Security Engineer, Threat Response
$202k - $230kAsana
At Asana, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.
We are looking for a Security Engineer, Threat Response to join our Security blue team in New York City. You'll be a foundational member of the security presence in a key hub, partnering directly with IT, infrastructure, and product teams to ensure we have robust detection, response, and vulnerability management capabilities. You will be instrumental in scaling our security practices by building effective monitoring, automating repetitive security operations tasks, and championing a security-first mindset. This role sits within the Security Threat Operations and Response Management (STORM) group, responsible for the security of Asana the company and the security of the product - ensuring we maintain customer trust and are able to grow sustainably. You will collaborate with teams across the company including Infrastructure, Customer Success, Legal, IT, and other key stakeholders to drive better incident response outcomes. This role is based in our New York City or San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements. What you'll achieve- Lead security incident detection, analysis, and response efforts, ensuring timely and effective remediation of security incidents.
- Actively participate in and lead the on-call rotation, setting the standard for security incident management across the team.
- Manage and mature our vulnerability management program, including scanning, assessment, prioritization, and tracking remediation efforts.
- Utilize and optimize security tools such as Panther for SIEM, CrowdStrike for endpoint detection and response, and other security platforms.
- Develop, implement, and maintain security playbooks and automation scripts to streamline security operations and reduce manual toil.
- Monitor security alerts and threat intelligence feeds, proactively identifying and addressing emerging threats.
- Conduct forensic analysis during security incidents to understand the scope and impact of incidents.
- Lead retrospectives to help raise engineering excellence and embed a continuous improvement culture across the team.
- Drive incident management and incident response best practices across the company, mentoring fellow engineers through pairing, process definition, and training exercises.
- Participate in and help lead tabletop exercises to ensure different stakeholders are thinking about and preparing for incidents across the company.
- Collaborate with engineering teams to integrate security best practices into development processes and provide guidance on secure configurations.
- Stay informed of industry trends, emerging threats, and best practices in security operations, detection, and response to ensure Asana's security posture remains robust.
- Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management.
- 5+ years of experience in security operations, incident response, threat detection, or vulnerability management.
- Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security) for log analysis, alert correlation, and dashboard creation.
- Deep working knowledge of endpoint detection and response (EDR) tools (e.g., CrowdStrike, SentinelOne) and their capabilities.
- Proven experience in developing and implementing security automation using scripting languages (e.g., Python, PowerShell) or orchestration tools.
- Experience performing security incident investigations and forensic analysis.
- Familiarity with common attack techniques, tactics, and procedures (TTPs) and frameworks like MITRE ATT&CK.
- Hands-on technical expertise in at least two of the following areas: Cloud Security, Detection & Response, Digital Forensics, Network Security, Abuse, or Fraud.
- Experience working in environments composed primarily of SaaS and cloud resources.
- Track record of successfully leading incident response projects and mentoring engineers on security operations.
- Experience making technical trade-offs and articulating them clearly to stakeholders at different levels, both internal and external.
- Excellent communication skills, able to explain complex technical concepts clearly to both technical and non-technical partners.
- Customer-obsessed mindset with a drive to deliver the best possible experience and outcomes for Asana's customers and users.
- A pragmatic and collaborative mindset, with a passion for building robust defences and enabling other engineers to do their best, most secure work.
- Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
- Hands-on experience with logging and monitoring tools such as Datadog, Splunk, and Panther.
- Hands-on experience with AWS, Google Workspace, and common SaaS applications.
- Experience with macOS endpoint security, including investigation workflows and EDR capabilities on Apple platforms.
- Experience with bug bounty programs.
- Experience with red team/blue team or purple team exercises.
