Principal Security Engineer

Asana Asana · Enterprise · San Francisco, CA · Infrastructure Engineering

Principal Security Engineer at Asana, focusing on defining security architecture, setting technical direction, and driving cross-company alignment in a global SaaS environment. The role requires a strong software engineering background and hands-on experience securing cloud environments.

What you'd actually do

  1. Define and deliver the Security Engineering technical strategy and multi-year roadmap aligned with Asana’s product, platform, and business priorities.
  2. Raise the technical bar across security engineering through design and risk reviews, hands-on mentorship, and clear standards.
  3. Partner with senior leaders across Engineering, Product, and Infrastructure to improve Asana’s overall security posture.
  4. Develop security policies, processes, and procedures that scale with a growing, global engineering organization.
  5. Stay ahead of the threat landscape and support teams building new features and technologies to ensure they are secure by design.

Skills

Required

  • Security architecture
  • Technical leadership
  • Software engineering
  • System design
  • Cloud security (AWS)
  • Risk assessment
  • Identity and access controls (OAuth, OIDC, SAML)
  • Modern attack patterns

Nice to have

  • AI tools

What the JD emphasized

  • 10+ years in a security-related engineering role
  • 3+ years in a staff or principal-level role
  • technical lead across multiple teams
  • Deep understanding of application and platform risks
  • Significant, hands-on experience securing cloud environments at scale, especially AWS