Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Risk and Compliance Lead image - Rise Careers
Job details

Security Risk and Compliance Lead

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana’s employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards and collaborate across the organization to build and maintain trust at scale.

As the Security Risk and Compliance Lead at Asana, you’ll play a critical and high-impact role in building and maintaining trust with Asana’s global customers. You will lead and continuously improve our vendor risk assessment and security risk management programs, ensuring we maintain a strong security posture and meet both compliance requirements and customer expectations.

This is a highly cross-functional role where you’ll partner closely with Legal, Privacy, Finance, R&D, and other key stakeholders. You’ll help evolve our programs with a strategic, risk-based mindset—balancing operational excellence with agility as we grow and scale.

This role is based in our Warsaw office with an office-centric hybrid schedule - in-office days are Monday, Tuesday, and Thursday. 

We offer a Contract of Employment (UoP) for our employees in Poland.

What you’ll achieve

  • Vendor Risk Management: Own and operate Asana’s vendor risk management program, including performing due diligence for new vendors, ongoing monitoring and reporting, and reviewing vendor contracts for security and compliance requirements.
  • Security Risk Management: Support the execution of periodic assessments across the organization to identify, evaluate, and track risks—driving mitigation and treatment efforts with business and technical owners.
  • Risk Register Maintenance: Assist in maintaining the central security risk register to promote and drive accountability across the organization.
  • Compliance Audit Support: Partner with internal teams to support annual compliance audits such as SOC 2 and ISO 27001, providing evidence and program documentation as needed.
  • Policy Management: Draft, update, and maintain security policies, standards, and procedures that align with evolving business needs and industry best practices.
  • Metrics: Define, track, and report on key metrics that demonstrate program effectiveness and operational excellence—using insights from data to continuously refine and improve risk and compliance processes.

About you

  • 5+ years of experience in Governance Risk and Compliance, with a focus on risk assessments and risk management. 
  • Demonstrated understanding of security compliance frameworks and audits (e.g., SOC 2, ISO 27001, PCI DSS, NIST, HIPAA, FedRAMP, etc.).
  • Experience with enterprise SaaS applications, cloud infrastructure, modern software engineering practices and tools, databases, operating systems, secure network design, and public cloud models such as AWS
  • Experience performing third-party vendor security reviews and due diligence processes
  • Proven ability to drive operational process improvements and develop metrics for tracking success.
  • Excellent communicator and influencer, with the ability to translate complex security and compliance requirements to both technical and non-technical stakeholders. 

At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.

What we offer

  • Generous, transparent and fair compensation system (base salary and generous Restricted Stock Unit for Asana Inc.) 
  • Contract of Employment (with 50% tax deductible costs for author’s rights usage for Engineers) 
  • Health insurance with dental and travel coverage (Lux Med) 
  • Lunch catering on the days that you work from the office
  • Career growth budget 
  • Home office setup budget 
  • Gym/Fitness reimbursement
  • Fertility healthcare and family-forming support with Carrot
  • Mental health support in Modern Health
  • Group life insurance
  • MacBooks with all necessary accessories


For this role, the estimated base salary range is between 22 000  - 28 000 PLN gross monthly on the contract of employment (UoP). The actual base salary will vary based on various factors and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base compensation range for this role may be modified.

Our total compensation consists of base salary and equity (RSUs). 

About us

Asana helps teams orchestrate their work, from small projects to strategic initiatives. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named a Top 10 Best Workplace for 5 years in a row, is Fortune's #1 Best Workplace in the Bay Area, and one of Glassdoor’s and Inc.’s Best Places to Work. After spending more than a year physically distanced, Team Asana is safely and mindfully returning to in-person collaboration, incorporating flexibility that adds hybrid elements to our office-centric culture. With 11+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong. 

We believe in supporting people to do their best work and thrive, and building a diverse, equitable, and inclusive company is core to our mission. Our goal is to ensure that Asana upholds an inclusive environment where all people feel that they are equally respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law. We also comply with the San Francisco Fair Chance Ordinance and similar laws in other locations.

Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.

