Director of Security Engineering
Asana
- Location
- San Francisco
- Work model
- On-Site
- Level
- Staff
- Salary
- $306k – $360k/yr
- H-1B history
- 32 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
At Asana, security is foundational to our mission of helping teams work together effortlessly. Our Security organization protects Asana’s employees, users, and customers by proactively addressing threats, enabling secure product development, and embedding security into the fabric of how we operate. We partner closely with Engineering, Product, IT, Legal, and Compliance to build and maintain trust at scale.
We are seeking a Director of Security Engineering to lead and grow our Security Engineering organization as Asana continues to grow globally. This role is pivotal in translating high-level security strategy into technical reality, ensuring our infrastructure is resilient by design and our internal security tooling is world-class.
This is a leadership role with accountability for people management, technical mentorship, and the delivery of high-impact security initiatives across a complex, high-growth SaaS environment.
This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.
What you’ll achieve
• Build security by construction, design and default throughout all of Asana’s products and infrastructure.
• Accelerate the development lifecycle by building and owning frameworks, interfaces, services and libraries that solves security problems and frees other Asanas to focus.
• Be the voice of the customer in driving security features in our products and making those product features a differentiator for Asana.
• Lead and mentor a multi-disciplinary engineering team, fostering a culture of technical excellence, psychological safety, and high accountability.
• Own the security engineering roadmap, ensuring high-quality and high-velocity delivery and measurable risk reduction through effective prioritization and data-driven operations.
• Drive recruiting efforts to attract top-tier talent and establish clear, ambitious career paths for your team.
• Collaborate with Product and Engineering teams to embed security requirements directly into system designs and development workflows.
• Oversee complex design reviews, providing pragmatic guidance to ensure Asana’s infrastructure and features are inherently secure.
About you
• 10+ years of experience in a combination of security and software engineering, including 3+ years of experience directly managing high-performing engineering teams.
• A strong background in software engineering with the ability to participate in deep-dive design reviews and provide technical direction on architecture and code.
• Deep understanding of modern security domains, including application security (OWASP), cloud-native architecture, and identity frameworks (OAuth, OIDC, SAML).
• Hands-on experience with security controls and architecture within AWS or similar cloud environments at scale.
• You excel at balancing security requirements with business needs, making risk-informed decisions, and communicating the "why" behind security mandates to diverse stakeholders.
• You value automation over manual intervention and have a proven track record of shipping internal tools or services that improve security posture.
• You use AI tools fluently, champion their adoption across your team, and understand the security risks they introduce in a product environment.
At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this