Primary record

Security Risk Manager

Asana Indexed employerSan Francisco · San Francisco, California, United States
Source-hosted applyChecked 3h agoInternship
Apply at Asana

Asana receives this application through Greenhouse. Babu Careers does not claim delivery.

Workplace

hybrid

Employment

Internship

Published

Aug 11, 2026

Closes

No date supplied

The role

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations.

As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements

What you'll achieve

• Own Asana's security risk management program: Design and continuously mature a quantitative risk framework — including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds — that enables consistent, data-driven risk decisions across the organization.

• Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.

• Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security ris

Requirements

Department: Security Operations