At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations. As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements What you'll achieve Own Asana's security risk management program: Design and continuously mature a quantitative risk framework — including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds — that enables consistent, data-driven risk decisions across the organization. Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners. Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's
Jobiba hiring network
Security Risk Manager Jobs
3,372 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current security risk manager jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Role Overview You are a senior product leader who wants to shape how AI transforms IT and cyber risk management at scale. In this role, you will own one of the most strategic product areas in a global GRC SaaS platform, defining how organisations identify, assess, and act on cyber risk — and how CISOs and boards get the clarity they need when it matters most. You will set and drive the product vision, roadmap, and outcomes for IT & Cyber Risk on a multi-solution platform used by enterprises worldwide. You will partner closely with engineering, design, data science, and senior leaders to build AI-native capabilities that automate risk detection, prioritisation, and reporting. Your work will have high executive visibility, real strategic weight, and direct impact on how customers manage governance, risk, and compliance. Here’s a breakdown of what you’ll do (not all of it, just the important stuff) Lead the end-to-end product strategy and roadmap for IT & Cyber Risk, aligning to company objectives and broader platform direction. Design and deliver AI-powered features (LLMs, agents, ML models) that automate risk identification, assessment, and reporting for enterprise security and risk teams. Partner with engineering, data science, and design to define technical approaches, ship high-quality releases across web, mobile, and API, and iterate using product analytics. Develop deep market and customer insight by engaging regularly with CISOs, security leaders, and risk managers, and turn those insights into clear product bets. Define, track, and communicate product KPIs, AI performance metrics, and north star outcomes to senior stakeholders, including business cases for major investments. Work cross-functionally with Sales, Customer Success, Professional Services, and Marketing to ensure successful launches and adoption of new IT & Cyber Risk capabilities. These are the essentials you’ll need to get an interview 7+ years of product management experience, includi
Job Requisition ID # 26WD100179 Position Overview The Trust Risk Manager leads the Trust Risk Program at Autodesk and manages a multidisciplinary organization that includes Third-Party Risk Management as well as senior risk professionals. T rust Risk at Autodesk is an established team and program . W e are looking for a leader with the lived experience of operationalizing a risk program that is Trusted by leaders and executives to drive risk-based decisions in the areas of Trust – Security, Privacy, Trusted AI, and Resilience. This individual will report directly to the Director of Trust Governance, Risk, and Compliance. The successful candidate will bring deep expertise in at least one Trust risk domain and sufficient breadth across security, privacy, trusted AI, resilience, and third-party risk to integrate specialist perspectives into an enterprise risk view. Operationalizing risk management and working with executive stakeholders is as much of an art as it is science . Th e Trust Risk Manager needs to have lived, practical experience to g
The Assurance, Risk and Compliance (ARC) Initiatives team at MongoDB owns the governance and delivery of key cross-functional security risk and compliance initiatives. The team designs and executes programs that support compliance audits, risk assessments, common control frameworks, operating cadences, and executive reporting that strengthen the organization’s assurance, risk management and compliance objectives. The policy and controls governance pillar is responsible for the structure, standards and operating mechanisms that keep MongoDB’s security policies, standards, procedures, and controls governance processes current, aligned, auditable and scalable across the organization. This includes ownership of the policy lifecycle, common controls framework governance, issue management, and the review cadences and cross-functional coordination needed to maintain strong governance maturity and audit readiness. This role sits under the Assurance, Risk and Compliance function within the Global Security Office and reports to the Director of ARC Initiatives. This role will be based remotely in the United States Responsibilities: Scope of Ownership Policy governance program ownership, including policy lifecycle management, documentation standards, review and approval cadences, change tracking, and exception governance Controls governance ownership, including common controls framework lifecycle management, control harmonization, framework mapping, and processes that support audit readiness and scalable control oversight Governance over supporting systems and workflows, including Jira, GRC tooling, documentation repositories, and reporting structures, that enable consistent execution and visibility Issue management and remediation governance, including intake, triage, tracking, and reporting for timely closure of findings Executive-ready reporting and metrics for policy health, controls maturity, policy exceptions and broader program effectiveness Program Leadership Own
Who Are We HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools. HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations. Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank. Responsibilities Governance & Strategy: Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures. Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals. Providing regular reports to the Board of Directors and executive management on the state of cybersecurity. Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress. Oversee the information security budget, ensuring resources are allocated effectively to manage risk. Risk Management: Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program. Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks. Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented. Manage the vendor risk management program, assessing the security posture of
