01 Zakres zadań
- Lead security design reviews and structured threat modelling (STRIDE, OWASP Threat Dragon, MITRE ATT&CK) for new and in-flight projects to identify risk early and produce actionable guidance before code is written.
- Conduct security-focused code reviews and analyze data flows across services, APIs, and integrations to identify trust boundaries and attack surface reduction opportunities.
- Translate threat model findings into concrete engineering recommendations and feed architectural weaknesses to the red team for proactive adversary emulation planning.
- Build and mature Asana’s security architecture review process and define standards aligned to industry best practices like NIST 800-53, FedRAMP, ISO 27001, and OWASP ASVS.
- Develop and maintain a reusable security pattern library for authentication, authorization, encryption, API security, and data handling that engineering teams can adopt directly.
- Evaluate AI tooling and integrations using industry standards (OWASP Maestro and OWASP Top 10 for LLMs), assessing risks including prompt injection, model misuse, data leakage, and supply chain exposure.
- Develop governance practices for AI-augmented development workflows and stay current with the evolving AI security landscape.
