Application Security Engineer: Threat Modelling & Secure Design

Asana

Warszawa

Hybrid

PLN 356,004 - 404,550

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs
Health insurance with dental and 여행 보?
Breakfast and lunch catering
Vacation allowance
Career growth budget
Home office setup budget
Gym/Fitness card
Mental Health Support
Group life insurance
MacBooks with accessories

Job summary

Asana in Warsaw seeks an Application Security Engineer to join our Security team, partnering with IT, infrastructure, and product teams to ensure we design and ship secure software. This role is based in our Warsaw office with a hybrid schedule (office days Mon, Tue, Thu; possible WFH on Wed; Friday depends on work).

We offer a Contract of Employment for Poland. The candidate will conduct security design reviews, threat modelling, and vulnerability assessments, influencing secure design

Qualifications

  • 5+ years of experience in application security, product security, or software engineering with a security focus.
  • Strong software engineering background in at least one modern language (Python/JS/Scala).
  • Deep knowledge of OWASP Top 10 and common web vulnerabilities (XSS, CSRF, SSRF, SQLi).
  • Experience with security design reviews, threat modelling, and vulnerability assessments.

Responsibilities

  • Conduct security architecture reviews and threat modelling for new features and services across our product and internal applications, identifying risks early and influencing secure design decisions.
  • Perform vulnerability assessments of software and systems, using a range of assessment methodologies to surface and prioritize security weaknesses across our product surface.
  • Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program and automated security tooling, ensuring issues are tracked and resolved within defined SLAs.
  • Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
  • Investigate product security incidents as a subject matter expert, using logs and monitoring tools to assess scope, impact, and root cause.
  • Develop and deliver training to educate engineers on secure coding best practices, threat modelling techniques, and emerging threats.
  • Stay informed of industry trends, emerging threats, and best practices to ensure that Asana’s security posture remains robust.
  • Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management and security programme maturity.
  • Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure, and detection and response.

Skills

Python
JavaScript/TypeScript
Scala

Tools

SAST
DAST
SCA

Job description

Asana in Warsaw seeks an Application Security Engineer to join our Security team, partnering with IT, infrastructure, and product teams to ensure we design and ship secure software. This role is based in our Warsaw office with a hybrid schedule (office days Mon, Tue, Thu; possible WFH on Wed; Friday depends on work).

We offer a Contract of Employment for Poland. The candidate will conduct security design reviews, threat modelling, and vulnerability assessments, influencing secure design

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer - Threat Modeling Champion
Application Security Engineer - Threat Modeling Champion

Decisive Point • Warszawa

On-site
PLN 356,000 - 405,000
Health insurance
Breakfast and lunch catering
Career growth budget
+5
Application Security Engineer - Warsaw Hybrid
Application Security Engineer - Warsaw Hybrid

Asana • Warszawa

Hybrid
Health insurance
Meal allowances
Office-centric hybrid schedule
+1
Security Engineer, Threat Response Warsaw
Security Engineer, Threat Response Warsaw

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Vacation allowance
+6
Security Engineer, Threat Response
Security Engineer, Threat Response

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+3
Security Engineer, Threat Response
Security Engineer, Threat Response

Decisive Point • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Career growth budget
+2
Application Security Engineer Warsaw
Application Security Engineer Warsaw

Asana • Warszawa

Hybrid
RSUs
Health insurance with dental and 여행 보?
Breakfast and lunch catering
+7
Head of Offensive Security — Red Team & App Sec (Warsaw)
Head of Offensive Security — Red Team & App Sec (Warsaw)

Asana • Warszawa

Hybrid
Health insurance
Career growth budget
MacBooks with accessories
Warsaw Offensive Security Lead - Build and Defend
Warsaw Offensive Security Lead - Build and Defend

Decisive Point • Warszawa

Hybrid
PLN 485,000 - 552,000
Generous compensation package
Office-centric hybrid schedule
Health insurance
+3
Application Security Engineer
Application Security Engineer

Asana • Warszawa

Hybrid
Health insurance
Meal allowances
Office-centric hybrid schedule
+1
Security Operations Engineer — Hybrid (Warsaw)
Security Operations Engineer — Hybrid (Warsaw)

Asana • Warszawa

Hybrid
Health insurance
Breakfast and lunch catering
Vacation allowance
+6