Security Risk Manager

Added
26 days ago
Type
Full time
Salary
Upgrade to Premium to se...

Related skills

security siem fedramp soc2 iso27001

πŸ“‹ Description

  • Own Asana's internal security risk management program end-to-end.
  • Design and mature a quantitative risk framework with scoring and appetite.
  • Build systems and processes to scale risk, not just policies.
  • Serve as trusted advisor to senior leadership on risk.
  • Automate risk identification via data pipelines from scanners, SIEMs, and cloud tools.
  • Partner with Legal, Privacy, Finance, and Engineering on risk decisions.

🎯 Requirements

  • 7+ years of information security with a focus on risk management and GRC.
  • Proven track record building or leading a security risk program.
  • Hands-on experience with quantitative risk methods such as FAIR, risk scoring, or statistical risk analysis.
  • Scripting or automation to integrate security tooling and build data pipelines.
  • Deep knowledge of NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
  • Excellent communicator translating risk findings for engineering and C-suite stakeholders.

🎁 Benefits

  • Mental health, wellness & fitness benefits
  • Career coaching & support
  • Inclusive family building benefits
  • Long-term savings or retirement plans
  • In-office culinary options to cater to dietary preferences
Share job

Meet JobCopilot: Your Personal AI Job Hunter

Automatically Apply to Engineering Jobs. Just set your preferences and Job Copilot will do the rest β€” finding, filtering, and applying while you focus on what matters.

Related Engineering Jobs

See more Engineering jobs β†’