Skip to main content

Manager, Offensive Security

Asana
Hybrid - Warsaw, Poland (Mon/Tue/Thu in office)Updated 6d ago
Base salary
$44k–$50k
Published base salary range
Location
Hybrid - Warsaw, Poland (Mon/Tue/Thu in office)
Remote eligibility
Employment
Full-time
Lead / Manager
Role family
Security
B2B SaaS
Apply on asana.com
Job actionsApply now
Job actionsApply now

About the job

Company

Asana is a leading platform for human + AI collaboration, helping millions of teams achieve their goals. The Security team protects Asana's employees, users, and customers, collaborating across the organization to foster a culture of security.

Role

We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw. You will own and grow a team spanning red team operations, application security, and vulnerability management, driving strategic direction and hands-on execution.

Responsibilities

  • Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management.
  • Define team roadmap, OKRs, and priorities aligned with security and engineering strategy.
  • Plan and execute red team operations and adversary simulation exercises.
  • Perform cloud security assessments evaluating misconfigurations, privilege escalation paths, and lateral movement.
  • Develop and maintain red team tooling, TTPs, and playbooks.
  • Oversee security architecture reviews and threat modeling for new features.
  • Own and operate Asana's bug bounty program and mature vulnerability management.
  • Implement technical security controls within the SDLC, including PR blockers and automated pipeline gates.
  • Translate complex technical vulnerabilities into executive-level risk reports.

Qualifications

  • 8+ years in offensive security, application security, or related disciplines, with hands-on depth in red team operations or web application penetration testing.
  • 3+ years managing and mentoring a team of offensive or application security engineers.
  • Proven track record of leading end-to-end security assessments and operating/maturing vulnerability management programs.
  • Deep expertise in modern web application security flaws (OWASP Top 10) and cloud security assessments.
  • Ability to read and understand source code across Python, Java, JavaScript/TypeScript, Go, C/C++.
  • Strong understanding of vulnerability taxonomies (CVEs, CWEs, CVSS) and offensive tooling, red team frameworks, SAST/DAST/SCA platforms.
  • Exceptional ability to translate technical vulnerabilities into executive-level risk reports.

Compensation

Base salary range: 43,500 - 49,500 PLN gross per month, plus equity and benefits.

Benefits

  • Health insurance with dental and travel coverage (Lux Med)
  • Breakfast and lunch catering on office days
  • Vacation allowance
  • Career growth budget
  • Home office setup budget
  • Gym/Fitness card
  • Fertility healthcare and family-forming support with Carrot
  • Mental Health Support in Modern Health
  • Group life insurance
  • MacBooks with all necessary accessories

Application

Apply via the provided link.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.