
Manager, Offensive Security
The Security team is responsible for protecting Asana’s employees, users, and customers. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements. We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations. We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw. In this role, you will own and grow a team spanning red team operations, application security, and vulnerability management, driving both the strategic direction and the hands-on execution of our offensive security program. You will work directly with engineering leadership, legal, and senior stakeholders to ensure our security posture is continuously tested, measured, and improved.
This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland.
What you’ll achieve
-
Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations.
-
Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy.
-
Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team.
-
Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment.
-
Perform cloud security assessments evaluating misconfigurations, privilege escalation paths, and lateral movement opportunities.
-
Develop and maintain red team tooling, TTPs, and playbooks aligned with current threat actor behaviors.
-
Oversee security architecture reviews and threat modeling for new features and services, ensuring risks are identified early and secure design decisions are made.
-
Own and operate Asana's bug bounty program and mature our vulnerability management program across software and infrastructure.
-
Implement technical security controls within the SDLC, including PR blockers and automated pipeline gates.
-
Translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for senior leadership and legal.
About you
-
Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
-
8+ years of experience in offensive security, application security, or closely related disciplines, with significant hands-on depth in red team operations or web application penetration testing in enterprise environments.
-
3+ years of demonstrated experience managing and mentoring a team of offensive or application security engineers, while remaining actively involved in technical execution.
-
Proven track record of leading end-to-end security assessments and operating/maturing a vulnerability management program at scale (including bug bounty ownership).
-
Deep technical expertise in modern web application security flaws (OWASP Top 10 and beyond) and hands-on experience conducting cloud security assessments.
-
Ability to read and understand source code across multiple languages (Python, Java, JavaScript/TypeScript, Go, C/C++) to identify security weaknesses and advise on secure patterns.
-
Strong understanding of vulnerability taxonomies (CVEs, CWEs, CVSS scoring) and hands-on experience with offensive tooling, red team frameworks, and SAST/DAST/SCA platforms.
-
Exceptional ability to translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for non-technical leadership and legal.
At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.
What we’ll offer
-
Generous, transparent and fair compensation system (base salary and RSUs)
-
Contract of Employment (and the option of 50% tax deductible costs for author’s rights usage in respect of applicable roles)
-
Health insurance with dental and travel coverage (Lux Med)
-
Breakfast and lunch catering on the days that you work from the office
-
Vacation allowance
-
Career growth budget
-
Home office setup budget
-
Gym/Fitness card
-
Fertility healthcare and family-forming support with Carrot
-
Mental Health Support in Modern Health
-
Group life insurance
-
MacBooks with all necessary accessories
For this role, the estimated base salary range is between 43,500 - 49,500 PLN gross per month (subject to all taxes and necessary deductions). The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified.
In addition to base salary, your compensation package may include additional components such as equity and sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your recruiter to learn more about the total compensation and benefits for this role.
#LI-Hybrid
About us
Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.
We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law.Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.
Similar roles
Project Engineer
ACCIONA Construcción·New Zealand
ACCIONA is a global company, leading in the development of regenerative infrastructure that creates a positive impact on society. Our workforce consists of more than 65,000 professionals, present in more than 40 countries across the five continents, all contributing in our mission to design a better planet. Are you a passionate individual who wants to make a difference, promote sustainable…
- Contract
- Skilled Migrant (Residence) — PR, points-based, no single employer
Value Engineer
Tacto·Munich, Germany
YOUR IMPACT Procurement is the single biggest cost position for industrial companies, often 60-70% of revenue. Tacto brings AI to strategic procurement so teams can move faster, become more resilient and unlock savings at scale. However, winning a customer takes more than a good platform. It takes a business case that convinces the C-level (primarily CEO and CFO). As our…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
Senior Functional Safety Engineer/Safety Systems Engineer - M/F/D
Navflex·Munich, Germany
Non‑negotiables for this role * 3+ years hands-on programming of SICK safety controllers using SICK Safety Designer (professional, production use). * Electrical Engineering background with strong hands-on commissioning / troubleshooting on real vehicles. * Confident Python programming and ability to read and debug existing Python code (integration of safety system with application logic). ABOUT NAVFLEX Navflex builds autonomous mobile robots…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
Senior Manager, Robotic Platforms Engineering - M/F/D
Navflex·Munich, Germany
About Navflex At Navflex, we're pioneering the future of logistics automation through cutting-edge AI and robotics. Our autonomous mobile robots (AMRs) are transforming the way goods are loaded and unloaded, enabling plug-and-play solutions that streamline operations and enhance efficiency across the global supply chain for some of the world’s most demanding warehouse Environments. Our international, cross‑disciplinary team in the EU…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
IT System Engineer Microsoft Cloud & Infrastructure (m/w/d)
Michael Wessel·Hannover, Germany
IT System Engineer Microsoft Cloud & Infrastructure (m/w/d) Du möchtest Microsoft-Infrastrukturen nicht nur betreiben, sondern planen, modernisieren und weiterentwickeln? Dann verstärke unser Team Modern Workspace & Infrastructure. Wir suchen sowohl erfahrene System Engineers und Consultants als auch technisch starke Nachwuchskräfte, die sich gezielt in die Microsoft-Cloud- und Infrastrukturwelt entwickeln möchten. Entscheidend ist für uns nicht, dass du bereits jedes Produkt…
- On-site
- Full-time
- Blue Card — tied; settle 21–33mo
Senior AI & Solutions Engineer
MaxAccelerate·Dubai, United Arab Emirates
SENIOR AI & SOLUTIONS ENGINEER AI • SALESFORCE • LLMS • INTELLIGENT CRM • FULL-STACK ENGINEERING BUILD THE FUTURE OF AI-POWERED ENTERPRISE SOLUTIONS We are looking for an exceptional Senior AI & Solutions Engineer to join our team and help us push the boundaries of what is possible with AI, Salesforce and next-generation CRM technology. This is not a traditional…
- Remote
- Full-time
- Green Visa — self-sponsored, no tie
Research Engineer
Wehrtyou·United States
<p>Hudson River Trading (HRT) is a quantitative trading firm at the forefront of technological innovation. We build and deploy cutting-edge systems within one of the world’s most advanced computing environments to power our global trading operations. Our non-siloed, collaborative coding environment empowers talented engineers to make significant contributions and see their impact daily. At HRT, you'll be challenged to solve…
- On-site
- Full-time
ML Research Engineer, AI for Life Sciences
SandboxAQ·United Kingdom
ABOUT SANDBOXAQ SandboxAQ is a high-growth company delivering AI solutions that address some of the world's greatest challenges. The company’s Large Quantitative Models (LQMs) power advances in life sciences, financial services, navigation, cybersecurity, and other sectors. We are a global team that is tech-focused and includes experts in AI, chemistry, cybersecurity, physics, mathematics, medicine, engineering, and other specialties. The company…
- On-site
- Full-time