Security Engineer, Threat Response
San Francisco, San Francisco County, California, 94199, USA
Listed on 2026-06-28
-
IT/Tech
Cybersecurity, Security Manager, Network Security, Information Security
At the company, security is foundational to our mission of helping humanity thrive by enabling the world's teams to work together effortlessly. Our security team protects the company's employees, users, and customers by proactively addressing threats and fostering a culture of security throughout our product and operations.
We are looking for a Security Engineer, Threat Response to join our Security blue team in New York City. You'll be a foundational member of the security presence in a key hub, partnering directly with IT, infrastructure, and product teams to ensure we have robust detection, response, and vulnerability management capabilities. You will be instrumental in scaling our security practices by building effective monitoring, automating repetitive security operations tasks, and championing a security-first mindset.
This role sits within the Security Threat Operations and Response Management (STORM) group, responsible for the security of the company the company and the security of the product — ensuring we maintain customer trust and are able to grow sustainably. You will collaborate with teams across the company including Infrastructure, Customer Success, Legal, IT, and other key stakeholders to drive better incident response outcomes.
This role is based in our New York City or San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.
Whatyou’ll achieve
- Lead security incident detection, analysis, and response efforts, ensuring timely and effective remediation of security incidents.
- Actively participate in and lead the on-call rotation, setting the standard for security incident management across the team.
- Manage and mature our vulnerability management program, including scanning, assessment, prioritization, and tracking remediation efforts.
- Utilize and optimize security tools such as Panther for SIEM, Crowd Strike for endpoint detection and response, and other security platforms.
- Develop, implement, and maintain security playbooks and automation scripts to streamline security operations and reduce manual toil.
- Monitor security alerts and threat intelligence feeds, proactively identifying and addressing emerging threats.
- Conduct forensic analysis during security incidents to understand the scope and impact of incidents.
- Lead retrospectives to help raise engineering excellence and embed a continuous improvement culture across the team.
- Drive incident management and incident response best practices across the company, mentoring fellow engineers through pairing, process definition, and training exercises.
- Participate in and help lead tabletop exercises to ensure different stakeholders are thinking about and preparing for incidents across the company.
- Collaborate with engineering teams to integrate security best practices into development processes and provide guidance on secure configurations.
- Stay informed of industry trends, emerging threats, and best practices in security operations, detection, and response to ensure the company's security posture remains robust.
- Collaborate with teammates and stakeholders to develop both short-term and long-term strategies for risk management.
- 5+ years of experience in security operations, incident response, threat detection, or vulnerability management.
- Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security) for log analysis, alert correlation, and dashboard creation.
- Deep working knowledge of endpoint detection and response (EDR) tools (e.g., Crowd Strike, Sentinel One) and their capabilities.
- Proven experience in developing and implementing security automation using scripting languages (e.g., Python, Power Shell) or orchestration tools.
- Experience performing security incident investigations and forensic analysis.
- Familiarity with common attack techniques, tactics, and procedures (TTPs) and frameworks like…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).