Application Security Engineer
Навыки
- Коммуникация
- JavaScript
- OWASP
- Python
- Управление рисками
- Роадмап
- SAST / DAST
Ещё 4
- Scala
- SQL
- TypeScript
- Управление уязвимостями
О компании и продукте
- Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.
- We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law.
- Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.
Задачи
- Conduct security architecture reviews and threat modeling for new features and services across our product and internal applications, identifying risks early and influencing secure design decisions
- Perform vulnerability assessments of software and systems, using a range of assessment methodologies to surface and prioritize security weaknesses across our product surface
- Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program and automated security tooling, ensuring issues are tracked and resolved within defined SLAs
- Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs
- Investigate product security incidents as a subject matter expert, using logs and monitoring tools to assess scope, impact, and root cause
- Develop and deliver training to educate engineers on secure coding best practices, threat modeling techniques, and emerging threats
- Stay informed of industry trends, emerging threats, and best practices to ensure that Asana's security posture remains robust and ahead of the threat landscape
- Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management and security program maturity
- Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software
- You will be instrumental in scaling our security practices by conducting security design reviews, threat modeling, and vulnerability assessments across our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset
- This role is based in our Warsaw office with an office-centric hybrid schedule
- The standard in-office days are Monday, Tuesday, and Thursday
Требования
- Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making
- 5+ years of experience in application security, product security, or software engineering with a security focus, with significant experience in security design reviews, threat modeling, and vulnerability assessments
- Strong software engineering background with experience in languages like Python, JavaScript/TypeScript or Scala
- Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection
- Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management
- Proven experience performing security design reviews and threat modeling for complex, distributed applications, with the ability to identify systemic risk and drive remediation at scale
- Excellent communication skills for collaborating effectively with both technical and non-technical partners, translating security risk into business impact
- A pragmatic and collaborative mindset, with a passion for building defenses into the software development lifecycle and enabling other engineers to do their best, most secure work
- At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission
Условия
- Generous, transparent and fair compensation system (base salary and RSUs)
- Contract of Employment (and the option of 50% tax deductible costs for author’s rights usage in respect of applicable roles)
- Health insurance with dental and travel coverage (Lux Med)
- Breakfast and lunch catering on the days that you work from the office
- Vacation allowance
- Career growth budget
- Home office setup budget
- Gym/Fitness card
- Fertility healthcare and family-forming support with Carrot
- Mental Health Support in Modern Health
- Group life insurance
- MacBooks with all necessary accessories
- For this role, the estimated base salary range is between 31,900 - 36,250 PLN gross per month (subject to all taxes and necessary deductions)
- The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process
- The listed range above is a guideline, and the base salary range for this role may be modified
- In addition to base salary, your compensation package may include additional components such as equity and sales incentive pay (for most sales roles), and benefits
- If you're interviewing for this role, speak with your recruiter to learn more about the total compensation and benefits for this role
- Most Asanas have the option to work from home on Wednesdays
- Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements
- We offer a Contract of Employment (UoP) for our employees in Poland
Паспорт вакансии
История публикации
Появилась в Вакандии29 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 24 дня назад
Среди похожихНет данных60 из 30 · у похожих вакансий почти одинаковый возраст — сравнивать нечего
Откуда что взялось
Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.
ГрейдMiddleвыведено из другого признака
Формат работыГибридвычитано из текста вакансии
ГеографияВаршава, Польшавычитано из текста вакансии
Зарплата≈ 15 042 USD в месяцнаша оценка, в вакансии не названа
Почему на этом месте в выдаче
Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.
Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка
Проверка Вакандии
Источники и свежесть
- Тип источника
- Карьерный сайт работодателя
- Найдено публикаций
- 1
Посмотреть публикации и даты
- greenhouseОсновная публикация · 2026-07-21
Безопасность
Отклик уходит на сайт источника
Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайте — asana.com.
Признаки мошенничества
- Просят предоплату, «залог» или деньги за обучение и оборудование.
- Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
- Быстро уводят в мессенджер и торопят с решением.
- Обещают большой доход без опыта и без деталей задач.
Настоящий работодатель не просит денег и платёжных данных до трудоустройства.
Продолжить поиск
Похожие вакансии
Причина сходства указана на каждой карточке
Подробнее - Подробнее
Почему похожа: похожая специализация · тот же город
Applications Security Engineer III
- Senior
- Гибрид
- Варшава, Польша
- Подробнее
Почему похожа: похожая специализация · тот же грейд
Cybersecurity Application Security Engineer
- Middle
- Белград, Сербия