Security Engineer, Red Team
Asana · Warsaw, Poland · Infrastructure Engineering
About this role
Asana is hiring a mid-level Security Engineer based in Warsaw, Poland (hybrid). The posting calls out experience with Python, JavaScript, TypeScript, Scala and roughly 5+ years of relevant work.
- Role
- Security Engineer
- Function
- security
- Level
- mid
- Track
- Individual contributor
- Employment
- Full-time
- Location
- Warsaw, Poland
- Work mode
- Hybrid
- Experience
- 5+ years
- Department
- Infrastructure Engineering
More roles at Asana
Job description
from Asana careersAt Asana, security is foundational to our mission of helping humanity thrive by enabling the world’s teams to work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.
We’re looking for a security engineer to join our Security Red Team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by performing security reviews and penetration testing assessments of our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset.
This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday.
We offer a Contract of Employment (UoP) for our employees in Poland
What you’ll achieve:
- Conduct security architecture reviews, threat modeling, and penetration testing for new features and services across our product and internal applications.
- Test software for application security vulnerabilities through various assessment methodologies, including penetration testing.
- Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal penetration tests, and automated security tooling.