Jobedly Post a Job

Application Security Engineer

Asana · Warsaw
Full-timeLegal Services$102,000–$138,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Application Security Engineer role

Application Security Engineer positions focus on delivering results in their domain. This page aggregates open Application Security Engineer roles and what employers typically expect.

The Security team is responsible for protecting Asana’s employees, users, and customers. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements. We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations. We’re looking for an Application Security Engineer to join our Security team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by conducting security design reviews, threat modeling, and vulnerability assessments across our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset. This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve ● Conduct security architecture reviews and threat modeling for new features and services across our product and internal applications, identifying risks early and influencing secure design decisions. ● Perform vulnerability assessments of software and systems, using a range of assessment methodologies to surface and prioritize security weaknesses across our product surface. ● Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program and automated security tooling, ensuring issues are tracked and resolved within defined SLAs. ● Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs. ● Investigate product security incidents as a subject matter expert, using logs and monitoring tools to assess scope, impact, and root cause. ● Develop and deliver training to educate engineers on secure coding best practices, threat modeling techniques, and emerging threats. ● Stay informed of industry trends, emerging threats, and best practices to ensure that Asana's security posture remains robust and ahead of the threat landscape. ● Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management and security program maturity. ● Join a collaborative Security team composed of specialists in product, application, software engineering, infrastructure and detection and response, all working together to help engineering teams design and ship secure software. About you ● Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making. ● 5+ years of experience in application security, product security, or software engineering with a security focus, with significant experience in security design reviews, threat modeling, and vulnerability assessments. ● Strong software engineering background with experience in languages like Python, JavaScript/TypeScript or Scala. ● Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection. ● Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management. ● Proven experience performing security design reviews and threat modeling for complex, distributed applications, with the ability to identify systemic risk and drive remediation at scale. ● Excellent communication…

Salary estimate

$102,000 – $138,000/yr
Provided by the employer.

Skills for this role

JavascriptTypescriptPythonSQLCommunicationSecurity

Resume tips for Application Security Engineer applicants

Interview preparation

Prepare concrete STAR-format stories that show Application Security Engineer outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Application Security Engineer problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Asana

Asana is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles