Jobs · Information Technology · California

Security Risk Manager

Asana · San Francisco, CA · 4 days ago
HybridInformation Technology$194k–$220k/yrFull-time

About the role

Own Asana's security risk management program: Design and continuously mature a quantitative risk framework — including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds — that enables consistent, data-driven risk decisions across the organization.

Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.

Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's risk posture is always current and not dependent on manual review cycles.

Deliver quantitative risk reporting: Develop executive-level dashboards that communicate security risk in business terms — probability, potential impact, cost of control vs. cost of breach, and residual risk exposure — to inform investment and prioritization decisions.

Partner cross-functionally on risk: Act as the primary security risk partner to Legal, Privacy, Finance, and Engineering. Influence security investment decisions and build a culture of risk awareness across the company.

Responsibilities

  • Own Asana's security risk management program: Design and continuously mature a quantitative risk framework — including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds — that enables consistent, data-driven risk decisions across the organization.
  • Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.
  • Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's risk posture is always current and not dependent on manual review cycles.
  • Deliver quantitative risk reporting: Develop executive-level dashboards that communicate security risk in business terms — probability, potential impact, cost of control vs. cost of breach, and residual risk exposure — to inform investment and prioritization decisions.
  • Partner cross-functionally on risk: Act as the primary security risk partner to Legal, Privacy, Finance, and Engineering. Influence security investment decisions and build a culture of risk awareness across the company.

Requirements

  • 7+ years of experience in information security with a strong focus on security risk management and GRC.
  • Demonstrated experience building or leading a security risk management program — not just contributing to one.
  • Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis. You back up risk ratings with numbers, not just color codes.
  • Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring — you've built things, not just directed others to build them.
  • Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
  • Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making.
  • Strong understanding of cloud environments and SaaS architecture — enough to have credible risk conversations with technical teams.
  • Excellent communicator who can translate technical risk findings for both engineering teams and C-suite stakeholders.
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity and decision-making.

Qualifications

  • Master's degree in Computer Science, Information Systems, or related field.
  • CISSP, CISM, or equivalent certification preferred.

Skills

  • Quantitative risk analysis and modeling
  • Data pipeline and automation development
  • Cloud security and SaaS architecture expertise
  • Effective communication and stakeholder engagement
  • Curiosity and adaptability towards new technologies

Benefits

What We'll Offer For this role, the estimated base salary range is between $194,000–$220,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. In addition to base salary, your compensation package may include equity and benefits.

Pay

The estimated base salary range for this role is between $194,000–$220,000.

Schedule

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner.

Similar jobs

Security Manager

Metropolis TechnologiesSan Francisco, CA· 1 wk ago
Information Technology$110k–$129k/yrapply on externalsp-spplus.icims.com

Security Manager

Detroit Manufacturing Systems (DMS)Auburn Hills, MI· 1 wk ago
Information Technologyapply on jobs.dayforcehcm.com

Security Manager

First Electronic BankSalt Lake City, UT· 1 wk ago
apply on recruiting.paylocity.com

Security Manager

Great Wolf LodgePerryville, MD· 2 wk ago
Information Technology$60k/yrapply on jobs.greatwolfresorts.com

Security Manager

Mercy Medical Center, Baltimore, MDTimonium, MD· 2 wk ago
Information Technologyapply on mdmercy.jibeapply.com

Security Manager

Upstate Coin & GoldWest Jordan, UT· 2 wk ago
Managementapply on paycomonline.net