Security Risk ManagerActive$194K–$220K

Hybrid · San FranciscoBusiness

The opportunity

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations.

What they're looking for

  • Demonstrated experience building or leading a security risk management program — not just contributing to one.
  • Hands-on experience with quantitative risk methodologies such as FAIR, risk: scoring models, or statistical risk analysis. You back up risk ratings with numbers, not just color codes.
  • Hands-on experience scripting or building automation to integrate security: tooling, build data pipelines, or automate risk monitoring — you've built things, not just directed others to build them.Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
  • Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making.
Security Risk Manager at Asana | Role Match