Corporate Security Engineer

Asana Asana · Enterprise · San Francisco, CA · Infrastructure Engineering

This role is for a Corporate Security Engineer at Asana, focusing on protecting the company's corporate environment and users. Responsibilities include leading initiatives in Endpoint Security, SSPM, IAM, Identity Governance, and DLP. The role involves collaborating with IT and engineering, designing automation scripts, and partnering in incident response. A familiarity with security concepts, scripting (Python), and specific tools like Okta is required. The company mentions AI tools as a potential enhancement for productivity.

What you'd actually do

  1. Lead initiatives across key security domains, including Endpoint Security, SaaS Security Posture Management (SSPM), Identity & Access Management (IAM), Identity Governance, and data-loss prevention
  2. Collaborate closely with IT, engineering, and business stakeholders to integrate security tools, policies, and processes into corporate systems and workflows, enabling secure-by-design implementations
  3. Design and build automation scripts and tools to streamline security workflows, collect actionable metrics, and enforce security policies at scale.
  4. Develop and implement strategies and tooling for Data Loss Prevention (DLP) and the mitigation of insider risks within Asana.
  5. Partner with our Incident Manager and provide subject matter expertise for incident response.

Skills

Required

  • 4 years experience in a Corporate Security or IT Security
  • Familiarity with Identify and Access Management, Authentication & Authorization, Endpoint management, and Network Security Controls.
  • Strong understanding of security concepts including zero trust architecture, threat modeling, security frameworks (SOC 2, ISO 27001) and CIS Controls.
  • Experience in implementing Data Loss Prevention tooling and insider risk programs.
  • Some experience writing and maintaining scripts in at least one language such as Python.
  • Experience with Okta, Google Workspace, osQuery and EDR solutions.

Nice to have

  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making

What the JD emphasized

  • Data Loss Prevention (DLP)
  • insider risks