asana
Security Risk Manager
At a Glance
- Location
- San Francisco
- Experience
- 7+ years
- Compensation
- base salary range is between $194,000–$220,000. The actual base salary will
- Posted
- 2026-06-29T14:42:34-04:00
Key Requirements
Certifications
- ISO
Domain Knowledge
- Automation
- Engineering
- SaaS
Benefits & Perks
ble and competitive benefits packages that support our employees worldwide a
Requirements
7+ years of experience in information security with a strong focus on security risk management and GRC.
Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis.
Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring — you've built things, not just directed others to build them.Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
Strong understanding of cloud environments and SaaS architecture — enough to have credible risk conversations with technical teams.
Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity and decision-making.
Responsibilities
Own Asana's security risk management program:
Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.
Automate risk identification and monitoring:
Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's risk posture is always current and not dependent on manual review cycles.
Deliver quantitative risk reporting:
Develop executive-level dashboards that communicate security risk in business terms — probability, potential impact, cost of control vs.