The opportunity
At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations.
What you'll do
Own Asana's security risk management program: Design and continuously mature a quantitative risk framework — including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds — that enables consistent, data-driven risk decisions across the organization.
Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.
Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's risk posture is always current and not dependent on manual review cycles.
Deliver quantitative risk reporting: Develop executive-level dashboards that communicate security risk in business terms — probability, potential impact, cost of control vs. cost of breach, and residual risk exposure — to inform investment and prioritization decisions.
Partner cross-functionally on risk: Act as the primary security risk partner to Legal, Privacy, Finance, and Engineering. Influence security investment decisions and build a culture of risk awareness across the company.
+ years of experience in information security with a strong focus on security risk management and GRC.
What they're looking for
- Demonstrated experience building or leading a security risk management program — not just contributing to one.
- Hands-on experience with quantitative risk methodologies such as FAIR, risk: scoring models, or statistical risk analysis. You back up risk ratings with numbers, not just color codes.
- Hands-on experience scripting or building automation to integrate security: tooling, build data pipelines, or automate risk monitoring — you've built things, not just directed others to build them.Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
- Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making.