Staff Detection Engineer

Decisive Point

Warszawa

On-site

PLN 446,000 - 502,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Breakfast and lunch catering
Vacation allowance
Career growth budget
Home office setup budget
MacBooks with accessories
Gym/Fitness card

Job summary

Asana is seeking a Staff Detection Engineer in our Warsaw hub to own threat detection logic and telemetry pipelines. You will design detections across cloud, identity, endpoints, and the software supply chain, while maturing a detection-as-code workflow in Panther and CI/CD.

Join a team that partners with incident responders and product teams to ensure fast, high-signal detections, with opportunities to apply AI tools and evolving tech. Polish contract work terms apply in Poland.

Qualifications

  • 8+ years in detection engineering, security operations, or threat hunting.
  • Strong Python skills with Git-based workflows, PR reviews, automated tests, and CI/CD.
  • Deep experience with detection-as-code and CI/CD pipelines.
  • Experience with SIEM platforms (Panther, Splunk, Elastic Security) and query languages.
  • Understanding cloud/identity telemetry (AWS, GCP, Okta logs) and attacker activity.
  • Familiarity with EDR tools (CrowdStrike, SentinelOne) and endpoint telemetry.
  • Knowledge of MITRE ATT&CK and how to apply it to coverage decisions.
  • Collaborative mindset with cross-functional communication and a focus on reducing noise.
  • Interest in AI tools and emerging technologies to boost productivity.

Responsibilities

  • Design, build, and maintain high-fidelity detections across cloud, identity, SaaS, endpoints, and software supply chain.
  • Own the detection-as-code pipeline in Panther: rules, tests, review standards, and CI/CD deployment.
  • Map coverage against MITRE ATT&CK and tune detections for top threats.
  • Onboard and normalize telemetry sources with infra and IT for complete logs.
  • Improve alert quality, reduce false positives, and track time-to-triage.
  • Validate detections against real attacker behavior through purple-team exercises and atomic tests.
  • Translate incidents and threat intel into durable detections and coverage.
  • Build enrichment and automation in SOAR so alerts have actionable context.

Skills

Python
Git workflows
PR-based review
CI/CD
Go
Bash
JavaScript/TypeScript
Detection-as-code
SIEM
Cloud telemetry
Okta logs
EDR tools
MITRE ATT&CK
Incident response
AI tools

Tools

Panther
Splunk
Elastic Security

Job description

Our Security team keeps Asana's employees, users, and customers safe by proactively addressing threats and fostering a culture of security across our product and operations.

We're looking for a Staff Detection Engineer to join our Threat Response team in our Warsaw innovation hub. You'll own how we find threats: the detection logic, the telemetry it runs on, and the pipeline that ships it. Detection here is software. Rules are written as code, tested against real and synthetic attacker behavior, reviewed in pull requests, and deployed through CI/CD. You'll partner with our incident responders, infrastructure, and product teams to make sure that when something bad happens, we see it fast and with high signal.

We offer a Contract of Employment (UoP) for our employees in Poland.