At Freddie Mac, our mission of Making Home Possible is what motivates us, and it’s at the core of everything we do. Since our charter in 1970, we have made home possible for more than 90 million families across the country. Join an organization where your work contributes to a greater purpose. Position Overview: The Cyber Security team at Freddie Mac is searching for a strong data analyst to collaborate on developing and administering data security policies as well as safeguarding information, evaluating existing data security procedures and identifying new areas of risk for Freddie Mac. If this role sounds like a fit for your skill set, please read on, apply and learn why there is #MoreatFreddieMac ! Our Impact: We develop and train the enterprise on relevant Identity and Access Management best practices, develop and support automated IAM processes, and develop and implement ongoing IAM efficiency improvements with limited oversight by managers. The role will work closely with Enterprise partners and security control owners on IAM automation development activities and alignment of IAM processes with InfoSec maturity targets as described in the InfoSec Strategy. Your Impact: Senior Data Analyst who can develop and implement new and updated business process automation for all Identity and Access Management activities. Develop and proposes strategies to reduce security risk in the organization by implementing procedural prevention, detection, and response measures, while still enabling positive business outcomes. Comfortable supporting ad hoc data retrieval and analysis requests using SQL queries and Copilot/Excel . Creating audit-ready reference documentation. This role will allow for and support rapid AI-based extrapolation/replication of these services as future automated IAM microservices. Qualifications: Typically, 5 - 7 years of rel
A BOUT TIDE At Tide, we help SMEs save time and money in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions, from invoicing to accounting. Tide is transforming the small business banking market and now supports over 2 million members globally across the UK, India, Germany and France. Using advanced technology, all solutions are designed with SMEs in mind. With quick onboarding, low fees and innovative features, we thrive on making data driven decisions to serve our mission: to help SMEs save time and money so they can get back to doing what they love. Tide facts: Tide is available for UK, Indian, German and French SMEs Over 2 million members across UK and India Over $300 million raised in funding Over 2,800 Tideans globally Recognised with Great Place to Work certification three years in a row, and among India’s Top 50 Best Workplaces in Banking, Financial Services, and Insurance in 2026 We have offices in Central London, with a member support and technology centre in Sofia, Bulgaria, technology centres in Serbia, Romania, Lithuania and Hyderabad and offices in Gurugram, New Delhi, Berlin, Paris and Luxembourg ABOUT THE ROLE As an Information Security Compliance Manager, you will be a seasoned information security and risk professional with unrivalled expertise in the Indian regulatory landscape for financial institutions. You excel at managing regulatory requirements, confidently representing Tide to local regulators, and ensuring compliance with mandatory security and data standards for Tide’s India operations. Core responsibilities will include: Primary Regulatory Liaison: Acting as the primary point of contact and representative for Tide Risk and Compliance when interacting with Indian financial regulators (e.g., RBI, CERT-IN) and key local partners on information security topics. Regulatory Compliance Ownership: Owning and
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . Coinbase is looking for a Senior Manager, Security Audit to lead the Internal Audit team's global coverage of information security, cybersecurity, and infrastructure/application security. Reporting to the Global Head of Internal Audit, you'll own the security audit portfolio, spanning identity and access management, threat detection, incident response, cloud security, application security, and crypto-native controls (wallets, cold storage, key management), while managing a small team and carrying your own book of complex audits. What you'll do: Own and lead Coinbase's global security audit portfolio covering IAM, threat detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight Partner with Security Engineering, Detection & Response, and AppSec teams as the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity. Manage and develop a team of security auditors while personally leading high-complexity, high-risk security engagements across multiple jurisdictions. Synthesize complex technical security findings into clear, risk-prioritized reports for executive leadership, the Audit Committee, and the Board. Drive proactive i
About the role We’re looking for an engineering manager to lead a team building software systems that detect and prevent harmful misuse of frontier AI models—before incidents occur. This is a builder’s role: you’ll lead engineers shipping production services, detection pipelines, and mitigation mechanisms that protect frontier model integrity and reduce high-severity misuse risk. While this work intersects with frontier model development, security and risk, we’re explicitly seeking someone with a software engineering foundation who is comfortable building reliable systems that can operate at billions of users scale. In this role you will: Lead a team of software engineers building detection + mitigation systems for frontier model misuse, with an emphasis on model IP protection / distillation detection and emerging risk surfaces from autonomous agents. Set the technical roadmap and execution strategy: prioritize, design, ship, iterate, measure impact. Build production systems: services, pipelines, tooling, instrumentation, and automation that scale with frontier model usage. Partner deeply with Research and Product to translate evolving model capabilities into concrete tests, signals, and mitigations that can be deployed at scale. Drive strong engineering fundamentals: architecture, reliability, monitoring, performance, and operational excellence. Hire and grow an exceptional team across backend, data systems, and applied ML engineering domains as needed. Anticipate what breaks at scale as agentic workflows become more capable. You might thrive in this role if you: Experience building systems in adversarial, fast-evolving environments Are comfortable with ambiguity and novelty Have experience adjacent to security (e.g., abuse prevention, fraud, integrity, platform defense, auth/identity, malware/spam, adversarial environments) Communicate clearly and build trust quickly with senior stakeholders—pragmatic, collaborative, and calm under scrutiny. Significant experience
