Senior Engineering Manager, Security

Asana Asana · Enterprise · San Francisco, CA · Infrastructure Engineering

Asana is seeking a Senior Engineering Manager, Security to lead and grow their Security Engineering organization. This role involves translating security strategy into technical reality, ensuring infrastructure resilience, and developing world-class internal security tooling. The manager will be responsible for people management, technical mentorship, and delivering high-impact security initiatives in a complex, high-growth SaaS environment. Key responsibilities include owning the security engineering roadmap, driving recruiting, fostering a high-performance culture, collaborating with Product and Engineering teams to embed security, and overseeing design reviews. The ideal candidate has 8+ years of experience in security or software engineering, including 3+ years of management experience, a strong software engineering background, deep understanding of modern security domains (application security, cloud-native architecture, identity frameworks), hands-on experience with AWS security controls, and a proven track record of shipping internal security tools. Curiosity about AI tools is mentioned as a plus.

What you'd actually do

  1. Lead and mentor a multi-disciplinary engineering team, fostering a culture of technical excellence, psychological safety, and high accountability.
  2. Own the security engineering roadmap, ensuring high-quality delivery and measurable risk reduction through effective prioritization.
  3. Drive recruiting efforts to attract top-tier talent and establish clear, ambitious career paths for your team.
  4. Champion a high-performance environment where security rigor acts as a catalyst for innovation rather than a bottleneck to velocity.
  5. Collaborate with Product and Engineering teams to embed security requirements directly into system designs and development workflows.
  6. Oversee complex design reviews, providing pragmatic guidance to ensure Asana’s infrastructure and features are inherently secure.

Skills

Required

  • 8+ years of experience in security or software engineering
  • 3+ years of experience directly managing high-performing engineering teams
  • Strong background in software engineering
  • Ability to participate in deep-dive design reviews
  • Provide technical direction on architecture and code
  • Deep understanding of modern security domains
  • Application security (OWASP)
  • Cloud-native architecture
  • Identity frameworks (OAuth, OIDC, SAML)
  • Hands-on experience with security controls and architecture within AWS or similar cloud environments at scale
  • Balancing security requirements with business needs
  • Making risk-informed decisions
  • Communicating the "why" behind security mandates to diverse stakeholders
  • Value automation over manual intervention
  • Proven track record of shipping internal tools or services that improve security posture

Nice to have

  • Curiosity about AI tools and emerging technologies
  • Willingness to learn and leverage them to enhance productivity, collaboration, or decision-making

What the JD emphasized

  • security strategy
  • technical reality
  • infrastructure resilience
  • internal security tooling
  • people management
  • technical mentorship
  • delivery of high-impact security initiatives
  • SaaS environment
  • security engineering roadmap
  • risk reduction
  • recruiting top-tier talent
  • career paths
  • high-performance environment
  • security rigor
  • innovation
  • velocity
  • Product and Engineering teams
  • security requirements
  • system designs
  • development workflows
  • design reviews
  • pragmatic guidance
  • inherently secure
  • application security
  • cloud-native architecture
  • identity frameworks
  • AWS
  • security controls
  • risk-informed decisions
  • automation
  • internal tools or services
  • security posture