# Security Risk Engineer at Asana

- Company: Asana
- What the company does: Work management software for teams and AI agents. Plan, automate, and execute critical workflows together. Backed by a16z and Founders Fund.
- Company website: https://asana.com
- Type: Startups
- Level: Mid level
- Location: San Francisco
- Work setup: On-site
- Pay: $194K to $220K base salary per year (USD)
- Posted: 2026-06-29
- Apply by: 2026-10-08
- Apply: https://www.asana.com/jobs/apply/7950767?gh_jid=7950767
- Page: https://www.1752.vc/careers/jobs/asana-security-risk-engineer/

## About the role

As the Security Risk Engineer, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership.

## What they're looking for

- 7+ years of experience in information security with a strong focus on security risk management and GRC
- Demonstrated experience building or leading a security risk management program — not just contributing to one
- Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis. You back up risk ratings with numbers, not just color codes
- Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making
- Strong understanding of cloud environments and SaaS architecture — enough to have credible risk conversations with technical teams
- Excellent communicator who can translate technical risk findings for both engineering teams and C-suite stakeholders

Tags: Security Operations