- Mental health, wellness & fitness benefits
- Career coaching & support
- Inclusive family building benefits
- Long-term savings or retirement plans
- In-office culinary options to cater to your dietary preferences
These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role. About us Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong. Join Asana's Talent Network to stay up to date on job opportunities and life at Asana.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer, Threat Response in New York, NY vacancy
- ...leading data streaming company in the United States is seeking an experienced security engineer to join their infrastructure security engineering team. This role focuses on threat detection and response, collaborating with engineering teams to enhance security across...Suggested
- ...Senior Security Engineer II – Threat Detection & Response Client is seeking a Senior Security Engineer- Detection & Response (Threat-Informed Defense) to join our Security Engineering team. You will act as the technical SME for threat Intelligence, detection and response...SuggestedImmediate start
- ...A leading cybersecurity firm is seeking a Security Engineer to enhance corporate security for its clients. You will lead projects involving threat detection, incident response, and cloud security. This role requires 3-5 years of experience in security engineering, focusing...SuggestedRemote work
$230k - $385k
...About the Team Security is at the foundation of OpenAI's mission... ...About the Role As a Security Engineer you will join our OpenAI... ...on all aspects of Detection & Response but with a strong emphasis on detecting insider threats and influencing controls to safeguard...Suggested$168k - $240k
...wide range of simple, reliable, and secure crypto products and services to individuals... ..., and impact. The Department: Threat Detection & Response In the emerging industry of... ...space. From security architecture and engineering to maintenance of cold storage systems...SuggestedWork at officeRemote workFlexible hours- ...Senior Security Engineer, Security Incident Response Team (SIRT) Remote, US GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables... ...broader GitLab environment against evolving security threats. This role also supports our FedRAMP environment and requires...Remote work
$120k - $135k
...hedge fund is seeking a Cybersecurity Analyst to enhance security controls and manage incident response. The ideal candidate will have 2-3 years of... ...passion for security and an ability to adapt to emerging threats are essential. The base pay is between $120,000 and $...- ...services firm in New York is seeking a Cyber Defense Response Analyst II to manage cyber incidents and threats. The candidate must have strong skills in digital... ..., and leading tabletop exercises. An education in Engineering or Computer Science is required, along with...
- A technology solutions provider in New York City is seeking a Cyber Security/SOC Analyst. The ideal candidate will manage cybersecurity projects, focusing on threat monitoring and incident response within a hybrid work environment. Responsibilities include investigating...
- A leading cybersecurity firm in Kentucky seeks an experienced L2 Cyber Security Analyst to manage incident response and conduct advanced threat hunting. The ideal candidate will have a bachelor's degree in Computer Science or a related field, with proven experience in...
$234.4k - $385k
...About the Team Security is at the foundation of OpenAI's mission to ensure... ...About the Role As a Security Engineer on Detection & Response, you'll help protect OpenAI's most sensitive... ...ship with the right telemetry, threat models, and response playbooks from...- Aegistech is seeking a Cyber Incident Response Analyst to enhance their security program. This role involves detecting and responding to security incidents, collaborating with Security Operations and Threat Intelligence teams to ensure comprehensive incident management...
- ...Security Engineer - Threat Intel New York City, NY; Remote-Friendly (Travel-Required) | San Francisco, CA | Washington, DC About Anthropic... .... The Threat Intelligence function within our Detection & Response team exists to make sure we see them coming. As a Threat...Work at officeRemote workVisa sponsorshipFlexible hours
- ...cross-chain payments protocol company in New York is seeking a Security Engineer to own the security posture of its infrastructure. You will lead threat modeling, vulnerability management, and incident response processes, along with driving compliance readiness. The ideal...Remote work
$139k - $204k
...Senior Security Engineer I, Advanced Response CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform... ...the world's most demanding AI infrastructure — and threat actors know it. The Advanced Response Team exists to fight...Temporary workCasual workWork at officeRemote workFlexible hours$156k - $210k
...unleash employee productivity without compromising security by ensuring every identity is authentic, every... ..., simpler digital future. As a Senior Security Engineer specialized in Threat Intelligence on the Detection & Response team, you will focus on understanding adversary...Currently hiringLocal areaImmediate startRemote workWork from home- ...GitLab is seeking a Senior Security Engineer for their Security Incident Response Team (SIRT) to lead incident response efforts against evolving security threats. This remote role requires U.S. citizenship and involves high-impact incident management, automation, and...Remote work
$167.5k - $235k
...Senior Security Engineer (Detection & Response) New York, New York Apply Who We Are At Justworks, you’ll enjoy a welcoming and casual environment... ...logic that powers our platform, conduct proactive threat hunting, and drive continuous improvements across our...Casual workLocal area- ...The Role We are seeking a seasoned Security Engineer with a specialization in detection and response to join our team. As a strategic partner, you will be responsible... .... Stay informed about the latest security threats, vulnerabilities, and compliance mandates affecting...
