Jobs / Poland / Asana INC

Staff Detection Engineer

Asana INC · 🌍 Warsaw

Sponsorship verdict

No sponsorship evidence yet

No government record and no wording either way. Not a refusal — ask the recruiter.

  • No government sponsor record hereNo government sponsor record covers this employer in this country.
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • Can’t check pay against the visa rulesWe don’t have visa salary rules for this country yet.
  • Confirmed live todayWhen a source last listed this job as open.

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Why not apply?

Sponsorship unknown

No register record and no sponsorship wording in the posting. Worth asking the employer before investing significant time.

SponsorApply flags time-wasters so your applications go where they can land. These come from the posting's own wording — read the original listing to confirm. See better-fit alternatives →

Sponsor Radar — Asana INC

Sponsorship not verified for this country

No government sponsor record covers this employer in this country.

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Asana INC →

About the role

Our Security team keeps Asana's employees, users, and customers safe by proactively addressing threats and fostering a culture of security across our product and operations. We're looking for a Staff Detection Engineer to join our Threat Response team in our Warsaw innovation hub. You'll own how we find threats: the detection logic, the telemetry it runs on, and the pipeline that ships it. Detection here is software. Rules are written as code, tested against real and synthetic attacker behavior, reviewed in pull requests, and deployed through CI/CD. You'll partner with our incident responders, infrastructure, and product teams to make sure that when something bad happens, we see it fast and with high signal. We offer a Contract of Employment (UoP) for our employees in Poland. What you'll achieve • Design, build, and maintain high-fidelity detections across cloud infrastructure (AWS/GCP), identity providers (e.g., Okta), SaaS environments, endpoints, and the software supply chain. • Own our detection-as-code pipeline in Panther: rule structure, unit and integration tests, review standards, and CI/CD deployment, so detection logic is treated as production code. • Map and close coverage gaps against MITRE ATT&CK and the threat model for our environment, prioritizing the techniques most likely to be used against a SaaS company. • Onboard and normalize new telemetry sources , working with infrastructure and IT to make sure the right logs exist, are complete, and are queryable. • Measure and improve alert quality , tracking precision, time-to-triage, and false-positive rates, and tuning or retiring detections that don't earn their keep. • Validate detections against real attacker behavior through purple-team exercises, atomic tests, and emulation, and feed findings back into rule development. • Turn incidents and threat intelligence into detections , partnering with incident responders to convert lessons learned and emerging TTPs into durable coverage. • Build enrichment and automation in our SOAR platform so alerts arrive with the context responders need to act. About you • 8+ years in detection engineering, security operations, or threat hunting , with a track record of building detections that responders actually trust. • Strong Python skills , with hands-on experience in Git workflows, PR-based code review, automated testing, and CI/CD. Go, Bash, or JavaScript/TypeScript is a plus. • Deep experience with detection-as-code , including test-driven detection logic, rule lifecycle management, and deploying rules through CI/CD pipelines. • Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security), including query languages, log schemas, and correlation. • Deep understanding of cloud and identity telemetry , such as AWS, GCP audit logs, Okta system logs, and SaaS audit APIs, and what attacker activity looks like in each. • Working knowledge of EDR tools (e.g., CrowdStrike, SentinelOne) and endpoint telemetry. • Fluency with attacker TTPs and MITRE ATT&CK, and experience using it to drive coverage decisions rather than as a checklist. • Collaborative and pragmatic mindset , with strong communication across technical and non-technical partners, and an instinct for reducing noise rather than adding to it. • Demonstrated curiosity about AI tools and emerging technologies, with willingness to learn and leverage them to enhance productivity, collaboration, or decision-making. Nice to have • Experience detecting software supply chain and CI/CD threats , including anomalous behavior in build systems and developer ecosystems (e.g., npm, PyPI, GitHub Actions). • Experience with adversary emulation frameworks (e.g., Atomic Red Team, Caldera) or running purple-team exercises. • Experience with data engin

View the official posting →

Source: Greenhouse (employer board) First seen: 2026-10-01 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities