Application Security Engineer - Threat Modeling Champion

Decisive Point

Warszawa

On-site

PLN 356,000 - 405,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Breakfast and lunch catering
Career growth budget
Home office setup budget
Gym/Fitness card
MacBooks with accessories
Fertility healthcare and family-form"
Mental Health Support

Job summary

Asana is seeking an Application Security Engineer in Warsaw to join a security team that protects employees, users, and customers. You will conduct security design reviews, threat modeling, and vulnerability assessments across products and internal apps, driving secure design decisions and incident response.

You will collaborate with IT, infrastructure, and product teams to embed security into the software lifecycle, delivering training and staying ahead of evolving threats in a fast-paced

Qualifications

  • 5+ years of experience in application security, product security, or software engineering with a security focus, with significant experience in security design reviews, threat modeling, and vulnerability assessments.
  • Strong software engineering background with experience in languages like Python, JavaScript/TypeScript or Scala.
  • Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection.
  • Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management.
  • Proven experience performing security design reviews and threat modeling for complex, distributed applications, with the ability to identify systemic risk and drive remediation at scale.
  • Excellent communication skills for collaborating effectively with both technical and non-technical partners, translating security risk into business impact.
  • A pragmatic and collaborative mindset, with a passion for building defenses into the software development lifecycle and enabling other engineers to do their best, most secure work.

Responsibilities

  • Conduct security architecture reviews and threat modeling for new features and services across our product and internal applications, identifying risks early and influencing secure design decisions.
  • Perform vulnerability assessments of software and systems, using a range of assessment methodologies to surface and prioritize security weaknesses across our product surface.
  • Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program and automated security tooling, ensuring issues are tracked and resolved within defined SLAs.
  • Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
  • Investigate product security incidents as a subject matter expert, using logs and monitoring tools to assess scope, impact, and root cause.
  • Develop and deliver training to educate engineers on secure coding best practices, threat modeling techniques, and emerging threats.
  • Stay informed of industry trends, emerging threats, and best practices to ensure that Asana's security posture remains robust and ahead of the threat landscape.
  • Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management and security program maturity.
  • Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software.

Skills

Security architecture reviews
Threat modeling
Vulnerability assessments
Security design reviews
Communication skills
Collaborative mindset

Tools

Python
JavaScript/TypeScript
Scala
SAST/DAST tools
SCA
Vulnerability management tools

Job description

Asana is seeking an Application Security Engineer in Warsaw to join a security team that protects employees, users, and customers. You will conduct security design reviews, threat modeling, and vulnerability assessments across products and internal apps, driving secure design decisions and incident response.

You will collaborate with IT, infrastructure, and product teams to embed security into the software lifecycle, delivering training and staying ahead of evolving threats in a fast-paced

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer: Threat Modelling & Secure Design
Application Security Engineer: Threat Modelling & Secure Design

Asana • Warszawa

Hybrid
RSUs
Health insurance with dental and 여행 보?
Breakfast and lunch catering
+7
Application Security Engineer - Warsaw Hybrid
Application Security Engineer - Warsaw Hybrid

Asana • Warszawa

Hybrid
Health insurance
Meal allowances
Office-centric hybrid schedule
+1
Head of Offensive Security — Red Team & App Sec (Warsaw)
Head of Offensive Security — Red Team & App Sec (Warsaw)

Asana • Warszawa

Hybrid
Health insurance
Career growth budget
MacBooks with accessories
Warsaw Offensive Security Lead - Build and Defend
Warsaw Offensive Security Lead - Build and Defend

Decisive Point • Warszawa

Hybrid
PLN 485,000 - 552,000
Generous compensation package
Office-centric hybrid schedule
Health insurance
+3
Security Operations Engineer, Threat Response
Security Operations Engineer, Threat Response

Decisive Point • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+2
Purple Team Tech Lead - Threat Ops & Response
Purple Team Tech Lead - Threat Ops & Response

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+2
Security Engineer, Threat Response Warsaw
Security Engineer, Threat Response Warsaw

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Vacation allowance
+6
Security Engineer, Threat Response
Security Engineer, Threat Response

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+3
Senior Application Security Engineer: Threat Modeling & Pentests
Senior Application Security Engineer: Threat Modeling & Pentests

HeadHR • Warszawa

On-site
PLN 250,000 - 350,000
Private healthcare with rehabilitation
Extra parental days (6/yr)
Cafeteria
+1
Security Engineer, Threat Response
Security Engineer, Threat Response

Decisive Point • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+2