Asana
Asana
New

Security Risk and Compliance Lead

22.8k - 27.3k PLN/ mies.UoP
MidFull-time·Umowa o pracę
#398195·Dodano wczoraj·1
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

risk managementSecurityNISTISOAuditCloudSaaSCommunication skillsAI

Firma i stanowisko

Asana is a company focused on security as foundational to its mission of helping teams work together effortlessly. The security team consists of security engineers and risk and compliance practitioners who build safeguards and collaborate to maintain trust at scale. This role is based in the Warsaw office with a hybrid schedule and involves managing the Third Party Risk Management program.

Wymagania

  • 5+ years of experience in third-party risk management, vendor risk assessment, or related information security discipline.
  • Strong knowledge of TPRM frameworks and standards including SIG, CAIQ, NIST SP 800-161, ISO 27001, SOC 2.
  • Experience conducting vendor security assessments and reviewing audit reports, certifications, and penetration test summaries.
  • Solid understanding of core security principles, cloud environments, data privacy, and compliance standards relevant to B2B SaaS.
  • Proven ability to build and operationalize scalable risk management processes and develop effectiveness metrics.
  • Excellent communication skills to translate technical risk findings for technical and non-technical audiences.
  • Experience collaborating cross-functionally with Procurement, Legal, Privacy, and Engineering teams.
  • Curiosity about AI tools and emerging technologies, willingness to learn and leverage them to enhance productivity and decision-making.

Obowiązki

  • Own and scale Asana’s TPRM program: design, implement, and continuously improve a risk-based framework for third-party vendors.
  • Lead vendor security assessments, including reviewing SOC 2 reports, ISO 27001 certifications, and security questionnaires (SIG, CAIQ).
  • Identify gaps and work with vendors to remediate findings.
  • Track and manage open findings, facilitate remediation prioritization and formal risk acceptance.
  • Develop and execute continuous monitoring for critical and high-risk vendors, maintain risk inventories.
  • Review security provisions in vendor contracts with Legal and Privacy teams.
  • Report on TPRM program health with metrics and support audit and compliance activities.
  • Operate globally with coordination across timezones to support vendor assessments and risk decisions.

Benefity

  • Generous compensation system paying between 22,750 and 27,250 PLN gross per month.
  • Contract of Employment with 50% tax deductible costs option for author’s rights usage for applicable roles.
  • Health insurance with dental and travel coverage (Lux Med).
  • Meals reimbursement on office work days.
  • Career growth budget and home office setup budget.
  • Gym/Fitness reimbursement.
  • Fertility healthcare and family-forming support with Carrot.
  • Mental Health Support via Modern Health.
  • Group life insurance.
  • MacBooks with necessary accessories.
  • Private healthcare, mental health care, sport subscription, training budget, coaching.
  • Long-term savings or retirement plans.
  • Free coffee, canteen, modern office, no dress code.
  • In-house trainings, in-office culinary options, free lunch, free snacks.
  • Shower, bike parking, free beverages, free breakfast.
  • Startup atmosphere, in-house hack days.
Opieka zdrowotna
Karta sportowa
Dofinansowanie szkoleń
Szkolenia wewnętrzne
Płatny urlop
Premie
Firmowa stołówka
Napoje w biurze
Darmowe przekąski
Prysznic
Parking dla rowerów

Inne informacje

Employees in Poland are employed under a contract of employment. The role requires working from the Warsaw office on Monday, Tuesday, and Thursday, with hybrid work options on Wednesday and possibly Friday depending on role specifics.

Asana

Asana

63 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz