Senior Software Engineer, Security Development

Asana Asana · Enterprise · San Francisco, CA · Infrastructure Engineering

Senior Software Engineer for Asana's new Security Development team, focused on building secure-by-default frameworks, libraries, and platforms to protect infrastructure and product. Responsibilities include engineering preventative controls, improving core security services, and developing a platform for vulnerability remediation. Requires 4+ years of software development experience, with a background in building platforms or infrastructure, and a strong interest in security engineering.

What you'd actually do

  1. Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities.
  2. Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems.
  3. Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently.
  4. Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure.
  5. Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents)

Skills

Required

  • 4+ years of experience in full-time professional software development, working with large codebases.
  • Proven software engineering experience, with a background in building platforms, libraries, or core infrastructure.
  • Strong interest or direct experience in security engineering, with a focus on building preventative controls.
  • Expertise in programming and computer science fundamentals.
  • Experience with cloud infrastructure and services, particularly AWS.
  • Excellent communication skills for collaborating effectively with engineering teams across the organization.
  • A proactive mindset geared towards identifying and eliminating systemic risks, not just individual bugs.

Nice to have

  • curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making

What the JD emphasized

  • security engineering
  • building platforms
  • building frameworks
  • preventative controls
  • systemic risks