About the role We’re looking for an engineering manager to lead a team building software systems that detect and prevent harmful misuse of frontier AI models—before incidents occur. This is a builder’s role: you’ll lead engineers shipping production services, detection pipelines, and mitigation mechanisms that protect frontier model integrity and reduce high-severity misuse risk. While this work intersects with frontier model development, security and risk, we’re explicitly seeking someone with a software engineering foundation who is comfortable building reliable systems that can operate at billions of users scale. In this role you will: Lead a team of software engineers building detection + mitigation systems for frontier model misuse, with an emphasis on model IP protection / distillation detection and emerging risk surfaces from autonomous agents. Set the technical roadmap and execution strategy: prioritize, design, ship, iterate, measure impact. Build production systems: services, pipelines, tooling, instrumentation, and automation that scale with frontier model usage. Partner deeply with Research and Product to translate evolving model capabilities into concrete tests, signals, and mitigations that can be deployed at scale. Drive strong engineering fundamentals: architecture, reliability, monitoring, performance, and operational excellence. Hire and grow an exceptional team across backend, data systems, and applied ML engineering domains as needed. Anticipate what breaks at scale as agentic workflows become more capable. You might thrive in this role if you: Experience building systems in adversarial, fast-evolving environments Are comfortable with ambiguity and novelty Have experience adjacent to security (e.g., abuse prevention, fraud, integrity, platform defense, auth/identity, malware/spam, adversarial environments) Communicate clearly and build trust quickly with senior stakeholders—pragmatic, collaborative, and calm under scrutiny. Significant experience
Role overview
Job description
At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations. As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are M
…What they are looking for
Skills & requirements
Qualification
About you 7+ years of experience in information security with a strong focus on security risk management and GRC
Department · Security Operations
Hiring company
Asana
We are looking for enthusiastic collaborators who are passionate about their craft to be a part of our journey building technology that is a force for positive change in the world. Make an impact by helping us achieve a powerful mission while developing your career.
Keep exploring
Similar active roles
Fresh roles matched to this title and market.
About the Team The Corporate Security team is responsible for safeguarding all OpenAI employees and executives. Our mission is to create a secure, resilient environment that allows our teams to focus on their work without risk or disruption. We manage physical security operations across offices, events, and global initiatives, partnering closely with internal teams and external agencies to stay ahead of emerging threats. About the Role As a Corporate Security Manager , based in our San Francisco office, you will lead day-to-day security operations while supporting the development of global physical security strategies, policies, and procedures. You will work cross-functionally to maintain a strong and adaptive security posture, manage vendor security teams, and serve as a key liaison with law enforcement and security partners. This position requires hands-on experience in corporate security operations. This role typically involves 4–5 days in the office each week . In this role, you will: Office Security: Develop, implement, and manage physical security measures, including policies, systems, and vendor relationships, to protect employees and visitors in the San Francisco offices. International Offices: Support the International Director to safeguard OpenAI’s global footprint by assisting with security policy writing, consistent with US and main office policy and procedures, including ongoing mitigation strategies. Events: Support local events when needed and work with the resilience team on updating policy and procedures that involve the GSOC’s support. Partnerships & Stakeholder Engagement: Establish and strengthen relationships with local law enforcement agencies, peer security organizations, and other external partners to stay current on emerging risks. Policy Development & Compliance: Be the primary point of contact for the Corporate Security Operations team for global policy and procedures. Support and contribute to all the Corp Sec pillars as needed, f
About the Team Safety Systems manages the complete lifecycle of safety efforts for OpenAI’s frontier models, ensuring our models are deployed responsibly and have a positive impact on society. Our work spans diverse research and engineering initiatives—from system-level safeguards and model training to evaluation and red-teaming—all aimed at mitigating misuse, misalignment, and maintaining our high bar for safety. We lead OpenAI's commitment to developing and deploying safe Artificial General Intelligence (AGI), fostering a culture of trust, responsibility, and transparency. Our goal is to continuously learn from deployments, distribute AI’s benefits widely, and ensure that powerful tools remain aligned with human values and safety considerations. Within Safety Systems, the Model Policy team works to ensure that frontier models behave safely and reliably in real-world environments by designing policies that define safe model behavior. Some of our publications include: Safety at every step OpenAI GPT6 System Card OpenAI Model Spec About the Role We’re hiring a Model Policy Manager to shape model behavior for U.S. government use, with a focus on national security applications. You’ll define nuanced policies and translate them into training and evaluation criteria, helping models navigate high-stakes scenarios while preserving their usefulness and capabilities. In this role, you will: Develop model policies that guide safe and useful behavior. Build evaluations, identify policy gaps and model failures, and use findings to improve policies and training. Work with research, engineering, and domain experts to support safe, reliable deployment. You might thrive in this role if you: Bring relevant experience in AI safety, policy, or risk assessment. Have strong judgment and can turn complex safety questions into clear, practical policies. Have the technical fluency to work hands-on with model data and evaluations. Are motivated by OpenAI’s mission and the responsible use of
About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. About the Role We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected. You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program. This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program. You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD confor
About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership
Drata is building the trust layer between great companies - automating compliance, managing risk, and helping organizations prove trust continuously as they scale. We're Dratanauts: a global crew of 600+ professionals united by a culture that rewards integrity, ownership, and raising the bar, no matter where in the world we're working from. Why Join the Drata Team? At Drata, you're not maintaining legacy compliance software - you're building the agentic AI platform defining what trust looks like for the next generation of companies. Here's what makes the work itself worth showing up for: Problems without a playbook: You'll work at the edge of AI and security, building agentic governance, continuous compliance, and real-time trust verification to solve problems that don't have an established answer yet. You're writing it as you go. Real ownership, not just process: Our values center on owning outcomes and raising the bar, not checking boxes. You're expected to have opinions and back them. A seat at the table: Your perspective is unique and valued. Open debate and diverse viewpoints are built into how decisions actually get made here, at every level. Growth at rocketship speed: Drata is scaling fast, which means scope grows fast too. High performers get more ownership, visibility, and experience. A crew, not just coworkers: Dratanauts consistently describe a "come as you are" culture with sharp, curious people—the kind of team that makes hard problems genuinely fun to solve. See what they say here and follow us on LinkedIn for company news, employee stories, and career updates. Job Summary: As Revenue Operations Manager, you’ll help build the operational foundation for a fast-scaling GTM team. What you'll do: Own and operate some of our core GTM systems — including Salesforce, sales engagement, marketing automation, and BI tools. Translate GTM requirements into scalable workflows, automations, and processes across Sales, Marketing, Partnerships, and Account Management
🔔 Get job alerts
New Security Risk Manager jobs in San Francisco, straight to your inbox.
No spam · Unsubscribe anytime