asana

Security Risk Manager

Apply Now

At a Glance

Location
San Francisco
Experience
7+ years
Compensation
base salary range is between $194,000–$220,000. The actual base salary will
Posted
2026-06-29T14:42:34-04:00

Key Requirements

Certifications

  • ISO

Domain Knowledge

  • Automation
  • Engineering
  • SaaS

Benefits & Perks

Health Insurance

ble and competitive benefits packages that support our employees worldwide a

Requirements

7+ years of experience in information security with a strong focus on security risk management and GRC.

Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis.

Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring — you've built things, not just directed others to build them.Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.

Strong understanding of cloud environments and SaaS architecture — enough to have credible risk conversations with technical teams.

Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity and decision-making.

Responsibilities

Own Asana's security risk management program:

Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.

Automate risk identification and monitoring:

Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's risk posture is always current and not dependent on manual review cycles.

Deliver quantitative risk reporting:

Develop executive-level dashboards that communicate security risk in business terms — probability, potential impact, cost of control vs.