Security Engineer Red Team

3 tygodni temu


Warsaw, Polska Asana Pełny etat

At Asana, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations. We're looking for a security engineer to join our Security Red Team in Warsaw. You'll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by performing security reviews and penetration testing assessments of our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset. This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. We offer a Contract of Employment (UoP) for our employees in Poland What you'll achieve: Conduct security architecture reviews, threat modeling, and penetration testing for new features and services across our product and internal applications. Test software for application security vulnerabilities through various assessment methodologies, including penetration testing. Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal penetration tests, and automated security tooling. Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs. Investigate product security incidents as an incident subject matter expert, using logs and monitoring tools. Develop and deliver training to educate engineers on secure coding best practices and emerging threats. Stay informed of industry trends, emerging threats, and best practices to ensure that Asana's security posture remains robust. Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management. Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software. About you: 5 years of experience in application security, product security, penetration assessments, or software engineering with a security focus, with significant experience in security reviews and penetration testing. Strong software engineering background with experience in languages like Python, Javascript/Typescript or Scala Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management. Proven experience performing security design reviews and threat modeling for complex applications, as well as conducting comprehensive penetration tests. Excelling communication skills for collaborating effectively with both technical and non-technical partners. A pragmatic and collaborative mindset, with a passion for building defenses against real-world attacks and enabling other engineers to do their best, most secure work. What we offer: Generous, transparent and fair compensation system (base salary and generous Restricted Stock Unit for Asana Inc.) Contract of Employment (with 50% tax deductible costs for author's rights usage for Engineers) Health insurance with dental and travel coverage (Lux Med) Lunch catering on the days that you work from the office Career growth budget Home office setup budget Gym/Fitness reimbursement Fertility healthcare and family-forming support with Carrot Mental health support in Modern Health Group life insurance MacBooks with all necessary accessories For this role, the estimated base salary range is between 25,604 - 35,854 PLN gross monthly on the contract of employment (UoP). The actual base salary will vary based on various factors and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base compensation range for this role may be modified. Our total compensation consists of base salary and equity (RSUs).


  • IT Security Specialist

    4 tygodni temu


    Warsaw, Polska Jit Team Pełny etat

    Salary: 800 - 1000 PLN/day on B2B Work model: elastic hybrid from Gdynia / Gdańsk / Warszawa (at least 2-3 days per week from the office) Why choose this offer? You can expect a flexible work organization The international work environment will give you the opportunity to interact with the English language on a daily basis Scandinavian organizational...


  • Warsaw, Polska Jit Team sp. z o.o. Pełny etat

    Cisco ISE Network Security Engineer Miejsce pracy: Warszawa Technologies we use Expected ISE Catalyst Center Cisco About the project Salary: 1000 - 1200 PLN/day on B2B Work model: hybrid from Warszawa (2-3 days per week from the office) The project focuses on migrating the existing TrustSec implementation from RADIUS to a more resilient REST API–based...

  • IT Recruiter

    3 tygodni temu


    Warsaw, mazowieckie, Polska Red Global Pełny etat

    About the jobWarsaw based opportunity for a Delivery Consultant role(hybrid, 3 days in the office)At RED Global, we connect the best SAP & IT professionals with leading companies across the world. We’re now growing our Delivery Team in Poland – looking for an experienced Delivery Consultant / Senior Resourcer who’s passionate about tech recruitment and...


  • Warsaw, Polska Visa Technology Europe sp. z o.o. Pełny etat

    Senior Cybersecurity Engineer (Endpoint Security) Miejsce pracy: Warszawa Technologies we use Expected HTML C++ Java Spring Angular About the project Cyber Security is an integral part of Visa's corporate culture. It is important to maintaining our position as an industry leader in electronic payments. At Visa, we believe that it is the responsibility of...


  • Warsaw, Polska The Stepstone Group Polska sp. z o.o. Pełny etat

    Senior Security Engineer II Miejsce pracy: Warszawa Technologies we use Expected Python About the project As a Senior SOC Engineer you will be responsible for monitoring, analysing and responding to security threats, using tools like SIEM and EDR platforms. You'll lead the team in incident detection and response efforts, ensuring swift containment and...


  • Warsaw, Polska Eviden Pełny etat

    We are looking for a 2nd Line Application Engineer with solid expertise in Red Hat Enterprise Linux to join our growing team. This role focuses on ensuring the stability, availability, and performance of critical business applications by providing advanced technical support and troubleshooting. Key Responsibilities: Deliver 2nd line support for...


  • Warsaw, Polska NESS SOLUTION sp. z o.o. Pełny etat

    Imperva Security Engineer Miejsce pracy: Warszawa Technologie, których używamy Wymagane Imperva SecureSphere Cloud WAF O projekcie Szukamy Imperva Security Engineera (Mid), który będzie odpowiadał za utrzymanie i rozwój rozwiązań bezpieczeństwa aplikacyjnego oraz ochrony danych opartych o technologie Imperva. Jeśli dobrze czujesz się w WAF,...

  • Cyber Security Analyst

    4 tygodni temu


    Warsaw, Polska Bayer Sp. z o.o. Pełny etat

    For Digital Hub Warsaw, we are looking for: Cyber Security Analyst This role is responsible for assessing, managing, and enhancing the security measures of Bayer's systems, networks, and data. Especially using data analytics for monitoring of Bayer's security systems and applications. Key Tasks & Responsibilities: Oversee security alerts and incidents,...

  • CSIRT Security Engineer

    3 tygodni temu


    Warsaw, Polska Cyclad Pełny etat

    CSIRT Security Engineer Miejsce pracy: Warszawa Technologies we use Expected ServiceNow Elastic Search About the project In Cyclad we work with top international IT companies in order to boost their potential in delivering outstanding, cutting edge technologies that shape the world of the future. Currently, we are looking for an experienced CSIRT Security...

  • Cloud Identity Systems

    3 tygodni temu


    Warsaw, Polska PRETIUS SOFTWARE SP. Z O.O. Pełny etat

    Cloud Identity Systems & Security Engineer Miejsce pracy: Warszawa Technologies we use Expected Azure Solutions Architect Expert Identity and Access Administrator Associate SAML Microsoft Entra ID Python PowerShell Terraform Optional AI About the project At Pretius, we are looking for Senior Cloud Identity Systems & Security Engineer to a project for...