Security Architecture Engineer, STORM
asana
📍 Warsaw, US0🕐 4 giorni fa
Candidati ora →
Crea un account gratis in 30 secondi: ottieni anche il match score AI con il tuo CV.
Descrizione
<p id="p-rc_7f7ddae2932a5d60-340" data-path-to-node="3"><span data-path-to-node="3,0">STORM (Security Threat Operations & Response Management) is Asana's security operations organization, made up of red and blue team specialists focused on protecting Asana's employees, users, and customers</span><span data-path-to-node="3,2">. We proactively address threats, embed security across the product lifecycle, and partner closely with Asana's broader R&D and engineering teams to make security-by-design the norm</span><span data-path-to-node="3,4">. We are looking for a collaborative, analytical Security Architecture Engineer to join our team in Warsaw to solve complex design challenges and scale our architectural security defenses</span><span data-path-to-node="3,6">.</span></p>
<p id="p-rc_7f7ddae2932a5d60-341" data-path-to-node="4"><span data-path-to-node="4,0">This role is based in our Warsaw offi<span class="citation-1340 citation-end-1340">ce with an office-centric hybrid schedule</span></span><span data-path-to-node="4,2"><span class="citation-1339">. The standard in-office days are Monday, Tuesday, and</span><span class="citation-1338 citation-1339 citation-end-1339"> Thursday</span></span><span data-path-to-node="4,4"><span class="citation-1336 citation-1337 citation-end-1337">. Most Asanas have the option to work from home on Wednesdays</span></span><span data-path-to-node="4,6"><span class="citation-1334 citation-1335 citation-end-1335">. Working from home on Frida</span><span class="citation-1334 citation-end-1334">ys depends on the type of work you do and the teams with which you partner</span></span><span data-path-to-node="4,8"><span class="citation-1333 citation-end-1333">. If you're interview</span>ing for this role, your recruiter will share more about the in-office requirements</span><span data-path-to-node="4,10">.</span></p>
<p id="p-rc_7f7ddae2932a5d60-342" data-path-to-node="5"><span data-path-to-node="5,0">We offer a Contract of Employment (UoP) for our employees in Poland</span><span data-path-to-node="5,2">.</span></p>
<h3 data-path-to-node="6">What you’ll achieve</h3>
<ul data-path-to-node="7">
<li>
<p id="p-rc_7f7ddae2932a5d60-343" data-path-to-node="7,0,0"><span data-path-to-node="7,0,0,0"><strong data-path-to-node="7,0,0,0" data-index-in-node="0">Security Design Review & Threat Modelling:</strong> Lead architecture reviews and structured threat modelling (such as STRIDE, OWASP Threat Dragon, and MITRE ATT&CK) for new and in-flight projects to identify risk early and produce actionable guidance before code is written</span><span data-path-to-node="7,0,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-344" data-path-to-node="7,1,0"><span data-path-to-node="7,1,0,0"><strong data-path-to-node="7,1,0,0" data-index-in-node="0">Code & Data Flow Analysis:</strong> Conduct security-focused code reviews and analyze data flows across services, APIs, and integrations to identify trust boundaries and attack surface reduction opportunities</span><span data-path-to-node="7,1,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-345" data-path-to-node="7,2,0"><span data-path-to-node="7,2,0,0"><strong data-path-to-node="7,2,0,0" data-index-in-node="0">Defensive Engineering Recommendations:</strong> Translate threat model findings into concrete engineering recommendations and feed architectural weaknesses to STORM’s red team for proactive adversary emulation planning</span><span data-path-to-node="7,2,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-346" data-path-to-node="7,3,0"><span data-path-to-node="7,3,0,0"><strong data-path-to-node="7,3,0,0" data-index-in-node="0">Architecture Standards & Frameworks:</strong> Build and mature Asana’s security architecture review process and define standards aligned to industry best practices like NIST 800-53, FedRAMP, ISO 27001, and OWASP ASVS</span><span data-path-to-node="7,3,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-347" data-path-to-node="7,4,0"><span data-path-to-node="7,4,0,0"><strong data-path-to-node="7,4,0,0" data-index-in-node="0">Security Pattern Library:</strong> Develop and maintain a reusable security pattern library for authentication, authorization, encryption, API security, and data handling that engineering teams can adopt directly</span><span data-path-to-node="7,4,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-348" data-path-to-node="7,5,0"><span data-path-to-node="7,5,0,0"><strong data-path-to-node="7,5,0,0" data-index-in-node="0">AI Security Architecture:</strong> Evaluate AI tooling and integrations using industry standards (such as OWASP Maestro and OWASP Top 10 for LLMs), assessing risks including prompt injection, model misuse, data leakage, and supply chain exposure</span><span data-path-to-node="7,5,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-349" data-path-to-node="7,6,0"><span data-path-to-node="7,6,0,0"><strong data-path-to-node="7,6,0,0" data-index-in-node="0">AI Governance:</strong> Develop governance practices for AI-augmented development workflows and stay current with the evolving AI security landscape</span><span data-path-to-node="7,6,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-350" data-path-to-node="7,7,0"><span data-path-to-node="7,7,0,0"><strong data-path-to-node="7,7,0,0" data-index-in-node="0">Security Artifact Advocacy:</strong> Champion security-by-design by driving organizational adoption of architecture diagrams, data flow diagrams, and threat models as first-class engineering artefacts</span><span data-path-to-node="7,7,0,2">.</span></p>
</li>
<li>
<p id="p-rc_7f7ddae2932a5d60-351" data-path-to-node="7,8,0"><span data-path-to-node="7,8,0,0"><strong data-path-to-node="7,8,0,0" data-index-in-node="0">Training & Culture:</strong> Deliver highly technical training and workshops to engineering and product teams, making the secure choice the path of least resistance across the organization</span><span data-path-to-node="7,8,0,2">.</span></p>
</li>
</ul>
<h3 data-path-to-node="8">About you</h3>
<ul data-path-to-node="9">
<li>
<p id="p-rc_7f7ddae2932a5d60-352" data-path-to-node="9,0,0"><span data-path-to-node="9,0,0,0">7+ years o
TalentyGo è un aggregatore di offerte da fonti pubbliche. Verifica sempre le informazioni direttamente con l'azienda. La candidatura avviene tramite il sito originale dell'azienda; TalentyGo non gestisce processi di selezione.