What you'll achieve
  • Design, build, and maintain high-fidelity detections across cloud infrastructure (AWS/GCP), identity providers (e.g., Okta), SaaS environments, endpoints, and the software supply chain.
  • Own our detection-as-code pipeline in Panther: rule structure, unit and integration tests, review standards, and CI/CD deployment, so detection logic is treated as production code.
  • Map and close coverage gaps against MITRE ATT&CK and the threat model for our environment, prioritizing the techniques most likely to be used against a SaaS company.
  • Onboard and normalize new telemetry sources, working with infrastructure and IT to make sure the right logs exist, are complete, and are queryable.
  • Measure and improve alert quality, tracking precision, time-to-triage, and false-positive rates, and tuning or retiring detections that don't earn their keep.
  • Validate detections against real attacker behavior through purple-team exercises, atomic tests, and emulation, and feed findings back into rule development.
  • Turn incidents and threat intelligence into detections, partnering with incident responders to convert lessons learned and emerging TTPs into durable coverage.
  • Build enrichment and automation in our SOAR platform so alerts arrive with the context responders need to act.
About You
  • 8+ years in detection engineering, security operations, or threat hunting, with a track record of building detections that responders actually trust.
  • Strong Python skills, with hands-on experience in Git workflows, PR-based code review, automated testing, and CI/CD. Go, Bash, or JavaScript/TypeScript is a plus.
  • Deep experience with detection-as-code, including test-driven detection logic, rule lifecycle management, and deploying rules through CI/CD pipelines.
  • Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security), including query languages, log schemas, and correlation.
  • Deep understanding of cloud and identity telemetry, such as AWS, GCP audit logs, Okta system logs, and SaaS audit APIs, and what attacker activity looks like in each.
  • Working knowledge of EDR tools (e.g., CrowdStrike, SentinelOne) and endpoint telemetry.
  • Fluency with attacker TTPs and MITRE ATT&CK, and experience using it to drive coverage decisions rather than as a checklist.
  • Collaborative and pragmatic mindset, with strong communication across technical and non-technical partners, and an instinct for reducing noise rather than adding to it.
  • Demonstrated curiosity about AI tools and emerging technologies, with willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
Nice to have
  • Experience detecting software supply chain and CI/CD threats, including anomalous behavior in build systems and developer ecosystems (e.g., npm, PyPI, GitHub Actions).
  • Experience with adversary emulation frameworks (e.g., Atomic Red Team, Caldera) or running purple-team exercises.
  • Experience with data engineering for security, such as log pipelines, schema design, or cost optimization for high-volume telemetry.
What we offer
  • Generous, transparent and fair compensation system (base salary and RSUs).
  • Contract of Employment (and the option of 50% tax deductible costs for author’s rights usage in respect of applicable roles).
  • Health insurance with dental and travel coverage (Lux Med).
  • Breakfast and lunch catering on the days that you work from the office.
  • Vacation allowance.
  • Career growth budget.
  • Home office setup budget.
  • Gym/Fitness card.
  • Fertility healthcare and family-forming support with Carrot.
  • Mental Health Support in Modern Health.
  • Group life insurance.
  • MacBooks with all necessary accessories

For this role, the estimated base salary range is between 40 000 - 45 000 PLN gross per month (subject to all taxes and necessary deductions). The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified. In addition to base salary, your compensation package may include additional components such as equity and sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your recruiter to learn more about the total compensation and benefits

for this role.

About Us

Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law.

Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Detection Engineer Warsaw
Staff Detection Engineer Warsaw

Asana, Inc. • Warszawa

On-site
PLN 446,000 - 502,000
Health insurance
Home office setup budget
Gym/Fitness card
+3
Security Engineer, Threat Response
Security Engineer, Threat Response

Asana, Inc. • Warszawa

Hybrid
PLN 356,000 - 405,000
Health insurance with dental andTravel
Office-based with hybrid days
Lunch catering
+6
Security Engineer, Threat Response
Security Engineer, Threat Response

Asana • Warszawa

On-site
PLN 285,740 - 400,130
Health insurance
Breakfast and lunch catering
Career growth budget
+3
Security Engineer, Threat Response Warsaw
Security Engineer, Threat Response Warsaw

Asana • Warszawa

On-site
PLN 285,740 - 400,130
Health insurance
Breakfast and lunch catering
Vacation allowance
+6
Data Scientist
Data Scientist

Visa Hunt • Warszawa

On-site
PLN 323,640 - 367,164
Health insurance
Meal reimbursement
Career budget
+6
Data Scientist Warsaw
Data Scientist Warsaw

Asana • Warszawa

On-site
PLN 324,000 - 367,000
Health insurance
Meals reimbursement
Career growth budget
+7
Data Scientist
Data Scientist

Asana • Warszawa

On-site
PLN 323,640 - 367,164
Health insurance with dental andTravel
Meals reimbursement
Career growth budget
+6
Data Engineer Warsaw
Data Engineer Warsaw

Asana • Warszawa

On-site
PLN 232,000 - 335,000
Health insurance
Lunch catering on office days
Career growth budget
+3
Data Engineer
Data Engineer

Asana • Warszawa

On-site
PLN 232,000 - 335,000
Health insurance
Lunch catering on office days
Career growth budget
+6
Product Manager, Command
Product Manager, Command

Asana • Warszawa

On-site
PLN 412,920 - 513,360
Competitive pay
Contract with tax relief
Health insurance
+8