GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsCaliforniaSan Francisco Bay AreaSecurity Risk Engineer

Security Risk Engineer

Asana
RiskOn-siteFull-timeSan Francisco$202,000–$230,000

Asana is hiring for the job of Security Risk Engineer, San Francisco (On-site). This is a Risk job in the governance, risk, and compliance field, with a posted range of $202,000–$230,000. Review the full details below and apply directly with Asana.

Organization: AsanaLocation: San FranciscoWorkplace: On-siteFocus: RiskSalary: $202,000–$230,000Posted: Sep 19, 2026
Asana is hiring for this Risk job in San Francisco, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC jobs in San Francisco →

At Asana security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana s employees users and customers by proactively addressing threats ensuring compliance and fostering a culture of security throughout our product and operations.

As the Security Risk Engineer you will own Asana s internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You ll build the systems and processes that make risk scalable not just the policies that describe it and serve as a trusted advisor to senior leadership.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday Tuesday and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you re interviewing for this role your recruiter will share more about the in-office requirements

What you ll achieve

Own Asana s security risk management program Design and continuously mature a quantitative risk framework including risk scoring methodologies likelihood and impact modeling and risk appetite thresholds that enables consistent data-driven risk decisions across the organization. Build and maintain a living risk register Own Asana s central security risk register developing KRIs tracking trends over time and driving accountability for risk treatment and remediation with business and technical owners. Automate risk identification and monitoring Design and implement automated data pipelines and integrations that continuously surface security risks pulling signals from vulnerability scanners cloud security tooling SIEMs and third-party risk sources so Asana s risk posture is always current and not dependent on manual review cycles. Deliver quantitative risk reporting Develop executive-level dashboards that communicate security risk in business terms probability potential impact cost of control vs. cost of breach and residual risk exposure to inform investment and prioritization decisions. Partner cross-functionally on risk Act as the primary security risk partner to Legal Privacy Finance and Engineering. Influence security investment decisions and build a culture of risk awareness across the company.

About you

7+ years of experience in information security with a strong focus on security risk management and GRC. Demonstrated experience building or leading a security risk management program not just contributing to one. Hands-on experience with quantitative risk methodologies such as FAIR risk scoring models or statistical risk analysis. You back up risk ratings with numbers not just color codes. Hands-on experience scripting or building automation to integrate security tooling build data pipelines or automate risk monitoring you ve built things not just directed others to build them.Deep knowledge of security frameworks including NIST CSF NIST SP 800-30 ISO 27001 SOC 2 and FedRAMP. Proven ability to develop risk metrics KRIs and executive-level reporting that drives decision-making. understanding of cloud environments and SaaS architecture enough to have credible risk conversations with technical teams. Excellent communicator who can translate technical risk findings for both engineering teams and C-suite stakeholders. Demonstrates curiosity about AI tools and emerging technologies with a willingness to learn and leverage them to enhance productivity and decision-making.

At Asana we re committed to building teams that include a variety of backgrounds perspectives and skills. If you re interested in this role and don t meet every listed requirement we still encourage you to apply.

What we ll offer

For this role the estimated base salary range is between $202,000–$230,000. The actual base salary will vary based on various factors including market and individual qualifications objectively assessed during the interview process.

In addition to base salary your compensation package may include equity and benefits. If you re interviewing for this role speak with your Talent Acquisition Partner to learn more.

We strive to provide equitable and competitive benefits packages that support our employees worldwide and include

Mental health wellness fitness benefits Career coaching support Inclusive family building benefits Long-term savings or retirement plans In-office culinary options to cater to your dietary preferences

Pursuant to the San Francisco Fair Chance Ordinance we will consider for employment qualified applicants with arrest and conviction records.

# -Hybrid

About us

1 Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals faster. Asana has been named to Fortune s Best Workplaces for 7+ years and recognized by Fast Company Forbes and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

TypographyPresentation_31345133_root--medium RichText3-paragraph--withVSpacingNormal RichText3-paragraph HighlightSol_1625403506_highlightSol HighlightSol_1625403506_buildingBlock left We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race color religion age sex national origin disability status genetics protected veteran status sexual orientation gender identity or expression or any other characteristic protected by law.

1 strong a LinkPrimaryPresentation LinkPrimaryPresentation--sentimentSelected PrimaryLink HighlightSol HighlightSol--core HighlightSol--buildingBlock Join Asana’s Talent Network;to stay up to date on job opportunities and life at Asana.

Location and market context

This job is based in San Francisco on-site. Local candidates benefit from being close to Asana's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About risk management jobs

Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.

How to position yourself for this risk management job

Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Asana would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Asana

More GRC jobs in San Francisco

Hiring for Risk?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Security Risk Engineer in San Francisco open regularly. Be first to know, privately. No current employer ever sees you looking.

New Risk jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.