Application Security Engineer

Asana Asana · Enterprise · Warsaw, Poland · Security Engineering

Asana is seeking an Application Security Engineer to join their Security team in Warsaw. The role involves protecting Asana's employees, users, and customers by building safeguards, ensuring compliance, and collaborating with various teams. The engineer will conduct security design reviews, threat modeling, and vulnerability assessments, and foster a security-first mindset. Responsibilities include reviewing architecture, performing vulnerability assessments, triaging and remediating vulnerabilities, influencing engineering initiatives, investigating security incidents, and developing training. The role requires a strong software engineering background, experience with security tools, and knowledge of web application vulnerabilities. A curiosity about AI tools is mentioned as a plus.

What you'd actually do

  1. Conduct security architecture reviews and threat modeling for new features and services across our product and internal applications, identifying risks early and influencing secure design decisions.
  2. Perform vulnerability assessments of software and systems, using a range of assessment methodologies to surface and prioritize security weaknesses across our product surface.
  3. Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program and automated security tooling, ensuring issues are tracked and resolved within defined SLAs.
  4. Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
  5. Investigate product security incidents as a subject matter expert, using logs and monitoring tools to assess scope, impact, and root cause.

Skills

Required

  • 5+ years of experience in application security, product security, or software engineering with a security focus
  • significant experience in security design reviews, threat modeling, and vulnerability assessments
  • Strong software engineering background
  • experience in languages like Python, JavaScript/TypeScript or Scala
  • Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection
  • Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management
  • Proven experience performing security design reviews and threat modeling for complex, distributed applications
  • ability to identify systemic risk and drive remediation at scale
  • Excellent communication skills for collaborating effectively with both technical and non-technical partners
  • translating security risk into business impact
  • pragmatic and collaborative mindset

Nice to have

  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.

What the JD emphasized

  • security design reviews
  • threat modeling
  • vulnerability assessments
  • secure software
  • security posture