Senior Security Engineer, Threat Response
31k - 36.3k PLN31 000 - 36 250 PLN/ mies.UoP
SeniorFull-time·Umowa o pracę
#452766·Dodano wczoraj·0
Źródło: nofluffjobs.comTech Stack / Keywords
SecurityCloud platformSaaSAuditPythonREST APIGitnpmCI/CDSIEMSplunkEndpoint Detection and ResponsemacOSCommunication skillsAIJavaScriptTypeScriptBashGo
Firma i stanowisko
Asana's Security team proactively addresses threats and fosters a culture of security throughout their product and operations. This role is based in Asana's Warsaw office as a foundational member of their Blue Team, partnering with IT, infrastructure, and product teams to ensure robust detection and response capabilities. The team invests in automation and detection-as-code to reduce manual triage.
Wymagania
- 7+ years of experience in threat detection, security operations, or incident response.
- Experience investigating incidents across cloud platforms, identity providers, and SaaS applications.
- Practical knowledge of audit logging and IAM.
- Proficient in Python for security scripting and automation; Bash, Go, or JavaScript/TypeScript are a plus.
- Hands-on experience with REST APIs, Git workflows, and PR-based code reviews.
- Experience investigating software supply chain threats and auditing developer ecosystems (e.g., npm, PyPI), build logs, and CI/CD pipelines.
- Familiarity with "Detection as Code" methodologies including test-driven detection logic and rule management through CI/CD pipelines.
- Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security) for log analysis, alert correlation, and dashboard creation.
- Deep knowledge of endpoint detection and response (EDR) tools (e.g., CrowdStrike, SentinelOne) with expertise in macOS endpoint security, telemetry, and threat detection.
- Experience in digital forensics and root-cause analysis.
- Familiarity with common attack techniques, tactics, and procedures (TTPs) and frameworks like MITRE ATT&CK.
- Strong communication skills across technical and non-technical partners.
- Demonstrated curiosity about AI tools and emerging technologies with willingness to learn and leverage them.
Obowiązki
- Lead detection, analysis, and response across cloud and SaaS environments, identity providers, endpoints, and the software supply chain.
- Investigate and remediate security incidents across cloud infrastructure (e.g., AWS, GCP, Azure), identity providers (e.g., Okta), and SaaS environments.
- Investigate and contain software supply chain and CI/CD incidents involving build environments and third-party dependencies (e.g., npm, PyPI).
- Build and maintain detection-as-code infrastructure (e.g., Panther), SOAR automation, and response playbooks treating detection logic as tested, version-controlled production code.
- Utilize and optimize security tools such as Panther for SIEM, CrowdStrike for endpoint detection and response, and other security platforms.
- Conduct proactive threat hunting and operationalize threat intelligence using cloud, endpoint, and identity telemetry.
- Conduct forensic analysis during security incidents to determine scope and impact.
- Collaborate with engineering teams to integrate security best practices and provide guidance on secure configurations.
- Develop and deliver training on security operations and incident response best practices.
Benefity
- Generous, transparent, and fair compensation system including base salary and RSUs.
- Contract of Employment (UoP) with option of 50% tax deductible costs for author's rights usage.
- Health insurance with dental and travel coverage (Lux Med).
- Breakfast and lunch catering on office days.
- Vacation allowance.
- Career growth budget.
- Home office setup budget.
- Gym/fitness card.
- Fertility healthcare and family-forming support with Carrot.
- Mental health support through Modern Health.
- Group life insurance.
- MacBooks with necessary accessories.
- Private healthcare.
- Mental health care.
- Sport subscription.
- Training budget.
- Coaching.
- Long-term savings or retirement plans.
- Free coffee and beverages.
- Canteen and in-office culinary options.
- Free lunch and snacks.
- Shower and bike parking.
- Modern office with no dress code.
- In-house trainings and hack days.
- Startup atmosphere.
Opieka zdrowotna
Karta sportowa
Dofinansowanie szkoleń
Szkolenia wewnętrzne
Premie
Płatny urlop
Firmowa stołówka
Napoje w biurze
Darmowe przekąski
Prysznic
Parking dla rowerów
Inne informacje
This role is office-centric hybrid based in Warsaw, with standard in-office days Monday, Tuesday, and Thursday; most employees may work from home on Wednesdays, and Friday work-from-home depends on the type of work.
Asana
33 aktywne oferty