Security Engineer Red Team
4 tygodni temu
At Asana, security is foundational to our mission of helping humanity thrive by enabling the world’s teams to work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.
We’re looking for a security engineer to join our Security Red Team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by performing security reviews and penetration testing assessments of our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset.
This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday.
We offer a Contract of Employment (UoP) for our employees in Poland
What you’ll achieve:
Conduct security architecture reviews, threat modeling, and penetration testing for new features and services across our product and internal applications.
Test software for application security vulnerabilities through various assessment methodologies, including penetration testing.
Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal penetration tests, and automated security tooling.
Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
Investigate product security incidents as an incident subject matter expert, using logs and monitoring tools.
Develop and deliver training to educate engineers on secure coding best practices and emerging threats.
Stay informed of industry trends, emerging threats, and best practices to ensure that Asana’s security posture remains robust.
Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management.
Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software.
About you:
5+ years of experience in application security, product security, penetration assessments, or software engineering with a security focus, with significant experience in security reviews and penetration testing.
Strong software engineering background with experience in languages like Python, Javascript/Typescript or Scala
Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection
Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management.
Proven experience performing security design reviews and threat modeling for complex applications, as well as conducting comprehensive penetration tests.
Excelling communication skills for collaborating effectively with both technical and non-technical partners.
A pragmatic and collaborative mindset, with a passion for building defenses against real-world attacks and enabling other engineers to do their best, most secure work.
What we offer:
Generous, transparent and fair compensation system (base salary and generous Restricted Stock Unit for Asana Inc.)
Contract of Employment (with 50% tax deductible costs for author’s rights usage for Engineers)
Health insurance with dental and travel coverage (Lux Med)
Lunch catering on the days that you work from the office
Career growth budget
Home office setup budget
Gym/Fitness reimbursement
Fertility healthcare and family-forming support with Carrot
Mental health support in Modern Health
Group life insurance
MacBooks with all necessary accessories
For this role, the estimated base salary range is between 25,604 - 35,854 PLN gross monthly on the contract of employment (UoP). The actual base salary will vary based on various factors and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base compensation range for this role may be modified.
Our total compensation consists of base salary and equity (RSUs).
-
CSIRT Security Engineer
6 dni temu
Warszawa, mazowieckie, Polska Experis Manpower Group Pełny etat 16 zł - 800 złExperis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.Location: WarsawSalary: 100-120 pln/hContract:...
-
Security Engineer Detection Engineering
4 tygodni temu
Warszawa, mazowieckie, Polska Asana Pełny etat 25 zł - 604 złSecurity Engineer, Detection EngineeringWe're looking for experienced Senior Security Engineers who care deeply about customers and are passionate about building products that improve the way millions of teams work together. As part of the Detection Engineering team in an innovative security team, you will build the detection capabilities that our blue and...
-
Senior DevOps Engineer
4 tygodni temu
Warszawa, mazowieckie, Polska Jit Team Pełny etat 21 złWynagrodzenie: 125 - 160 PLN net/h + VAT (B2B)Tryb pracy: Praca zdalna z okazjonalnymi wizytami w biurze klienta (Wrocław/Warszawa) - maks. 2 x w miesiącu Dlaczego warto wybrać tę ofertę?Dołącz do zespołu, który pracuje z najnowszymi rozwiązaniami IT, umożliwiając rozwój kariery i zdobywanie cennych doświadczeńZyskaj możliwość pracy nad...
-
Senior DevOps Engineer
3 tygodni temu
Warszawa, mazowieckie, Polska Jit Team Pełny etat 21 złWynagrodzenie: 125 - 160 PLN net/h + VAT (B2B)Tryb pracy: Praca zdalna z okazjonalnymi wizytami w biurze klienta (Wrocław/Warszawa) - maks. 2 x w miesiącu Dlaczego warto wybrać tę ofertę?Dołącz do zespołu, który pracuje z najnowszymi rozwiązaniami IT, umożliwiając rozwój kariery i zdobywanie cennych doświadczeńZyskaj możliwość pracy nad...
-
Senior Security Engineer SSDLC
1 tydzień temu
Warszawa, mazowieckie, Polska Base. Pełny etatDołącz do Base – globalnego lidera, który rewolucjonizuje e-commerce!Jesteśmy technologiczną siłą napędową dla sprzedawców na całym świecie, dostarczając innowacyjny system all-in-one. Naszą misją jest upraszczanie życia przedsiębiorców online, pomagając im automatyzować procesy, dynamicznie skalować działalność i efektywnie...
-
Senior Security Engineer SSDLC
1 tydzień temu
Warszawa, mazowieckie, Polska Base. Pełny etatDołącz do Base – globalnego lidera, który rewolucjonizuje e-commerce!Jesteśmy technologiczną siłą napędową dla sprzedawców na całym świecie, dostarczając innowacyjny system all-in-one. Naszą misją jest upraszczanie życia przedsiębiorców online, pomagając im automatyzować procesy, dynamicznie skalować działalność i efektywnie...
-
Security Engineer – Incident Response Team
1 tydzień temu
Warszawa, mazowieckie, mazowieckie, Polska Sii Sp. z o.o. Pełny etatSecurity Engineer – Incident Response TeamMiejsce pracy: WarszawaTechnologies we useExpectednetcraftVirustotalSymantec DLPGhidraServiceNowAbout the projectWe are seeking an experienced Security Engineer to join our client’s Computer Security Incident Response Team. As part of a team, you will play a crucial role in protecting our organization against...
-
Application Security Engineer
1 tydzień temu
Warszawa, mazowieckie, mazowieckie, Polska Sii Sp. z o.o. Pełny etatApplication Security EngineerMiejsce pracy: WarszawaTechnologies we useExpectedOpenText FortifySonatype NexusIQQualys WASAbout the projectWe are seeking a talented Security Engineer to join our client’s Application Security team. In this role, you will focus on securing applications through activities such as Static Application Security Testing, web...
-
Application Security Engineer
1 tydzień temu
Warszawa, mazowieckie, mazowieckie, Polska Sii Sp. z o.o. Pełny etatApplication Security EngineerMiejsce pracy: WarszawaTechnologies we useExpectedOpenText FortifySonatype NexusIQQualys WASJavaJavaScriptTypeScriptPythonAbout the projectWe are seeking a talented Security Engineer to join our client’s Application Security team. In this role, you will focus on securing applications through activities such as Static...
-
Security Engineer
4 tygodni temu
Warszawa, mazowieckie, Polska SNI Consulting Pełny etat 20 zł - 160 złSNI is serving as a trusted IT Outsourcing partner in line with the needs of World's most prestigious firms and carried out successful projects worldwide.Scope: This role focuses on analyzing current security processes, identifying automation opportunities, and developing tools and solutions to improve Digital Product Security. The engineer will also help...