CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Staff Detection Engineer

Asana • Warsaw

Job Description

<p>Our Security team keeps Asana's employees, users, and customers safe by proactively addressing threats and fostering a culture of security across our product and operations.</p> <p>We're looking for a Staff Detection Engineer to join our Threat Response team in our Warsaw innovation hub. You'll own how we find threats: the detection logic, the telemetry it runs on, and the pipeline that ships it. <strong>Detection here is software.</strong> Rules are written as code, tested against real and synthetic attacker behavior, reviewed in pull requests, and deployed through CI/CD. You'll partner with our incident responders, infrastructure, and product teams to make sure that when something bad happens, we see it fast and with high signal.</p> <p>We offer a Contract of Employment (UoP) for our employees in Poland.</p> <h3>What you'll achieve</h3> <ul> <li><strong>Design, build, and maintain high-fidelity detections</strong> across cloud infrastructure (AWS/GCP), identity providers (e.g., Okta), SaaS environments, endpoints, and the software supply chain.</li> <li><strong>Own our detection-as-code pipeline</strong> in Panther: rule structure, unit and integration tests, review standards, and CI/CD deployment, so detection logic is treated as production code.</li> <li><strong>Map and close coverage gaps</strong> against MITRE ATT&CK and the threat model for our environment, prioritizing the techniques most likely to be used against a SaaS company.</li> <li><strong>Onboard and normalize new telemetry sources</strong>, working with infrastructure and IT to make sure the right logs exist, are complete, and are queryable.</li> <li><strong>Measure and improve alert quality</strong>, tracking precision, time-to-triage, and false-positive rates, and tuning or retiring detections that don't earn their keep.</li> <li><strong>Validate detections against real attacker behavior</strong> through purple-team exercises, atomic tests, and emulation, and feed findings back into rule development.</li> <li><strong>Turn incidents and threat intelligence into detections</strong>, partnering with incident responders to convert lessons learned and emerging TTPs into durable coverage.</li> <li><strong>Build enrichment and automation</strong> in our SOAR platform so alerts arrive with the context responders need to act.</li> </ul> <h3>About you</h3> <ul> <li><strong>8+ years in detection engineering, security operations, or threat hunting</strong>, with a track record of building detections that responders actually trust.</li> <li><strong>Strong Python skills</strong>, with hands-on experience in Git workflows, PR-based code review, automated testing, and CI/CD. Go, Bash, or JavaScript/TypeScript is a plus.</li> <li><strong>Deep experience with detection-as-code</strong>, including test-driven detection logic, rule lifecycle management, and deploying rules through CI/CD pipelines.</li> <li><strong>Strong experience with SIEM platforms</strong> (e.g., Panther, Splunk, Elastic Security), including query languages, log schemas, and correlation.</li> <li><strong>Deep understanding of cloud and identity telemetry</strong>, such as AWS, GCP audit logs, Okta system logs, and SaaS audit APIs, and what attacker activity looks like in each.</li> <li><strong>Working knowledge of EDR tools</strong> (e.g., CrowdStrike, SentinelOne) and endpoint telemetry.</li> <li><strong>Fluency with attacker TTPs</strong> and MITRE ATT&CK, and experience using it to drive coverage decisions rather than as a checklist.</li> <li><

Job Reference ID: CF-141111 • Posted on CloudFrame Job Scanner