript or Scala
  • Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection
  • Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management.
  • Experience performing security design reviews and threat modeling for complex applications.
  • Excelling communication skills for collaborating effectively with both technical and non-technical partners.
  • A pragmatic and collaborative mindset, with a passion for building defenses against real-world attacks and enabling other engineers to do their best, most secure work.
  • Demonstrated curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.

What we offer

  • Generous, transparent and fair compensation system (base salary and generous Restricted Stock Unit for Asana Inc.) 
  • Contract of Employment (with 50% tax deductible costs for author’s rights usage for Engineers) 
  • Health insurance with dental and travel coverage (Lux Med) 
  • Lunch catering on the days that you work from the office
  • Career growth budget 
  • Home office setup budget 
  • Gym/Fitness reimbursement
  • Fertility healthcare and family-forming support with Carrot
  • Mental health support in Modern Health
  • Group life insurance
  • MacBooks with all necessary accessories

For this role, the estimated base salary range is between 23,667  - 34,875 PLN gross monthly on the contract of employment (UoP). The actual base salary will vary based on various factors and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base compensation range for this role may be modified.

Our total compensation consists of base salary and equity (RSUs). 

About us

Asana helps teams orchestrate their work, from small projects to strategic initiatives. Millions of teams around the world rely on Asana to achieve their most important goals faster. Asana has been named a Top 10 Best Workplace for 5 years in a row, is Fortune's #1 Best Workplace in the Bay Area, and one of Glassdoor’s and Inc.’s Best Places to Work. After spending more than a year physically distanced, Team Asana is safely and mindfully returning to in-person collaboration, incorporating flexibility that adds hybrid elements to our office-centric culture. With 11+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world. We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law. We also comply with the San Francisco Fair Chance Ordinance and similar laws in other locations.

 

#LI-Hybrid

Apply now Apply later
Job stats:  1  0  0

Tags: Application security Asana CSRF DAST JavaScript Monitoring OWASP Product security Python R&D Risk management SAST Scala SQL SQL injection SSRF TypeScript Vulnerabilities Vulnerability management XSS

Perks/benefits: Career development Equity / stock options Fertility benefits Fitness / gym Health care Insurance Travel

Region: Europe
Country: Poland

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.