- Location
- Vancouver, BC
- Level
- Senior
- Posted
- Today
About this role
Our Security team keeps Asana's employees, users, and customers safe, by proactively addressing threats and fostering a culture of security throughout our product and operations.
We are looking for a savvy Security Engineer to join our Blue Team. You will be a foundational member of the security presence in our Warsaw innovation hub, partnering directly with IT, infrastructure, and product teams to ensure we have robust detection and response capabilities. Detection and response here leans on engineering practice. We are investing in automation and detection-as-code to cut down on manual triage, and we are looking for someone comfortable writing and reviewing code as part of that work.
This role is based in our Vancouver office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.
What you'll achieve:
- Lead detection, analysis, and response across our cloud and SaaS environments, identity providers, endpoints, and the software supply chain, ensuring timely and effective remediation of security incidents.
- Investigate and remediate security incidents across cloud infrastructure (AWS/GCP/Azure), identity providers (e.g., Okta), and SaaS environments.
- Investigate and contain software supply chain and CI/CD incidents, from unauthorized changes in build environments to suspect third-party dependencies (e.g., npm, PyPI).
- Help build and maintain our detection-as-code infrastructure (e.g., Panther), SOAR automation, and response playbooks, treating detection logic as tested, version-controlled production code.
- Utilize and optimize security tools such as Panther for SIEM, CrowdStrike for endpoint detection and response, and other security platforms.
- Conduct proactive threat hunting and operationalize threat intelligence across cloud, endpoint, and identity telemetry to catch threats beyond standard SIEM alerting.
- Conduct forensic analysis during security incidents to understand the scope and impact of incidents.
- Collaborate with engineering teams to integrate security best practices into development processes and provide guidance on secure configurations.
- Develop and deliver training to educate engineers on security operations and incident response best practices.
About you:
- 8+ years of experience in threat detection, security operations, or incident response, including investigating incidents across cloud platforms, identity providers, and SaaS applications, with practical knowledge of audit logging and IAM.
- Proficient in Python (Bash, Go, or JavaScript/TypeScript is a plus) for security scripting and automation, with hands-on experience across REST APIs, Git workflows, and PR-based code reviews.
- Hands-on experience investigating software supply chain threats, with fluency in auditing modern developer ecosystems (e.g., npm, PyPI), build logs, and CI/CD pipelines.
- Familiarity with "Detection as Code" methodologies, including test-driven detection logic and rule management through CI/CD pipelines.
- Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security) for log analysis, alert correlation, and dashboard creation.
- Deep working knowledge of endpoint detection and response (EDR) tools (e.g., CrowdStrike, SentinelOne) with specialized expertise in macOS endpoint security, telemetry, and threat detection capabilities.
- Experience performing digital forensics and root-cause analysis to determine incident scope and impact.
- Familiarity with common attack techniques, tactics, and procedures (TTPs) and frameworks like MITRE ATT&CK.
- Collaborative and pragmatic, with strong communication skills across technical and non-technical partners, committed to building robust defenses and helping engineers do their best, most secure work.
- Demonstrated curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
What we offer:
Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.
For this role, the estimated base salary range is between CAD $200,000-$240,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified.
In addition to base salary, your compensation package may include additional components such as equity, sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.
We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:
- Mental health, wellness & fitness benefits
- Career coaching & support
- Inclusive family building benefits
- Long-term savings or retirement plans
- In-office culinary options to cater to your dietary preferences
These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
#LI-Hybrid
About us
Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.
We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law.
Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.
As published by Asana. Applications are handled on their site.
One click, then it is written
Apply to Asana with a resume written for this role.
Queue Senior Security Engineer, Threat Response and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Asana’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Asana
See all- Today
- Today
- Today
- Today
- Today
AI GTM Specialist
San Francisco
- Today
Similar roles elsewhere
See more- Yesterday
Senior Software Programmer, Audio Engine
Epic GamesVancouver, British Columbia
CA$227k - CA$332k/yrSeniorEngineering - Yesterday
Principal Research Programmer, Unreal Assistant
Epic GamesVancouver, British Columbia
CA$274k - CA$402k/yrPrincipalEngineering - Yesterday
Senior Programmer, AI and Creation Tools
Epic GamesVancouver, British Columbia
CA$166k - CA$244k/yrSeniorEngineering - Yesterday
Senior Tools Programmer, UI & AI Workflows
Epic GamesVancouver, British Columbia
CA$183k - CA$268k/yrSeniorEngineering - 2 days ago
Senior Security Operations Engineer I
SamsaraRemote - VancouverRemote
CA$133k - CA$172k/yrSeniorEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Asana publishes. Refolk is not the employer and does not handle their hiring. Applications go to Asana directly.