Asana3 дня назад
Manager, Offensive Security
Зарплата не указана
Warsaw
Обязанности
- 01Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations
- 02Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy
- 03Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team
- 04Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment
- 05Perform cloud security assessments evaluating misconfigurations, privilege escalation paths, and lateral movement opportunities
- 06Develop and maintain red team tooling, TTPs, and playbooks aligned with current threat actor behaviors
- 07Oversee security architecture reviews and threat modeling for new features and services, ensuring risks are identified early and secure design decisions are made
- 08Own and operate Asana's bug bounty program and mature our vulnerability management program across software and infrastructure
- 09Implement technical security controls within the SDLC, including PR blockers and automated pipeline gates
- 10Translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for senior leadership and legal
Требования
- 01Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making
- 028+ years of experience in offensive security, application security, or closely related disciplines, with significant hands-on depth in red team operations or web application penetration testing in enterprise environments
- 033+ years of demonstrated experience managing and mentoring a team of offensive or application security engineers, while remaining actively involved in technical execution
- 04Proven track record of leading end-to-end security assessments and operating/maturing a vulnerability management program at scale (including bug bounty ownership)
- 05Deep technical expertise in modern web application security flaws (OWASP Top 10 and beyond) and hands-on experience conducting cloud security assessments
- 06Ability to read and understand source code across multiple languages (Python, Java, JavaScript/TypeScript, Go, C/C++) to identify security weaknesses and advise on secure patterns
- 07Strong understanding of vulnerability taxonomies (CVEs, CWEs, CVSS scoring) and hands-on experience with offensive tooling, red team frameworks, and SAST/DAST/SCA platforms
- 08Exceptional ability to translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for non-technical leadership and legal
Условия
- 01Based in Warsaw office with an office-centric hybrid schedule (standard in-office days: Monday, Tuesday, Thursday; option to work from home on Wednesdays; Friday remote depends on work type)
- 02Contract of Employment (UoP) for employees in Poland
- 03Generous, transparent and fair compensation system (base salary and RSUs)
- 04Option of 50% tax deductible costs for author’s rights usage (where applicable)
- 05Health insurance with dental and travel coverage (Lux Med)
- 06Breakfast and lunch catering on office workdays
- 07Vacation allowance
- 08Career growth budget
- 09Home office setup budget
- 10Gym/Fitness card
- 11Fertility healthcare and family-forming support with Carrot
- 12Mental Health Support in Modern Health
- 13Group life insurance
- 14MacBooks with all necessary accessories
- 15Estimated base salary range: 43,500 - 49,500 PLN gross per month (subject to taxes and deductions)
- 16Potential additional compensation components such as equity and sales incentive pay (for most sales roles) and benefits