$70k - $99.2k
Hyundai Autoever America is looking for a Security Engineer II to enhance its security posture by implementing and managing enterprise security technologies. Ideal candidates will have a solid understanding of security frameworks and experience in Security Engineering,...$159.3k - $202.4k
...Customer Ecosystems (ACES) team, part of Amazon Cyber Threat Intelligence (ACTI), is responsible for developing actionable intelligence on... ...performing question-driven analysis is required. As a Security Intelligence Engineer, you will help enhance our capabilities by...Work experience placementInternshipFlexible hours- ...States is seeking a Cybersecurity Analyst to safeguard information systems from cyber threats. The role includes monitoring network traffic, analyzing incidents, and implementing security measures. Candidates should have a Bachelor's degree in Computer Science or...
$40 per hour
...will evaluate AI-generated security content, solve technical cybersecurity... ...reason about real-world threats and defenses. Cybersecurity... ...Australia, and New Zealand Responsibilities Evaluate AI-generated... ...incident response, detection engineering, DFIR, malware analysis, threat...Hourly payFull timePart timeRemote work$134k - $205k
...Gong is looking for a Senior Security Operations Engineer to lead efforts in securing our infrastructure. The... ...engineering and detection engineering. Responsibilities include automating processes, proactively identifying threats, and mentoring junior team members. We offer...Flexible hours- ...dedicated to transforming how patients receive care is seeking a Sr. Cyber Threat & Response Engineer. In this role, you will identify, analyze, and mitigate cyber threats, collaborate with a security team, and respond to critical alerts post-hours. Ideal candidates will...Remote workFlexible hours
$119k - $145k
...Framework Ventures is seeking a talented security professional to perform investigations into detected threats and utilize customers’ security products for remediation... ...like CrowdStrike and Microsoft Defender. Responsibilities include providing thorough reports to...Night shift- ...Threat Detection & Response Engineer Location: New York City, (Hybrid) Compensation: Top-tier compensation We're representing a global... ...lab than a traditional bank. They are looking for a Security Engineer who thinks like a Software Engineer. If you...
$235k - $255k
...WeightWatchers is looking for a Senior Security Engineer - Detection and Response to join their remote team. In this role, you will build and enhance a detection and response program, collaborate with multiple teams to secure infrastructure, and mentor others on security...Remote work$100k - $160k
...A cybersecurity firm is looking for a Senior/Principal Federal Security Engineer experienced in managing detection, response, and vulnerability issues within Federally regulated environments. The role requires expertise in security technologies and compliance standards...- ...Monarch Money is seeking a Senior Security Engineer to enhance our security team. This fully remote position focuses on developing detection and response capabilities, integrating AI workflows for automation, and responding to security incidents. The ideal candidate should...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Threat Response. Be the first to apply!
Related searches
- staff security engineer New York, NY
- senior application security engineer New York, NY
- sr information security engineer New York, NY
- security engineering manager New York, NY
- security operations engineer New York, NY
- cloud security engineer New York, NY
- azure security engineer New York, NY
- endpoint security engineer New York, NY
- physical security engineer New York, NY
- systems security engineer New York, NY

