Skip to main content

Security Risk Engineer

Asana
Hybrid - San Francisco, 3 days/week (Mon, Tue, Thu)Updated 14d ago
Base salary
$194k–$220k
Published base salary range
Location
Hybrid - San Francisco, 3 days/week (Mon, Tue, Thu)
Remote eligibility
Employment
Full-time
Senior
Role family
Security
B2B SaaS
Apply on asana.com
Job actionsApply now
Job actionsApply now

About the job

About the role

Asana's security team protects employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security. As the Security Risk Engineer, you will own Asana's internal security risk management program end-to-end, engineering the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. This is a senior role for someone who goes beyond frameworks and checklists.

What you'll achieve

  • Own and continuously mature a quantitative risk framework, including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds.
  • Build and maintain a living risk register, developing KRIs, tracking trends, and driving accountability for risk treatment.
  • Design and implement automated data pipelines and integrations that surface security risks from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources.
  • Develop executive-level dashboards that communicate risk in business terms (probability, impact, cost of control vs. breach, residual risk).
  • Partner cross-functionally with Legal, Privacy, Finance, and Engineering to influence security investment decisions.

About you

  • 7+ years of experience in information security with a strong focus on security risk management and GRC.
  • Demonstrated experience building or leading a security risk management program.
  • Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis.
  • Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring.
  • Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
  • Proven ability to develop risk metrics, KRIs, and executive-level reporting.
  • Strong understanding of cloud environments and SaaS architecture.
  • Excellent communication skills for technical and C-suite audiences.
  • Curiosity about AI tools and emerging technologies.

Compensation & benefits

Estimated base salary range: $194,000–$220,000. Compensation may include equity and benefits. Benefits include mental health, wellness & fitness benefits, career coaching & support, inclusive family building benefits, long-term savings or retirement plans, and in-office culinary options.

Location & work style

Based in San Francisco with an office-centric hybrid schedule. Standard in-office days are Monday, Tuesday, and Thursday; most Asanas have the option to work from home on Wednesdays.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.