Group Tech Lead, Security Threat Operations & Response Management

Asana Asana · Enterprise · Warsaw, Poland · Infrastructure Engineering

This role is for a Group Tech Lead in Security Threat Operations & Response Management at Asana. The primary focus is on defining and leading the technical strategy for a purple team function, integrating offensive and defensive security capabilities. Key responsibilities include adversary emulation, improving security maturity, managing the incident response lifecycle, vulnerability operations, process design, detection engineering, and leveraging AI/ML for enhanced threat detection and analysis. The role requires strong technical leadership, expertise in both red and blue team disciplines, and experience with security platforms and automation.

What you'd actually do

  1. Define and own the technical strategy for a fully integrated purple team function, bridging offensive (red team) and defensive (blue team) capabilities into a cohesive, intelligence-driven program.
  2. Design and implement a structured adversary emulation programme based on real threat intelligence, ensuring red team exercises directly improve blue team detection and response playbooks while establishing continuous feedback loops.
  3. Lead Asana's security maturity journey, defining a roadmap that progressively advances capabilities toward frameworks and standards such as NIST CSF, ISO 27001, SOC 2, and MITRE ATT&CK maturity levels.
  4. Develop, own, and continuously improve the end-to-end incident response lifecycle, including policies, playbooks, runbooks, and post-incident review processes.
  5. Identify, evaluate, and implement AI and machine learning capabilities to enhance the speed, accuracy, and coverage of threat detection, automated alert triage, root cause analysis, and incident summarization.

Skills

Required

  • 8+ years of progressive experience in security operations, threat detection and response, or offensive security, with at least 3 years in a senior technical leadership or principal engineering role.
  • Deep technical expertise across both red and blue team disciplines, with a proven track record of designing and leading a purple team or integrated threat operations programme at scale.
  • Strong command of SIEM platforms (e.g., Panther, Splunk, Elastic Security) for detection engineering, advanced log correlation, and extensive knowledge of EDR platforms (e.g., CrowdStrike, SentinelOne) for proactive threat hunting.
  • Expert-level familiarity with operationalizing adversary emulation frameworks (such as MITRE ATT&CK) and handling forensic analysis during complex incident investigations in large cloud-native environments.
  • Strong engineering and automation background utilizing scripting languages (e.g., Python, PowerShell) paired with exposure to SOAR platforms.
  • Strategic capability to translate business risk into a technical roadmap aligned to NIST CSF, ISO 27001, or SOC 2 standards, combined with strong technical process design skills.
  • Excellent communication and collaborative skills, with a track record of building cross-functional trust and explaining complex threat concepts clearly to engineering, product, legal, and executive teams alike.

Nice to have

  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.

What the JD emphasized

  • AI and machine learning capabilities to enhance the speed, accuracy, and coverage of threat detection, automated alert triage, root cause analysis, and incident summarization.

Other signals

  • AI and machine learning capabilities to enhance the speed, accuracy, and coverage of threat detection, automated alert triage, root cause analysis, and incident summarization.