Security Risk Engineer

Asana
San Francisco
Workplace: HybridFull time194,000 - 220,000 annuallyFunction: Legal, Risk & ComplianceExperience: 7+ yearsSkills: ["Communication","Leadership","Problem-solving","Presentation","Stakeholder management"]

Lead Asana's security risk program end-to-end by building quantitative risk frameworks, automated risk monitoring, and executive-level reporting; partner with Legal, Privacy, Finance, and Engineering to drive risk-informed decisions in a hybrid San Francisco office.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Asana
Asana
2 months ago

Security Risk Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Lead Asana's security risk program end-to-end by building quantitative risk frameworks, automated risk monitoring, and executive-level reporting; partner with Legal, Privacy, Finance, and Engineering to drive risk-informed decisions in a hybrid San Francisco office.
Location: San Francisco
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Sr. Manager level

Key Responsibilities

  • •Own and mature Asana's security risk management program with a quantitative framework, risk scoring, and appetite thresholds.
  • •Build and maintain a central security risk register with KRIs, trend analysis, and remediation ownership.
  • •Automate risk identification and monitoring by designing data pipelines and integrations from scanners, cloud tooling, SIEMs, and third-party sources.
  • •Deliver executive-level risk reporting with dashboards showing probability, impact, cost of control vs. breach, and residual risk.
  • •Partner cross-functionally with Legal, Privacy, Finance, and Engineering to inform security investments and foster a culture of risk awareness.

Pay and Benefits

Salary: 194,000 - 220,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceWellness StipendRetirementFamily Building

Key Requirements

  • •7+ years of experience in information security with a strong focus on security risk management and GRC
  • •Demonstrated experience building or leading a security risk management program — not just contributing to one
  • •Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis
  • •Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring
  • •Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP
Experience:7+ yearsSecurityGRCCloudSaaS
Skills:CommunicationLeadershipProblem-solvingPresentationStakeholder management
Languages:English
Tech Stack:FAIRNISTISO 27001SOC 2FedRAMPSIEMCloudData pipelinesScripting

Company Brief

Asana
Asana provides a work management platform that helps teams coordinate, track, and manage tasks, projects, and workflows. It offers collaboration, task tracking, automation, and reporting tools for organizations of all sizes.
Industry: Enterprise Software
Company Size: Enterprise (1,001+ employees)
Revenue: USD 500M to 1B
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2008
Glassdoor
Glassdoor: 4.2
WebsiteLinkedInGlassdoor