Security Engineer, Red Team

Asana Asana · Enterprise · Warsaw, Poland · Infrastructure Engineering

Security Engineer, Red Team role at Asana, focusing on application security, penetration testing, and threat modeling to ensure secure software development and product security. This role involves collaborating with engineering teams, conducting security reviews, and triaging vulnerabilities.

What you'd actually do

  1. Conduct security architecture reviews, threat modeling, and penetration testing for new features and services across our product and internal applications.
  2. Test software for application security vulnerabilities through various assessment methodologies, including penetration testing.
  3. Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal penetration tests, and automated security tooling.
  4. Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
  5. Investigate product security incidents as an incident subject matter expert, using logs and monitoring tools.

Skills

Required

  • Python
  • Javascript/Typescript
  • Scala
  • OWASP Top 10
  • web application vulnerabilities
  • SAST/DAST
  • SCA
  • vulnerability management
  • security design reviews
  • threat modeling
  • penetration tests
  • communication skills

Nice to have

  • secure coding best practices
  • emerging threats

What the JD emphasized

  • security reviews
  • penetration testing
  • threat modeling
  • application security
  • product security