<p> </p> <p>Our Security team keeps Asana's employees, users, and customers safe, by proactively addressing threats and fostering a culture of security throughout our product and operations. </p> <p>We are looking for a savvy Security Engineer to join our Blue Team in Warsaw. You will be a foundational member of the security presence in our Warsaw innovation hub, partnering directly with IT, infrastructure, and product teams to ensure we have robust detection and response capabilities. <strong>Detection and response here leans on engineering practice. We are investing in automation and detection-as-code to cut down on manual triage, and we are looking for someone comfortable writing and reviewing code as part of that work.</strong></p> <p> </p> <p>This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements.</p> <p>We offer a Contract of Employment (UoP) for our employees in Poland.</p> <h3><strong>What you'll achieve:</strong></h3> <ul> <li><strong>Lead detection, analysis, and response across our cloud and SaaS environments, identity providers, endpoints, and the software supply chain</strong>, ensuring timely and effective remediation of security incidents.</li> <li><strong>Investigate and remediate security incidents across cloud infrastructure</strong> (AWS/GCP/Azure), identity providers (e.g., Okta), and SaaS environments.</li> <li><strong>Investigate and contain software supply chain and CI/CD incidents</strong>, from unauthorized changes in build environments to suspect third-party dependencies (e.g., npm, PyPI).</li> <li><strong>Help build and maintain our detection-as-code infrastructure</strong> (e.g., Panther), SOAR automation, and response playbooks, treating detection logic as tested, version-controlled production code.</li> <li><strong>Utilize and optimize security tools</strong> such as Panther for SIEM, CrowdStrike for endpoint detection and response, and other security platforms.</li> <li><strong>Conduct proactive threat hunting and operationalize threat intelligence</strong> across cloud, endpoint, and identity telemetry to catch threats beyond standard SIEM alerting.</li> <li><strong>Conduct forensic analysis</strong> during security incidents to understand the scope and impact of incidents.</li> <li><strong>Collaborate with engineering teams</strong> to integrate security best practices into development processes and p
asana
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated today.
Apply Now