Product Security Engineer
Job Description
At Asana, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.
We're looking for a Product Security Engineer to join our Product Security team in Vancouver. You'll be a key member of our security engineering team, partnering directly with product and infrastructure teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by building secure-by-default frameworks, eliminating entire classes of vulnerabilities, and championing a security-first mindset across our web, mobile, and AI-powered product surfaces.
This role is based in our Vancouver office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements.
What you'll achieve
• Partner with product and engineering teams across the full software development lifecycle to ensure security is designed and built into Asana's products and platform.
• Conduct security architecture reviews, threat modeling, and code reviews for new features and services.
• Develop, implement, and maintain secure-by-default frameworks and libraries that empower engineering teams to build secure systems easily.
• Build and maintain automated security tooling (static and dynamic analysis rules, custom SAST/DAST checks, and automated red-teaming) to scale security coverage without scaling headcount.
• Identify and address AI-specific security risks such as prompt injection, insecure tool permissions, and abuse-resistant design in Asana's AI and agentic features.
• Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program, internal testing, and automated security tooling.
• Influence engineering initiatives by conducting design and roadmap reviews, effectively communicating security constraints, and assisting teams in making informed trade-offs.
• Investigate product security incidents as a subject matter expert, using logs and monitoring tools to contain, analyze, and drive resolution.
• Evaluate and improve software supply chain security, including dependency management, SCA tooling, and third-party risk in the development pipeline.
• Develop and deliver training to educate engineers on secure coding best practices and emerging threats.
• Stay informed of industry trends, emerging threats, and best practices to ensure that Asana's security posture remains robust.
• Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management.
About you
• Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making
• 5+ years of experience in application security, product security, or software engineering with a security focus.
• Strong software engineering background with experience in languages like Python, Javascript/Typescript or Scala.
• Deep working knowledge of the OWASP Top 10 and common web application vulnerabilities such as XSS, CSRF, SSRF, and SQL injection.
• Familiarity with AI/ML security concepts, including LLM-specific risks such as prompt injection and agentic attack surfaces.
• Experience with security tools for static/dynamic analysis (SAST/DAST), software composition analysis (SCA), and vulnerability management.
• Experience performing security design reviews and threat modeling for complex applications.
• Excellent communication skills for collaborating effectively with both technical and non-technical partners.
• A pragmatic and collaborative mindset, with a passion for building defenses against real-world attacks and enabling other engineers to do their best, most secure work.
At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.
What we'll offer
Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.
For this role, the estimated base salary range is between 176,000 - 200,000 CAD. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified.
In addition to base salary, your compensation package may include additional components such as equity, sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your recruiter to learn more about the total compensation and benefits for this role.
We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:
• Mental health, wellness & fitness benefits
• Career coaching & support
• Inclusive family building benefits
• Long-term savings or retirement plans
• In-office culinary options to cater to your dietary preferences
These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your recruiter to learn more about the total compensation and benefits for this role.
#LI-Hybrid
About us
Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.
We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law.
Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.
Requirements
Department: Security Engineering