#LI-Hybrid

 

Asana Glassdoor Company Review
4.1 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Asana DE&I Review
4.8 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Asana
Asana CEO photo
Dustin Moskovitz
Approve of CEO

Average salary estimate

$75000 / YEARLY (est.)
min
max
$66000K
$84000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Risk and Compliance Lead, Asana

At Asana, we're on a mission to help teams work together effortlessly, and security is at the heart of everything we do. If you're an expert in risk and compliance and want to make a significant impact, we invite you to join our team as the Security Risk and Compliance Lead in our vibrant Warsaw office! In this pivotal role, you'll not only oversee our vendor risk management program but also enhance our security risk management strategies. You'll work closely with various teams, including Legal, Privacy, and Finance, fostering a culture of security by proactively addressing potential threats and ensuring compliance with regulations. We believe in balancing operational excellence with agility, so your strategic approach will be essential to our success as we grow and scale. You’ll play a critical role in ensuring that Asana maintains a robust security posture while meeting customer expectations. You’ll collaborate with diverse stakeholders to evolve our programs and translate complex compliance requirements into understandable processes. With a hybrid work schedule offering flexibility, we value the health and well-being of our employees and provide generous benefits. If you’re excited about the opportunity to lead in security risk and compliance at Asana, we’d love to hear from you!

Frequently Asked Questions (FAQs) for Security Risk and Compliance Lead Role at Asana
What are the main responsibilities of the Security Risk and Compliance Lead at Asana?

As the Security Risk and Compliance Lead at Asana, your primary responsibilities include managing the vendor risk assessment program, supporting risk management initiatives, assisting with compliance audits, and drafting security policies. You will work closely with various internal teams to ensure all aspects of security compliance are met, and you'll also help track and report on key metrics that demonstrate the effectiveness of our programs.

Join Rise to see the full answer
What qualifications are required for the Security Risk and Compliance Lead position at Asana?

To qualify for the Security Risk and Compliance Lead at Asana, candidates should have at least 5 years of experience in Governance Risk and Compliance, a strong understanding of security compliance frameworks (SOC 2, ISO 27001, etc.), and experience in vendor security assessments. Excellent communication and influencing skills, coupled with a strategic risk-based mindset, are essential for this role.

Join Rise to see the full answer
How does the role of Security Risk and Compliance Lead impact Asana’s customers?

In the role of Security Risk and Compliance Lead at Asana, you will play a vital role in ensuring that customer data is protected and that the company complies with industry regulations. By managing vendor risk and ensuring security measures are in place, you will help build and maintain trust with our global customers, enhancing their confidence in Asana’s services.

Join Rise to see the full answer
What is the work environment like for the Security Risk and Compliance Lead at Asana?

The work environment at Asana for the Security Risk and Compliance Lead is dynamic and collaborative. Positioned in our Warsaw office, this role supports a hybrid work model, where you'll be encouraged to engage with teams in person and remotely. Asana promotes a culture of inclusion and flexibility that values diverse perspectives.

Join Rise to see the full answer
What benefits does Asana offer for the Security Risk and Compliance Lead role?

Asana provides an attractive benefits package for the Security Risk and Compliance Lead, including competitive salary options, health insurance, lunch catering, a career growth budget, and personal development support. The company is committed to employees' well-being, offering mental health resources, fitness reimbursements, and support for family-forming healthcare.

Join Rise to see the full answer
Common Interview Questions for Security Risk and Compliance Lead
Can you describe your experience with compliance frameworks such as SOC 2 or ISO 27001?

In preparation for this question, think about specific projects where you've worked with compliance frameworks like SOC 2 or ISO 27001. Highlight your role in implementing policies, conducting audits, or ensuring compliance. Mention any challenges faced and how you overcame them, showing your problem-solving skills and understanding of these frameworks.

Join Rise to see the full answer
How do you approach vendor risk assessments?

When answering this question, detail your process for conducting vendor risk assessments. Discuss the criteria you use to evaluate vendors, how you ensure ongoing monitoring, and your methods for documenting and communicating findings. Emphasize your attention to detail and dedication to maintaining security standards in vendor relationships.

Join Rise to see the full answer
What strategies do you employ to maintain a strong security posture?

In your response, outline the strategies you have used to maintain a strong security posture, such as regular risk assessments, robust policy management, and employee training programs. Provide examples of how these strategies helped mitigate risks or improve compliance within an organization.

Join Rise to see the full answer
Tell us about a time you improved a compliance process.

