Application Security Engineer

Asana

Warszawa

On-site

PLN 356,004 - 404,550

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Meal allowances
Office-centric hybrid schedule
Equity/RSUs

Job summary

Asana in Warsaw seeks an Application Security Engineer to join the Security team. You will partner with IT, infrastructure, and product teams to design and ship secure software, conducting security reviews and threat modeling across products and internal apps.

You’ll develop and deliver training on secure coding, stay ahead of threats, and help evolve risk management as part of a collaborative security function. Office-centric hybrid schedule in Warsaw.

Qualifications

  • 5+ years of experience in application security, product security, or software engineering with security focus.
  • Strong software engineering background: Python, JavaScript/TypeScript, or Scala.
  • Deep knowledge of OWASP Top 10 and common web vulnerabilities (XSS, CSRF, SSRF, SQLi).
  • Experience with security design reviews, threat modeling, vulnerability assessments.

Responsibilities

  • Conduct security architecture reviews and threat modeling for new features and services.Identify risks early and influence secure design decisions.
  • Perform vulnerability assessments of software and systems and prioritize weaknesses.
  • Triage, investigate, and remediate vulnerabilities from bug bounty and tooling, tracking SLAs.
  • Influence engineering through security constraints in design/roadmap reviews and trade-offs.
  • Investigate security incidents using logs and monitoring tools to assess impact and root cause.
  • Deliver training on secure coding, threat modeling, and emerging threats.
  • Stay informed on industry threats to keep security posture robust.

Skills

Security design reviews
Threat modeling
Vulnerability assessments
OWASP Top 10 knowledge
SAST/DAST tools
SCA tools
Python
JavaScript/TypeScript
Scala
Communication skills

Tools

SAST
DAST
SCA

Job description

The Security team is responsible for protecting Asana’s employees, users, and customers. Weare a team of security engineers and risk and compliance practitioners who build innovativesafeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements. We collaborate closely with teams across theorganization to foster a culture of security throughout our product and operations. We’re lookingfor an Application Security Engineer to join our Security team in Warsaw. You’ll be afoundational member of the security presence in a key engineering hub, partnering directly withIT, infrastructure, and product teams to ensure we design and ship secure software. You will beinstrumental in scaling our security practices by conducting security design reviews, threatmodeling, and vulnerability assessments across our products and internal applications,eliminating entire classes of vulnerabilities, and championing a security-first mindset.

This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, andyour recruiter can share more about the in-office requirements.We offer a Contract of Employment (UoP) for our employees in Poland.

What you’ll achieve
  • Conduct security architecture reviews and threat modeling for new features and servicesacross our product and internal applications, identifying risks early and influencing securedesign decisions.
  • Perform vulnerability assessments of software and systems, using a range of assessmentmethodologies to surface and prioritize security weaknesses across our product surface.
  • Triage, investigate, and drive remediation of vulnerabilities from our bug bounty programand automated security tooling, ensuring issues are tracked and resolved within definedSLAs.
  • Influence engineering initiatives by conducting design and roadmap reviews, effectivelycommunicating security constraints, and assisting teams in making informed trade-offs.
  • Investigate product security incidents as a subject matter expert, using logs andmonitoring tools to assess scope, impact, and root cause.
  • Develop and deliver training to educate engineers on secure coding best practices, threatmodeling techniques, and emerging threats.
  • Stay informed of industry trends, emerging threats, and best practices to ensure thatAsana's security posture remains robust and ahead of the threat landscape.
  • Collaborate with teammates and stakeholders to develop both short-term and long-termstrategies for risk management and security program maturity.
  • Join a collaborative Security team composed of specialists in product, application,software engineering, infrastructure and detection and response, all working together tohelp engineering teams design and ship secure software.
About you
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
  • 5+ years of experience in application security, product security, or software engineeringwith a security focus, with significant experience in security design reviews, threatmodeling, and vulnerability assessments.
  • Strong software engineering background with experience in languages like Python,JavaScript/TypeScript or Scala.
  • Deep working knowledge of the OWASP Top 10 and common web applicationvulnerabilities such as XSS, CSRF, SSRF, and SQL injection.
  • Experience with security tools for static/dynamic analysis (SAST/DAST), softwarecomposition analysis (SCA), and vulnerability management.
  • Proven experience performing security design reviews and threat modeling for complex,distributed applications, with the ability to identify systemic risk and drive remediation atscale.
  • Excellent communication skills for collaborating effectively with both technical andnon-technical partners, translating security risk into business impact.
  • A pragmatic and collaborative mindset, with a passion for building defenses into thesoftware development lifecycle and enabling other engineers to do their best, most securework.

At Asana, we're committed to building teams that include a variety of backgrounds,perspectives, and skills, as this is critical to helping us achieve our mission.

What we’ll offer
  • Generous, transparent and fair compensation system (base salary and RSUs)
  • Contract of Employment (and the option of 50% tax deductible costs for author’s rightsusage in respect of applicable roles)
  • Health insurance with dental and travel coverage (Lux Med)
  • Breakfast and lunch catering on the days that you work from the office
  • Vacation allowance
  • Career growth budget
  • Home office setup budget
  • Gym/Fitness card
  • Fertility healthcare and family-forming support with Carrot
  • Mental Health Support in Modern Health
  • Group life insurance
  • MacBooks with all necessary accessories

For this role, the estimated base salary range is between 31,900 - 36,250 PLN gross per month (subject to all taxes and necessary deductions). The actual base salary will vary based onvarious factors, including market and individual qualifications objectively assessed during theinterview process. The listed range above is a guideline, and the base salary range for this rolemay be modified.
In addition to base salary, your compensation package may include additional componentssuchas equity and sales incentive pay (for most sales roles), and benefits. If you're interviewing forthis role, speak with your recruiter to learn more about the total compensation and benefits forthis role.

About us

Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

Join Asana’s Talent Networkto stay up to date on job opportunities and life at Asana.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Decisive Point • Warszawa

On-site
PLN 356,000 - 405,000
Health insurance
Breakfast and lunch catering
Career growth budget
+5
Manager, Offensive Security Warsaw
Manager, Offensive Security Warsaw

Asana • Warszawa

Hybrid
Health insurance
Career growth budget
MacBooks with accessories
Manager, Offensive Security
Manager, Offensive Security

Decisive Point • Warszawa

Hybrid
PLN 485,000 - 552,000
Generous compensation package
Office-centric hybrid schedule
Health insurance
+3
Application Security Engineer Warsaw
Application Security Engineer Warsaw

Asana • Warszawa

Hybrid
RSUs
Health insurance with dental and 여행 보?
Breakfast and lunch catering
+7
Security Engineer, Threat Response Warsaw
Security Engineer, Threat Response Warsaw

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Vacation allowance
+6
Security Engineer, Threat Response
Security Engineer, Threat Response

Decisive Point • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+2
Security Engineer, Threat Response
Security Engineer, Threat Response

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+3
Group Tech Lead, Security Operations
Group Tech Lead, Security Operations

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch at office
Vacation allowance
+4
Group Tech Lead, Security Threat Operations & Response Management Warsaw
Group Tech Lead, Security Threat Operations & Response Management Warsaw

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+2
Security Risk and Compliance Lead Warsaw
Security Risk and Compliance Lead Warsaw

Asana • Warszawa

Hybrid
PLN 254,000 - 304,000
Health insurance (Lux Med)
Meals reimbursement on office days
Career growth budget
+3