Asana

Staff Detection Engineer

Asana
Apply
5 hours ago
Warsaw, PolandStaff+

Responsibilities

  • Design, build, and maintain high-fidelity detections across AWS, GCP, identity providers, SaaS environments, endpoints, and software supply chains.
  • Own the Panther detection-as-code pipeline, including rule structure, unit and integration testing, review standards, and CI/CD deployment.
  • Map and close detection coverage gaps using MITRE ATT&CK and the organization’s threat model.
  • Onboard and normalize telemetry sources and ensure logs are complete, available, and queryable.
  • Measure and improve alert precision, time-to-triage, and false-positive rates by tuning or retiring detections.
  • Validate detections through purple-team exercises, atomic tests, adversary emulation, and real attacker behavior.
  • Convert incident findings and threat intelligence into durable detection coverage.
  • Build SOAR enrichment and automation so alerts provide responders with useful context.

Requirements

  • 8+ years of experience in detection engineering, security operations, or threat hunting.
  • Strong Python skills and hands-on experience with Git workflows, pull-request code review, automated testing, and CI/CD.
  • Deep experience with detection-as-code, test-driven detection logic, rule lifecycle management, and CI/CD deployment.
  • Strong experience with SIEM platforms such as Panther, Splunk, or Elastic Security, including query languages, log schemas, and correlation.
  • Deep understanding of cloud and identity telemetry, including AWS audit logs, GCP audit logs, Okta system logs, and SaaS audit APIs.
  • Working knowledge of EDR tools such as CrowdStrike and SentinelOne and associated endpoint telemetry.
  • Fluency with attacker TTPs and MITRE ATT&CK, using them to drive coverage decisions.
  • Experience detecting software supply-chain and CI/CD threats, including npm, PyPI, or GitHub Actions, is preferred.
  • Experience with adversary emulation frameworks such as Atomic Red Team or Caldera and purple-team exercises is preferred.
  • Experience with security data engineering, including log pipelines, schema design, or high-volume telemetry cost optimization, is preferred.
  • Go, Bash, or JavaScript/TypeScript experience is a plus.
  • Curiosity about AI tools and emerging technologies and willingness to use them to improve productivity, collaboration, or decision-making.

Benefits

  • Contract of Employment in Poland, with an option for 50% tax-deductible author’s-rights costs where applicable.
  • Estimated base salary of 40,000–45,000 PLN gross per month, plus possible equity and other compensation components.
  • Hybrid, office-centric work in Asana’s Warsaw innovation hub, with catering on office days.
  • Health insurance with dental and travel coverage through Lux Med.
  • Vacation allowance, career growth budget, and home-office setup budget.
  • Gym or fitness card, fertility healthcare and family-forming support through Carrot, mental-health support through Modern Health, and group life insurance.
  • MacBook with necessary accessories.

Tech Stack

Categories

Asana

About Asana

1,001-5,000 employees

Asana builds a work management platform that helps teams plan, track, and coordinate projects and goals, with AI-assisted features and integrations. It sells subscription-based SaaS used across functions from marketing to engineering. Founded in 2008 and headquartered in San Francisco, Asana is publicly traded on the NYSE and used by more than 170,000 organizations, including Accenture and Amazon.

Contact me