Senior Security Engineer, Threat Response

Asana, Inc.

Vancouver

Hybrid

CAD 200,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Mental health benefits
Career coaching
Inclusive family building benefits
Long-term savings/retirement plans
In-office culinary options

Job summary

Asana, Inc. is seeking a seasoned Security Engineer to lead detection, analysis, and response across our cloud, identity, and software supply chain. You will build and maintain detection-as-code infrastructure, contribute to SOAR playbooks, and collaborate with engineering to integrate secure practices.

The role emphasizes automation, code reviews, and proactive threat hunting within an office-centric hybrid Vancouver setup. Strong scripting and EDR/SIEM expertise are essential.

Qualifications

  • 8+ years in threat detection, security operations, or incident response across cloud, identity, and SaaS.
  • Proficient in Python and security scripting; knowledge of Bash/Go/JS is a plus.
  • Experience auditing modern developer ecosystems (npm, PyPI) and CI/CD pipelines.

Responsibilities

  • Lead detection, analysis, and response across cloud, endpoints, and software supply chain.
  • Investigate and remediate incidents across AWS/GCP/Azure and SaaS environments.
  • Contribute to detection-as-code infrastructure, SOAR playbooks, and production codebase.

Skills

Threat detection
Security operations
Incident response
Python
Bash/Go/JS
REST APIs
Git workflows
Threat hunting
MITRE ATT&CK

Tools

Panther
Splunk
Elastic Security
CrowdStrike
SentinelOne
Okta

Job description

Our Security team keeps Asana's employees, users, and customers safe, by proactively addressing threats and fostering a culture of security throughout our product and operations.

We are looking for a savvy Security Engineer to join our Blue Team. You will be a foundational member of the security presence in our Warsaw innovation hub, partnering directly with IT, infrastructure, and product teams to ensure we have robust detection and response capabilities.Detection and response here leans on engineering practice. We are investing in automation and detection-as-code to cut down on manual triage, and we are looking for someone comfortable writing and reviewing code as part of that work.

This role is based in our Vancouver office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.

What you'll achieve:
  • Lead detection, analysis, and response across our cloud and SaaS environments, identity providers, endpoints, and the software supply chain, ensuring timely and effective remediation of security incidents.
  • Investigate and remediate security incidents across cloud infrastructure (AWS/GCP/Azure), identity providers (e.g., Okta), and SaaS environments.
  • Investigate and contain software supply chain and CI/CD incidents, from unauthorized changes in build environments to suspect third-party dependencies (e.g., npm, PyPI).
  • Help build and maintain our detection-as-code infrastructure (e.g., Panther), SOAR automation, and response playbooks, treating detection logic as tested, version-controlled production code.
  • Utilize and optimize security tools such as Panther for SIEM, CrowdStrike for endpoint detection and response, and other security platforms.
  • Conduct proactive threat hunting and operationalize threat intelligence across cloud, endpoint, and identity telemetry to catch threats beyond standard SIEM alerting.
  • Conduct forensic analysis during security incidents to understand the scope and impact of incidents.
  • Collaborate with engineering teams to integrate security best practices into development processes and provide guidance on secure configurations.
  • Develop and deliver training to educate engineers on security operations and incident response best practices.
About you:
  • 8+ years of experience in threat detection, security operations, or incident response, including investigating incidents across cloud platforms, identity providers, and SaaS applications, with practical knowledge of audit logging and IAM.
  • Proficient in Python (Bash, Go, or JavaScript/TypeScript is a plus) for security scripting and automation, with hands-on experience across REST APIs, Git workflows, and PR-based code reviews.
  • Hands-on experience investigating software supply chain threats, with fluency in auditing modern developer ecosystems (e.g., npm, PyPI), build logs, and CI/CD pipelines.
  • Familiarity with "Detection as Code" methodologies, including test-driven detection logic and rule management through CI/CD pipelines.
  • Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security) for log analysis, alert correlation, and dashboard creation.
  • Deep working knowledge of endpoint detection and response (EDR) tools (e.g., CrowdStrike, SentinelOne) with specialized expertise in macOS endpoint security, telemetry, and threat detection capabilities.
  • Experience performing digital forensics and root-cause analysis to determine incident scope and impact.
  • Familiarity with common attack techniques, tactics, and procedures (TTPs) and frameworks like MITRE ATT&CK.
  • Collaborative and pragmatic, with strong communication skills across technical and non-technical partners, committed to building robust defenses and helping engineers do their best, most secure work.
  • Demonstrated curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.

What we offer:

Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.

For this role, the estimated base salary range is between CAD $200,000-$240,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified.

In addition to base salary, your compensation package may include additional components such as equity, sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:

  • Mental health, wellness & fitness benefits
  • Career coaching & support
  • Inclusive family building benefits
  • Long-term savings or retirement plans
  • In-office culinary options to cater to your dietary preferences

These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

#LI-Hybrid

About us

Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law.

Join Asana’s Talent Networkto stay up to date on job opportunities and life at Asana.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Threat Response Vancouver, BC
Senior Security Engineer, Threat Response Vancouver, BC

Asana, Inc. • Vancouver

Hybrid
CAD 200,000 - 240,000
Mental health benefits
Career coaching
Family building benefits
+2
Product Security Engineer Vancouver, BC
Product Security Engineer Vancouver, BC

Asana, Inc. • Vancouver

On-site
CAD 176,000 - 200,000
Mental health benefits
Career coaching & support
Inclusive family building benefits
+2
Senior Security Technical Program Manager Vancouver, BC
Senior Security Technical Program Manager Vancouver, BC

Asana • Vancouver

On-site
CAD 150,000 - 170,000
Mental health benefits
Career coaching
Family building benefits
+2
Senior Security Technical Program Manager
Senior Security Technical Program Manager

Decisive Point • Vancouver

On-site
CAD 150,000 - 170,000
Mental health and wellness benefits
Career coaching & support
Inclusive family building benefits
+2
Third Party Risk Management Lead Vancouver, BC
Third Party Risk Management Lead Vancouver, BC

Asana, Inc. • Vancouver

Hybrid
CAD 123,000 - 140,000
Mental health benefits
Career coaching
Retirement plans
+1
Third Party Risk Management Lead
Third Party Risk Management Lead

Decisive Point • Vancouver

Hybrid
CAD 123,000 - 140,000
Mental health benefits
Career coaching
Inclusive family building benefits
+2
Analytical Engineering Manager Vancouver, BC
Analytical Engineering Manager Vancouver, BC

Asana • Vancouver

On-site
CAD 167,000 - 178,000
Mental health, wellness & fitness
Career coaching & support
Inclusive family building benefits
+2
IT Systems Engineer - Identity
IT Systems Engineer - Identity

Asana • Vancouver

On-site
CAD 132,000 - 150,000
Mental health, wellness & fitness
Career coaching & support
Inclusive family building benefits
+2
Analytical Engineering Manager
Analytical Engineering Manager

Asana • Vancouver

Hybrid
CAD 167,000 - 178,000
Mental health, wellness & fitness
Career coaching & support
Inclusive family benefits
+2
Senior Analytics Engineer Vancouver, BC
Senior Analytics Engineer Vancouver, BC

Asana • Vancouver

On-site
CAD 106,000 - 120,000
Health insurance
Home office setup budget
Gym/Fitness card
+2