🏢
Asana
Security Risk Manager
Job Description
ABOUT THE ROLE
Asana is seeking a seasoned Security Risk Manager to lead the development and implementation of a comprehensive security risk management program. This critical role will be responsible for designing and continuously maturing a quantitative risk framework that enables data-driven risk decisions across the organization. The successful candidate will leverage their expertise in security risk management, GRC, and quantitative risk methodologies to drive a culture of security awareness and risk awareness across the company.
WHAT YOU'LL DO
As the Security Risk Manager, you will be responsible for:
- Designing and continuously maturing a quantitative risk framework, including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds.
- Building and maintaining a living risk register, developing key risk indicators (KRIs), tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.
- Automating risk identification and monitoring through the design and implementation of data pipelines and integrations that continuously surface security risks.
- Delivering quantitative risk reporting through the development of executive-level dashboards that communicate security risk in business terms.
- Partnering cross-functionally with Legal, Privacy, Finance, and Engineering to influence security investment decisions and build a culture of risk awareness.
WHAT YOU'LL NEED
- 7+ years of experience in information security with a strong focus on security risk management and GRC.
- Demonstrated experience building or leading a security risk management program, not just contributing to one.
- Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis.
- Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring.
- Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
- Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making.
- Strong understanding of cloud environments and SaaS architecture.
- Excellent communication skills to translate technical risk findings for both engineering teams and C-suite stakeholders.
- Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity and decision-making.
WHY REMOTE
Asana is committed to building a global team that includes a variety of backgrounds, perspectives, and skills. This role will be remote, with the opportunity to work with a distributed team and collaborate with colleagues from around the world.
BENEFITS
- Estimated base salary range: $194,000–$220,000.
- Equity and benefits package, including mental health, wellness & fitness benefits, career coaching & support, inclusive family building benefits, long-term savings or retirement plans, and more.