What is a Security Engineer?
A Security Engineer at Asana safeguards the trust that powers collaboration for millions of teams. You will design and build secure-by-default frameworks, controls, and tooling that let product and infrastructure teams move fast without creating risk. Your work prevents entire classes of vulnerabilities, hardens our platform and corporate environment, and ensures threat detection and response scales with the business.
The role spans impactful domains: infrastructure security (AWS, access control, secrets management, cloud networking), product and platform guardrails (frameworks, libraries, policy engines), and corporate security (endpoint, IAM, SSPM, DLP, incident response). You’ll partner closely with Engineering, Product, IT, and leadership to influence system design, define security architecture, and execute under pressure during critical incidents.
This role is compelling because you will be both a strategist and a builder. You’ll set vision through threat models and roadmaps while writing code, crafting policies-as-code, and shipping automated controls that eliminate systemic risk. Expect to contribute to initiatives like AWS permissions systems, access control frameworks, vulnerability remediation platforms, and data-loss prevention strategies—all with the goal of enabling fast, safe delivery.
