
Asana · Warsaw
At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana’s employees, users, and customer...
At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana’s
employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and
fostering a culture of security throughout our product and operations. We are a team of security engineers and risk and compliance
practitioners who build innovative safeguards and collaborate across the organization to build and maintain trust at scale.
As the Third Party Risk Management Lead, you will be responsible for building and running Asana’s Third Party Risk Management
(TPRM) program. You will own the end-to-end lifecycle of vendor security risk — from initial due diligence and risk tiering
through ongoing monitoring and remediation. You will work closely with Procurement, Legal, Privacy, and Engineering teams to
ensure that our third-party relationships are effectively assessed, tracked, and managed.
This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday,
and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of
work you do, and your recruiter can share more about the in-office requirements.
Our employees in Poland are employed under a contract of employment.
What you’ll achieve
managing third-party vendors and service providers. Establish risk tiering criteria, assessment workflows, and governance
processes that scale with business growth.
SOC 2 reports, ISO 27001 certifications, security questionnaires (SIG, CAIQ), and other relevant documentation. Identify gaps
and work with vendors to remediate findings.
to prioritize remediation, and facilitate formal risk acceptance processes where appropriate. Ensure findings are documented
and resolved in a timely manner.
including periodic reassessments, breach notifications, and security posture updates. Maintain an accurate and up-to-date
vendor risk inventory.
security-related clauses in vendor agreements, data processing addenda, and subprocessor agreements, ensuring alignment with
Asana’s policies and obligations.
and relevant stakeholders. Support audit and compliance activities by providing evidence of TPRM program effectiveness,
including for SOC 2, ISO 27001, and customer audits.
assessments and risk decisions that span multiple regions.
About you
certifications, penetration test summaries, etc.).
SaaS organizations.
effectiveness.
technical and non-technical audiences.
productivity, collaboration, or decision-making.
At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical
to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage
you to apply.
What we’ll offer
)
For this role, the estimated base salary range is between 22,750 - 27,250 PLN gross per month (subject to all taxes and necessary
deductions). The actual base salary will vary based on various factors, including market and individual qualifications objectively
assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be
modified.
In addition to base salary, your compensation package may include additional components such as equity and sales incentive pay
(for most sales roles), and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn
more about the total compensation and benefits for this role.
#LI-Hybrid
About us
Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most
important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes,
and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the
best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+
offices all over the world, we are always looking for individuals who care about building technology that drives positive change
in the world and a culture where everyone feels that they belong.
Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.
We are seeking a Dynamics 365 Finance & Operations (D365 F&O) Developer with 3–5 years of experience designing, developing, and supporting solutions within the D365 F&O platform. This role will focus on configuration, customization, and development within D365 F&O to support finance and accounting operations. The developer will work on initiatives such as optimizing accounting workflows, configuring new legal entities, developing localizations, and building financial reporting solutions to support business requirements across regions. In addition, this role will provide day-to-day administrative support for the platform and collaborate with finance and business stakeholders to deliver scalable ERP solutions. Responsibilities * Design, develop, and implement solutions within D365 F&O. * Configure and customize system functionality to support finance and accounting processes. * Optimize and automate accounting workflows within the platform. * Support and enhance financial reporting using Management Reporter. * Configure and manage legal entities, security roles, and system settings. * Develop and maintain localizations to support local business and regulatory requirements. * Work with Microsoft’s Common Data Model (CDM) and Data Management Framework (DMF) and data entities to support integrations, data consistency, and custom reporting. * Provide day-to-day system administration and user support, including troubleshooting and issue resolution. * Collaborate with business stakeholders to gather requirements and translate them into technical solutions. * Support system enhancements, integrations, and platform upgrades. Qualifications * 3–5 years of experience developing solutions in D365 F&O with a working knowledge of its architecture. * Experience with D365 F&O configuration and customization, including extensions and integrations. * Strong proficiency and development experience with X++. * Experience supporting financial reporting with Management Reporter. * Experience developing localizations within ERP systems. * Working experience with Microsoft Common Data Model (CDM) and Data Management Framework (DMF). * Understanding of ERP financial modules and accounting workflows. * Knowledge of integrations using REST / SOAP * Strong analytical, troubleshooting, and communication skills. Preferred * Experience with Power Platform (Power Apps, Power Automate) and Azure Services. * MB-500 certification (Dynamics 365: Finance and Operations Apps Developer Associate).
