InterviewHack.ai
Start free
Jobs / Asana

Staff Detection Engineer

Asana·Warsawsenior

In short

  • →Ingeniero de detección de alto nivel que construye y mantiene reglas de seguridad como código en entornos cloud y SaaS.
  • →Día a día: desarrolla detecciones en Panther, prueba con comportamiento real de atacantes, mejora calidad de alertas y colabora con equipos de respuesta e infra
  • →Lo destacado: las detecciones se gestionan como código de producción, con pruebas, revisión por pull request y despliegue automático en CI/CD.

Fluency in English is required.

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

The questions they'll ask you

1. ¿Cómo estructurarías una regla de detección en Panther para detectar intentos de acceso no autorizado en Okta usando logs de sistema?

2. ¿Qué métricas usarías para evaluar la calidad de una detección y cómo mejorarías una regla con alto ratio de falsos positivos?

3. ¿Cómo integrarías un nuevo flujo de telemetría de SaaS en Panther para que sea usable en detecciones con pruebas unitarias y validación de datos?

🔒 +7 more questions

No card. Upload your resume and the full dossier is ready in ~1 minute.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

💵 USD · Remote · No visa

Not finding what you want? Try Micro1

Micro1 places engineers directly at US companies paying in USD. One vetting, multiple offers — no cold applying.

Get matched by Micro1 →
📬Jobs picked for YOUR resume, every morning on WhatsApp. Free: text “vacantes” and the bot sends your daily matches. Subscribe →

What they ask for

  • ✓8+ años en ingeniería de detección, operaciones de seguridad o caza de amenazas.
  • ✓Habilidades sólidas en Python y fluidez en Git, PRs, pruebas automatizadas y CI/CD.
  • ✓Experiencia comprobada con detección como código (detection-as-code) y gestión del ciclo de vida de reglas.
  • ✓Conocimiento profundo de SIEMs como Panther, Splunk o Elastic Security, incluyendo lenguajes de consulta.
  • ✓Experiencia con telemetría de cloud (AWS/GCP), identidad (Okta) y SaaS, y cómo se manifiestan las tácticas de ataque.
  • ✓Familiaridad con EDR (CrowdStrike, SentinelOne) y uso práctico de MITRE ATT&CK para priorizar cobertura.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

PantherPythonGitCI/CDSplunkElastic SecurityAWSGCPOktaCrowdStrike

Who should you write to at Asana?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

Our Security team keeps Asana's employees, users, and customers safe by proactively addressing threats and fostering a culture of security across our product and operations. We're looking for a Staff Detection Engineer to join our Threat Response team in our Warsaw innovation hub. You'll own how we find threats: the detection logic, the telemetry it runs on, and the pipeline that ships it. Detection here is software. Rules are written as code, tested against real and synthetic attacker behavior, reviewed in pull requests, and deployed through CI/CD. You'll partner with our incident responders, infrastructure, and product teams to make sure that when something bad happens, we see it fast and with high signal. We offer a Contract of Employment (UoP) for our employees in Poland. What you'll achieve • Design, build, and maintain high-fidelity detections across cloud infrastructure (AWS/GCP), identity providers (e.g., Okta), SaaS environments, endpoints, and the software supply chain. • Own our detection-as-code pipeline in Panther: rule structure, unit and integration tests, review standards, and CI/CD deployment, so detection logic is treated as production code. • Map and close coverage gaps against MITRE ATT&CK and the threat model for our environment, prioritizing the techniques most likely to be used against a SaaS company. • Onboard and normalize new telemetry sources , working with infrastructure and IT to make sure the right logs exist, are complete, and are queryable. • Measure and improve alert quality , tracking precision, time-to-triage, and false-positive rates, and tuning or retiring detections that don't earn their keep. • Validate detections against real attacker behavior through purple-team exercises, atomic tests, and emulation, and feed findings back into rule development. • Turn incidents and threat intelligence into detections , partnering with incident responders to convert lessons learned and emerging TTPs into durable coverage. • Build enrichment and automation in our SOAR platform so alerts arrive with the context responders need to act. About you • 8+ years in detection engineering, security operations, or threat hunting , with a track record of building detections that responders actually trust. • Strong Python skills , with hands-on experience in Git workflows, PR-based code review, automated testing, and CI/CD. Go, Bash, or JavaScript/TypeScript is a plus. • Deep experience with detection-as-code , including test-driven detection logic, rule lifecycle management, and deploying rules through CI/CD pipelines. • Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security), including query languages, log schemas, and correlation. • Deep understanding of cloud and identity telemetry , such as AWS, GCP audit logs, Okta system logs, and SaaS audit APIs, and what attacker activity looks like in each. • Working knowledge of EDR tools (e.g., CrowdStrike, SentinelOne) and endpoint telemetry. • Fluency with attacker TTPs and MITRE ATT&CK, and experience using it to drive coverage decisions rather than as a checklist. • Collaborative and pragmatic mindset , with strong communication across technical and non-technical partners, and an instinct for reducing noise rather than adding to it. • Demonstrated curiosity about AI tools and emerging technologies, with willingness to learn and leverage them to enhance productivity, collaboration, or decision-making. Nice to have • Experience detecting softwar

More jobs like this

Remote Security Engineer jobs

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsCompanies hiringFree ATS checkerInterview-English checkSalary checkFree STAR answerResume verdict (Jev)LATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Field Marketing Manager

Asana · San Francisco

→

IT Support Specialist

Asana · Dublin

→

Staff Software Engineer, AI Teammates

Asana · San Francisco

→

Manager, Customer Success

Asana · San Francisco

→