Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Architecture Engineer (AI): Designing and scaling architectural security defenses for Asana's security operations with an accent on threat modelling, defensive engineering, and AI security governance. Focus on building security pattern libraries, conducting deep code and data flow analysis, and implementing industry-standard compliance frameworks.
Location: Hybrid (Warsaw, Poland). Standard in-office days are Monday, Tuesday, and Thursday.
Salary: 31,900 - 36,000 PLN gross per month
Company
Asana is a leading platform for human + AI collaboration used by millions of teams worldwide to achieve their goals faster.
What you will do
- Lead architecture reviews and structured threat modelling (STRIDE, MITRE ATT&CK) to identify risks early in the project lifecycle.
- Analyze data flows and conduct security-focused code reviews across services and APIs to reduce attack surfaces.
- Develop and maintain a reusable security pattern library for authentication, authorization, encryption, and data handling.
- Evaluate AI tooling and integrations for risks such as prompt injection, model misuse, and data leakage using OWASP standards.
- Define and mature security architecture standards aligned with NIST 800-53, FedRAMP, ISO 27001, and OWASP ASVS.
- Deliver technical training and workshops to engineering and product teams to foster a security-by-design culture.
Requirements
- 7+ years of experience in security roles, focusing on security architecture, appsec, or high-scale design reviews.
- Proficiency with threat modelling methodologies (STRIDE/PASTA) and the MITRE ATT&CK framework.
- Ability to conduct security code reviews in languages such as Python, Go, Java, or TypeScript.
- Deep knowledge of compliance frameworks: NIST 800-53, FedRAMP, ISO 27001, and OWASP ASVS.
- Strong understanding of OAuth 2.0, OIDC, SAML, and Kubernetes security (RBAC, network policies, secrets management).
- Must be based in or be able to work from the Warsaw office on a hybrid schedule.
Nice to have
- Familiarity with OWASP Top 10 for LLMs and OWASP Maestro.
- Experience securing multi-tenant SaaS platforms.
Culture & Benefits
- Transparent compensation including base salary and RSUs.
- Comprehensive health insurance with dental and travel coverage (Lux Med).
- Breakfast and lunch catering provided on office days.
- Dedicated budgets for career growth and home office setup.
- Fitness card, mental health support (Modern Health), and family-forming support (Carrot).
- MacBooks and all necessary accessories provided.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →