Asana3 дня назад

Manager, Offensive Security

Зарплата не указана
Warsaw

Обязанности

  • 01Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations
  • 02Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy
  • 03Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team
  • 04Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment
  • 05Perform cloud security assessments evaluating misconfigurations, privilege escalation paths, and lateral movement opportunities
  • 06Develop and maintain red team tooling, TTPs, and playbooks aligned with current threat actor behaviors
  • 07Oversee security architecture reviews and threat modeling for new features and services, ensuring risks are identified early and secure design decisions are made
  • 08Own and operate Asana's bug bounty program and mature our vulnerability management program across software and infrastructure
  • 09Implement technical security controls within the SDLC, including PR blockers and automated pipeline gates
  • 10Translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for senior leadership and legal

Требования

  • 01Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making
  • 028+ years of experience in offensive security, application security, or closely related disciplines, with significant hands-on depth in red team operations or web application penetration testing in enterprise environments
  • 033+ years of demonstrated experience managing and mentoring a team of offensive or application security engineers, while remaining actively involved in technical execution
  • 04Proven track record of leading end-to-end security assessments and operating/maturing a vulnerability management program at scale (including bug bounty ownership)
  • 05Deep technical expertise in modern web application security flaws (OWASP Top 10 and beyond) and hands-on experience conducting cloud security assessments
  • 06Ability to read and understand source code across multiple languages (Python, Java, JavaScript/TypeScript, Go, C/C++) to identify security weaknesses and advise on secure patterns
  • 07Strong understanding of vulnerability taxonomies (CVEs, CWEs, CVSS scoring) and hands-on experience with offensive tooling, red team frameworks, and SAST/DAST/SCA platforms
  • 08Exceptional ability to translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for non-technical leadership and legal

Условия

  • 01Based in Warsaw office with an office-centric hybrid schedule (standard in-office days: Monday, Tuesday, Thursday; option to work from home on Wednesdays; Friday remote depends on work type)
  • 02Contract of Employment (UoP) for employees in Poland
  • 03Generous, transparent and fair compensation system (base salary and RSUs)
  • 04Option of 50% tax deductible costs for author’s rights usage (where applicable)
  • 05Health insurance with dental and travel coverage (Lux Med)
  • 06Breakfast and lunch catering on office workdays
  • 07Vacation allowance
  • 08Career growth budget
  • 09Home office setup budget
  • 10Gym/Fitness card
  • 11Fertility healthcare and family-forming support with Carrot
  • 12Mental Health Support in Modern Health
  • 13Group life insurance
  • 14MacBooks with all necessary accessories
  • 15Estimated base salary range: 43,500 - 49,500 PLN gross per month (subject to taxes and deductions)
  • 16Potential additional compensation components such as equity and sales incentive pay (for most sales roles) and benefits