Manager, Offensive Security
Asana
| Company | Asana |
| Category | Security |
| Location | Warsaw |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Manager |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
The Security team is responsible for protecting Asana’s employees, users, and customers . We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements . We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations . We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw . In this role, you will own and grow a team spanning red team operations, application security, and vulnerability management, driving both the strategic direction and the hands-on execution of our offensive security program . You will work directly with engineering leadership, legal, and senior stakeholders to ensure our security posture is contin uously tested, measured, and improved .
This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland.
What you’ll achieve
Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations .
Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy .
Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team .
Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment .
Perform cloud security assessments evaluating misconfigurations, privilege escalation paths, and lateral movement opportunities .
Develop and maintain red team tooling, TTPs, and playbooks aligned with current threat actor behaviors .
Oversee security architecture reviews and threat modeling for new features and services, ensuring risks are identified early and secure design decisions are made .
Own and operate Asana's bug bounty program and mature our vulnerability management program across software and infrastructure .
Implement technical security controls within the SDLC, including PR blockers and automated pipeline gates .
Translate complex technical vulnerabilities into executive-level risk reports and actionable business insights for senior leadership and legal .
About you
Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making .
8+ years of experience in offensive security, application security, or closely related disciplines, with significant hands-on depth in red team operations or web application penetration testing in enterprise environments .
3+ years of demonstrated experience managing and mentoring a team of offensive or application security engineers, while remaining actively involved in technical execution .
Proven track record of leading end-to-end security assessments and operating/maturing a vulnerability management program at scale (including bug bounty ownership) .
Deep technical expertise in modern web application security flaws (OWASP Top 10 and beyond) and hands-on experience conducting cloud security assessments .
Ability to read and understand source code across multiple languages (Python, Java, JavaScript/TypeScript, Go, C/C++) to identify security weaknesses and advise
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →