Senior Software Engineer, Security Development
About the role
This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner.
Responsibilities
- Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities.
- Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems.
- Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently.
- Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure.
- Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents).
- Influence engineering initiatives through design reviews, communicating security principles, and helping teams make sound security trade-offs.
Requirements
- 4+ years of experience in full-time professional software development, working with large codebases.
- Proven software engineering experience, with a background in building platforms, libraries, or core infrastructure.
- Strong interest or direct experience in security engineering, with a focus on building preventative controls.
- Expertise in programming and computer science fundamentals.
- Experience with cloud infrastructure and services, particularly AWS.
- Excellent communication skills for collaborating effectively with engineering teams across the organization.
- A proactive mindset geared towards identifying and eliminating systemic risks, not just individual bugs.
- Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
Qualifications
- Master's degree in Computer Science, Engineering, or related field.
- Experience with security-related certifications such as CISSP, CISM, or equivalent.
- Experience with security research and threat modeling.
- Experience with security testing and penetration testing tools.
Skills
- Strong understanding of security principles and practices.
- Experience with security architecture and design.
- Experience with security compliance and regulatory requirements.
- Experience with security incident response and forensics.
Benefits
- Mental health, wellness & fitness benefits.
- Career coaching & support.
- Inclusive family building benefits.
- Long-term savings or retirement plans.
- In-office culinary options to cater to your dietary preferences.
Pay
The estimated base salary range for this role is between $202,000 - $230,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process.
Schedule
The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner.