Senior Software Engineer, Infrastructure Security

Asana Asana · Enterprise · San Francisco, CA · Infrastructure Engineering

Senior Software Engineer focused on building secure-by-default frameworks, libraries, and platforms to protect Asana's infrastructure and product. This role involves engineering preventative controls, improving core security services, and developing a platform for vulnerability remediation. The engineer will partner with product and infrastructure teams to implement foundational security controls and influence engineering initiatives through design reviews.

What you'd actually do

  1. Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities.
  2. Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems.
  3. Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently.
  4. Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure.
  5. Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents)

Skills

Required

  • 4+ years of experience in full-time professional software development, working with large codebases.
  • Proven software engineering experience, with a background in building platforms, libraries, or core infrastructure.
  • Strong interest or direct experience in security engineering, with a focus on building preventative controls.
  • Expertise in programming and computer science fundamentals.
  • Experience with cloud infrastructure and services, particularly AWS.
  • Excellent communication skills for collaborating effectively with engineering teams across the organization.
  • A proactive mindset geared towards identifying and eliminating systemic risks, not just individual bugs.

Nice to have

  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making

What the JD emphasized

  • security engineering
  • building preventative controls
  • security principles