Lead Security Response Engineer

San Francisco

Applications have closed

Asana

Work anytime, anywhere with Asana. Keep remote and distributed teams, and your entire organization, focused on their goals, projects, and tasks with Asana.

View company page

Asana is looking for a Lead Security Engineer to join our Security Detection & Response team. This role will lead the technical execution of this team, driving the maturation of our investigative and response capabilities, building cross-functional partnerships and applying automation to create a sustainable investigative environment, while uncovering malicious activity directed at our product and company.

A successful candidate for this role will have experience in establishing and maturing investigations and response efforts. They will also have experience in the discovery, containment and mitigation of threat actors, with a strong history of automating manual processes.

What you’ll achieve

  • Guide the technical development and execution of Asana’s investigation and response capabilities
  • Establish best practices including runbooks, strategies, and prioritization frameworks for response
  • Mature our incident response and investigative capabilities to enable us to protect Asana and our customers
  • Deploy detections, automations, and alerts using modern software engineering practices (i.e. automated testing/validation, CI/CD pipelines, detections as code, etc.)

About you

  • You want to help drive technical direction and execution for a group of engineers focused on investigation and response, as well as work on your own projects
  • You’re passionate about creating environments that foster sustainable work, and desire to build a culture resilient to burnout
  • You thrive in finding signal through the noise
  • You’re always looking to automate anything you’ve done once

Qualifications

  • 3-5 years minimum working in security response with a focus on incident response, threat hunting, or creating detection signatures.
  • Experience leading others in larger projects and initiatives and driving technical execution
  • Strong working knowledge of modern threats and working familiarity with  frameworks like MITRE ATT&CK
  • Experience leading incident response 
  • Experience working with SIEM solutions and tuning detection signatures
  • Ability to script solutions to enable automations, deploy detections, or quickly parse log files. 

 

About us

Asana helps teams orchestrate their work, from small projects to strategic initiatives. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named a Top 10 Best Workplace for 5 years in a row, is Fortune's #1 Best Workplace in the Bay Area, and one of Glassdoor’s and Inc.’s Best Places to Work. After spending more than a year physically distanced, Team Asana is safely and mindfully returning to in-person collaboration, incorporating flexibility that adds hybrid elements to our office-centric culture. With 11+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

 

We believe in supporting people to do their best work and thrive, and building a diverse, equitable, and inclusive company is core to our mission. Our goal is to ensure that Asana upholds an inclusive environment where all people feel that they are equally respected and valued, whether they are applying for an open position or working at the company. We welcome applicants of any educational background, gender identity and expression, sexual orientation, religion, ethnicity, age, citizenship, socioeconomic status, disability, and veteran status.

Tags: Automation CI/CD Incident response Log files MITRE ATT&CK SIEM

Region: North America
Country: United States
Job stats:  6  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.