Startups

Security Risk Engineer

Asana · San Francisco · On-site

← All jobs
About Asana

Work management software for teams and AI agents. Plan, automate, and execute critical workflows together. Backed by a16z and Founders Fund.

About the role

As the Security Risk Engineer, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership.

What they're looking for

  • 7+ years of experience in information security with a strong focus on security risk management and GRC
  • Demonstrated experience building or leading a security risk management program — not just contributing to one
  • Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis. You back up risk ratings with numbers, not just color codes
  • Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making
  • Strong understanding of cloud environments and SaaS architecture — enough to have credible risk conversations with technical teams
  • Excellent communicator who can translate technical risk findings for both engineering teams and C-suite stakeholders
More about this role

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations.

As the Security Risk Engineer, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements

-...

Read the full posting on Asana's site ↗

Security Operations

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.