At Morgan & Morgan, the work we do matters. For millions of Americans, we’re their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People. About the Role Morgan & Morgan is the largest plainti/-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Our scale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases. We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability. We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms. This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles through pragmatic guardrails, clear risk ownership, and modern security architecture. Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent—ensuring our teams can fight for clients without distraction, delay, or doubt. This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust. Key Responsibilities Security Strategy & Risk Leadership • Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale • Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment • Translate cyber risk into clear business impact for executive leadership and the Board • Guide security investment decisions that balance velocity, resilience, and client trustRisk Management & Compliance • Lead firm-wide risk assessments, threat modeling, and control maturity evaluations • Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning • Partner closely with Legal, Privacy, and Compliance leaders to ensure: • Protection of sensitive client and case data • Defensible security practices suitable for litigation discovery • Alignment with regulatory, contractual, and ethical obligations • Oversee third-party and vendor security risk management at national scale Security Architecture & Engineering Enablement • Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology • Embed security into: • Agile software development and CI/CD pipelines • Cloud-native platforms and SaaS ecosystems • AI-enabled legal workflows and analytics platforms • Implement Zero Trust principles using pragmatic, developer-friendly controls • Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys Security Operations • Oversee security operations including: • Identity & Access Management (IAM) • Endpoint, network, and cloud security • Security monitoring, detection, and response • Continuously improve detection, response time, and operational resilience • Ensure security operations remain resilient and e/ective during high-volume, time- sensitive legal operations • Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyersLeadership & Culture • Build, lead, and mentor a high-caliber, hands-on security organization • Establish strong operating models between Security, IT, Engineering, and the business • Set clear expectations and a high bar for execution, accountability, and follow-through across the security function • Champion a culture where security is designed in early, not bolted on late • This role requires a leader who is comfortable operating close to the technology engaging directly with teams, systems, and incidents when needed • Act as a visible, trusted executive leader approachable, decisive, and credible Required Experience • 10+ years in cybersecurity, including senior leadership roles in large, complex environments • Proven success leading security programs in high-data-sensitivity, fast-moving organizations • Demonstrated ability to communicate cyber risk clearly to executive leadership and Boards • Strong working knowledge of: • NIST Cybersecurity Framework (CSF) and/or ISO 27001 • Zero Trust architecture • Incident response and crisis leadership • Cloud and SaaS security at scaleExecutive Mindset • Business-first approach to security focused on outcomes, not checklists • Comfort making tradeo/s and defending decisions at the executive level • Calm, credible leadership during high-pressure situations • High integrity, sound judgment, and strong ethical foundationPreferred Qualifications • CISSP, CISM, or equivalent credentials • Experience supporting AI platforms, analytics, or large-scale digital transformation • Proven partnership with CIOs, General Counsel, and Compliance leadership • Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, or similar) Why Morgan & Morgan • Unmatched scale: Secure operations across 140+ offices nationwide • Real impact: Protect systems supporting more than $30 billion recovered for clients • Innovation focus: Security embedded in rapid software delivery and AI-driven legal tech • Executive influence: Direct involvement in firm-wide risk and investment decisions • Leadership commitment: Security treated as a strategic business capability What We Offer Morgan & Morgan offers a people-first environment grounded in high performance. We provide comprehensive medical, dental, vision, and mental health benefits; generous paid time off; strong onboarding and leadership support; and a culture that values accountability, growth, and results. You’ll work alongside driven professionals who expect excellence and support one another in achieving it. Benefits Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff. For full-time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan, paid time off and paid holidays. Equal Opportunity Statement Morgan & Morgan provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. E-Verify This employer participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact Department of Homeland Security (DHS) or Social Security Administration (SSA) so you can begin to resolve the issue before the employer can take any action against you, including terminating your employment. Employers can only use E-Verify once you have accepted a job offer and completed the I-9 Form. Privacy Policy Here is a link [https://www.forthepeople.com/privacy-policy/] to Morgan & Morgan's privacy policy.
Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! Figma's GRC team helps build and maintain trust with our users, regulators, business partners, and the organizations that rely on Figma every day. We partner across the company to strengthen security, manage risk, maintain compliance, and scale the programs that support our continued growth. We're growing our team and looking for security, risk, and compliance professionals across several disciplines. Whether your expertise is in compliance, risk management, governance, GRC tooling, or customer trust, you'll have the opportunity to build programs, improve processes, and help shape how Figma scales security and trust. Roles we hire for on this team: * Compliance Management * Lead compliance and certification programs across security and regulatory frameworks * Manage audit cycles, partner with external assessors, and drive audit readiness initiatives * Improve controls, processes, and evidence management practices across the organization * Security Risk Management * Build and maintain risk and controls frameworks that support Figma's security posture * Assess, prioritize, and communicate security risks across the business * Develop third-party risk management strategies and enterprise risk reporting programs * Policy & Governance * Manage the lifecycle of organizational security policies, standards, and procedures * Drive policy awareness and stakeholder engagement across the company * Ensure governance practices align with regulatory requirements and business objectives * GRC Platforms & Enablement * Select, implement, and optimize GRC platforms and supporting workflows * Scale evidence collection, reporting, and program management capabilities * Identify opportunities to automate and streamline GRC operations * Customer Trust * Support customer trust and business enablement activities across the sales lifecycle * Manage security knowledge bases, customer-facing documentation, and trust publications * Respond to customer security inquiries, audits, and questionnaires This is a full time role that can be held from one of our US hubs or remotely in the United States. WHAT YOU'LL DO AT FIGMA: * Lead compliance programs across frameworks such as SOC 2, ISO 27001, FedRAMP, SOX ITGC, GDPR, and NIS2 * Manage external audits and certification activities while partnering with auditors and assessors * Build and maintain risk and controls frameworks, including common control frameworks that support multiple certifications * Conduct risk and gap assessments and drive remediation efforts across technical and business stakeholders * Improve control effectiveness and operational efficiency through rationalization and process optimization * Implement and optimize GRC platforms that scale evidence collection and program management * Maintain security policies and governance processes that align with organizational risk objectives * Support customer trust initiatives, including security questionnaires, audits, and customer-facing security communications We’d love to hear from you if you have: * 4+ years of experience in information security, compliance, risk management, or a related field * Hands-on experience supporting security and compliance frameworks such as SOC 2, ISO 27001, FedRAMP, PCI-DSS, or SOX ITGC * Experience leading or supporting audits and partnering with external assessors * Demonstrated ability to conduct assessments, drive remediation efforts, and manage cross-functional initiatives * Exceptional written and verbal communication skills across technical, business, and executive audiences * Demonstrated ability to improve processes, manage competing priorities, and build strong cross-functional partnerships While it’s not required, it’s an added plus if you also have: * Operated in a public company environment with SOX ITGC requirements * Supported FedRAMP authorization, SSP development, 3PAO coordination, or continuous monitoring activities * Earned security or risk certifications such as CISA, CISSP, CISM, or CRISC * Implemented or administered GRC platforms such as Vanta, Drata, or similar tools * Scaled security, compliance, or risk programs in a high-growth environment At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you’re excited about this role but your past experience doesn’t align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles. Pay Transparency Disclosure If based in Figma’s San Francisco or New York hub offices, this role has the annual base salary range stated below. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information. Figma offers equity to employees, as well a competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave & reproductive or family planning support, mental health & wellness benefits, generous PTO, company recharge days, a learning & development stipend, a work from home stipend, and cell phone reimbursement. Figma also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Figma’s compensation and benefits are subject to change and may be modified in the future. Annual Base Salary Range: $153,000—$296,000 USD At Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities. Examples of accommodations include but are not limited to: * Holding interviews in an accessible location * Enabling closed captioning on video conferencing * Ensuring all written communication be compatible with screen readers * Changing the mode or format of interviews To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding. By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with Figma's Candidate Privacy Notice.