About the Team Corporate Security helps protect OpenAI's people, offices, events, and operations through practical and risk-informed security programs. The team partners closely with Workplace, Legal, People/HR, Resilience & Safety, Executive Operations, GSOC, regional leaders, vendors, and building management. About the Role OpenAI is seeking a Paris-based Security Operations Manager to lead corporate and physical security operations for Paris, provide primary support for Brussels, and coordinate regional support for Munich, Zurich, and other European cities as needed. This person will be a trusted security partner for local teams, regional stakeholders, vendors, building management, and global Corporate Security peers. In this role, you will: Lead day-to-day physical security operations for the Paris office and supporting Brussels operations. Coordinate regional security support for Munich, Zurich, and other European cities where business activity, events, travel, or executive visits require coverage. Manage practical security controls, including access management, visitor workflows, vendor coordination, incident response, emergency readiness, and site security documentation. Partner with Workplace, building management, Legal, People/HR, EHS/Resilience, GSOC, Executive Operations, and local leadership to keep security effective, locally appropriate, and employee-friendly. Support event and executive visit planning with clear escalation paths, stakeholder alignment, and proportionate risk mitigation. Improve vendor performance, operational standards, reporting, and remediation tracking. You might thrive in this role if you have: 8+ years of experience in corporate security, physical security operations, protective services, emergency management, public service, military, law enforcement, or a closely related operational field. Experience leading physical security operations in a modern office environment, ideally in technology, professional services, financial
Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. As the Logistics Security Program Manager for EMEA, this role is an essential part of Micron’s Global Security team. The person leads the management and continuous refinement of the company’s important logistics security efforts across the EMEA area. This position serves as the regional authority, advancing risk-focused security methods that protect high-value shipments, improve supply chain durability, and lower transportation security risks in intricate multimodal logistics networks. As a senior individual contributor, the Logistics Security Program Manager takes charge of regional program initiatives on their own. They apply solid judgment to shifting threat conditions and collaborate with colleagues across functions and external partners to produce security results. The position involves balancing security, operational efficiency, and business continuity while transforming regional risks into scalable, practical controls that advance cargo visibility, shipment protection, and incident readiness. Responsibilities: Act as the EMEA logistics security authority, guiding the creation and implementation of risk-focused security programs for valuable and sensitive shipments involving carriers, freight forwarders, and logistics providers. Develop, apply, and manage shipment security controls, including tracking, telematics, geofencing, chain of custody, tamper detection, monitoring, critical issue handling, recovery processes, and carrier compliance requirements. Conduct carrier, route, l
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As the Senior Manager of the Security Posture Management (SPM) team within the Product Security Department , you lead the team that secures GitLab's own software factory: the estate we build and ship from. Your team drives comprehensive, governed rollouts of GitLab's security capabilities across every project, applying our own product the way our customers do, and builds proactive software supply chain security as a first-class capability within Product Security. This is Customer Zero work with real reach. Where the team hits friction adopting our own features at scale, that signal goes straight to Produc
The Security team is responsible for protecting Asana’s employees, users, and customers . We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements . We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations . We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw . In this role, you will own and grow a team spanning red team operations, application security, and vulnerability management, driving both the strategic direction and the hands-on execution of our offensive security program . You will work directly with engineering leadership, legal, and senior stakeholders to ensure our security posture is contin uously tested, measured, and improved . This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations . Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy . Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team . Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment . Perform clo
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As Senior Manager, Internal Audit focused on Audit Automation & Technology Risk, you’ll anchor our Internal Audit operations in Bangalore, India, and lead three connected areas: audit automation and innovation, people and operations for our India hub, and support of our technology risk audit program. Reporting to the VP, Internal Audit, you’ll help position Internal Audit as a strategic partner that gives leaders practical risk insight and helps the business improve. You’ll pioneer data analytics, artificial intelligence (AI)-assisted workflows, and automation across the Internal Audit function; suppo
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Product Manager , you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it. You will own the full loop: detect a secret with high precision, tell the customer whether it i
Get new security risk manager jobs by email
Daily job updates · Unsubscribe anytime