Provide a specific example of a compliance process that you improved. Describe the initial process, the changes you made, and the impact of those changes. Focus on your analytical skills and ability to drive operational improvements, as well as how you engaged stakeholders in the process.

Join Rise to see the full answer
How do you communicate complex security concepts to non-technical stakeholders?

Discuss your approach to simplifying complex security concepts for non-technical stakeholders. Highlight your communication skills and provide an example of how you have successfully conveyed technical information in an easily understandable way, ensuring that the audience can grasp key points and implications.

Join Rise to see the full answer
What role does policy management play in your work as a Security Risk and Compliance Lead?

Share your perspective on the importance of policy management in maintaining compliance and security standards. Discuss your experience in drafting, updating, and enforcing policies, along with your methods for ensuring that employees are aware of and adhere to security practices.

Join Rise to see the full answer
How do you stay updated on the latest compliance regulations and security threats?

Outline the resources and methods you utilize to keep up with the latest compliance regulations and security threats. This could include attending industry conferences, participating in workshops, or engaging with professional networks. Highlight your commitment to continuous learning and improving your expertise.

Join Rise to see the full answer
Describe a situation where you had to influence a decision regarding security compliance.

Provide a relevant example of when you needed to influence a decision related to security compliance. Focus on your approach to advocating for security needs, the challenges you faced, and how you successfully communicated the importance of compliance to decision-makers.

Join Rise to see the full answer
What metrics do you consider essential for tracking compliance effectiveness?

Discuss your approach to identifying and tracking key metrics that indicate the effectiveness of compliance programs. Mention specific metrics you have used in previous roles, how you utilized them to assess performance, and how continuous metrics tracking can drive improvements in compliance efforts.

Join Rise to see the full answer
Why do you want to work as the Security Risk and Compliance Lead at Asana?

Your answer should reflect your passion for security and compliance and your alignment with Asana’s mission. Discuss how your values resonate with Asana’s culture and how you believe your skills and experience will contribute to the company’s goals in maintaining a secure environment for its customers.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 11 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Maternity Leave
Paternity Leave
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance

Join Asana's People Team as a People Systems Leader and shape the future of HR technology within a global organization.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Maternity Leave
Paternity Leave
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance

Lead Asana's Communications Integrations team as an Engineering Manager, driving innovative software solutions for enhanced user collaboration.

Photo of the Rise User
Posted 11 days ago

Bitstamp seeks a Senior Information Security Officer to lead security compliance and operational resilience efforts in a remote work environment.

Photo of the Rise User
Posted 6 days ago

We are looking for a Senior Systems Analyst at Sonata Software to drive the development of transformative business technology solutions.

GDIT Hybrid USA VA Fort Eustis
Posted yesterday

Become a vital part of GDIT's mission as a Systems Engineer, providing tailored technology solutions to enhance safety and efficiency for our clients.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Lead American Express's Information Security initiatives as a Technology Exam and Findings Management Manager, where your impact shapes the future of security compliance.

Join MUFG as an Infrastructure Technical Delivery and Support Engineer to impact the future of financial services through innovative Infrastructure solutions.

Photo of the Rise User
Eurofins Remote Arvada, CO, USA
Posted 7 days ago

Seeking a skilled IT Software Developer to enhance web applications within a global life sciences leader committed to sustainability and diversity.

Posted 6 days ago

Join our team as an AWS Consultant specializing in API development, and contribute to creating secure and efficient solutions within the AWS ecosystem.

Photo of the Rise User

Join ENS Solutions as an Information Systems Security Engineer, focusing on cybersecurity within the Intelligence Community.

Asana is a software development company offering a collaborative work management platform. The company is headquartered San Francisco, California and we are committed to enabling the world's teams to work together effortlessly.

51 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Family FriendlyBadge Work&Life Balance
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
BENEFITS & PERKS
Maternity Leave
Paternity Leave
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 20, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Perrysburg just viewed Sourcing Leader, Minerals & Cullet at Owens Corning
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF
Photo of the Rise User
Someone from OH, Solon just viewed Graphic Designer at Applause
Photo of the Rise User
Someone from OH, North Canton just viewed NodeJs developer at BlackStone eIT
Photo of the Rise User
Someone from OH, North Canton just viewed Software Development Engineer - Recent Grads Welcome at Sonos
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs