Manager, Offensive Security
Asana- Base salary
- $44k–$50k Published base salary range
- Location
- Hybrid - Warsaw, Poland (Mon/Tue/Thu in office) Remote eligibility
- Employment
- Full-time Lead / Manager
Role skills
Apply on asana.com
About the job
Company
Asana is a leading platform for human + AI collaboration, helping millions of teams achieve their goals. The Security team protects Asana's employees, users, and customers, collaborating across the organization to foster a culture of security.
Role
We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw. You will own and grow a team spanning red team operations, application security, and vulnerability management, driving strategic direction and hands-on execution.
Responsibilities
- Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management.
- Define team roadmap, OKRs, and priorities aligned with security and engineering strategy.
- Plan and execute red team operations and adversary simulation exercises.
- Perform cloud security assessments evaluating misconfigurations, privilege escalation paths, and lateral movement.
- Develop and maintain red team tooling, TTPs, and playbooks.
- Oversee security architecture reviews and threat modeling for new features.
- Own and operate Asana's bug bounty program and mature vulnerability management.
- Implement technical security controls within the SDLC, including PR blockers and automated pipeline gates.
- Translate complex technical vulnerabilities into executive-level risk reports.
Qualifications
- 8+ years in offensive security, application security, or related disciplines, with hands-on depth in red team operations or web application penetration testing.
- 3+ years managing and mentoring a team of offensive or application security engineers.
- Proven track record of leading end-to-end security assessments and operating/maturing vulnerability management programs.
- Deep expertise in modern web application security flaws (OWASP Top 10) and cloud security assessments.
- Ability to read and understand source code across Python, Java, JavaScript/TypeScript, Go, C/C++.
- Strong understanding of vulnerability taxonomies (CVEs, CWEs, CVSS) and offensive tooling, red team frameworks, SAST/DAST/SCA platforms.
- Exceptional ability to translate technical vulnerabilities into executive-level risk reports.
Compensation
Base salary range: 43,500 - 49,500 PLN gross per month, plus equity and benefits.
Benefits
- Health insurance with dental and travel coverage (Lux Med)
- Breakfast and lunch catering on office days
- Vacation allowance
- Career growth budget
- Home office setup budget
- Gym/Fitness card
- Fertility healthcare and family-forming support with Carrot
- Mental Health Support in Modern Health
- Group life insurance
- MacBooks with all necessary accessories
Application
Apply via the provided link.
Skills & tags
What you can verify before applying
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.