Talent.com
Postman
Staff Security EngineerPostman • San Francisco, United States
Staff Security Engineer

Staff Security Engineer

Postman • San Francisco, United States
30+ days ago
Job type
  • Full-time
Job description

Who Are We?

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

The Opportunity

As a Staff Security Engineer at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.

What You’ll Do:

  • Security Architecture Design : Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies.

  • Threat Modeling & Risk Assessment : Lead threat modeling and risk assessment to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.

  • Technology Review & Evaluation : Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.

  • Security Strategy : Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.

  • Incident Response : Work closely with the SOC to understand gaps in product architecture.

  • Mentorship & Leadership : Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.

About You:

Experience :

  • 15+ years in a security architecture role with a focus on software products and platforms.
  • Experience working within fast-paced, cloud-native environments.
  • Proven experience with securing distributed systems, microservices, and APIs.
  • Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR)
  • Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.
  • In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud

Communication & Leadership :

  • Strong ability to communicate complex security concepts to both technical and non-technical stakeholders.
  • Experience working cross-functionally with product, engineering, and operations teams.
  • Proven leadership in driving security initiatives and integrating security into product development lifecycles.

Preferred Skills:

  • Experience with API security, including OAuth, JWT, and OpenID Connect.

  • Knowledge of container security (Docker, Kubernetes).

  • Familiarity with security automation tools and methodologies (e.g., SAST, DAST, RASP).

  • Technical industry certifications such as OSCP, GPEN etc.

Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

What Else?

If the role is based in the greater San Francisco area, and the we are offering a base salary range of $250,000 to $350,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.

Equal Opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

Apply Now{"@context":"http://schema.org","@type":"JobPosting","datePosted":"2024-10-25","description":"Who Are We?\nPostman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.\nWe highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.\nThe Opportunity\nAs a Staff Security Engineer at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.\nWhat You’ll Do:\n\n\n\nSecurity Architecture Design: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies.\n\n\nThreat Modeling & Risk Assessment: Lead threat modeling and risk assessment to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.\n\n\nTechnology Review & Evaluation: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.\n\n\nSecurity Strategy: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.\n\n\nIncident Response: Work closely with the SOC to understand gaps in product architecture. \n\n\nMentorship & Leadership: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.\n\n\nAbout You:\nExperience:\n\n15+ years in a security architecture role with a focus on software products and platforms.\nExperience working within fast-paced, cloud-native environments.\nProven experience with securing distributed systems, microservices, and APIs.\nDemonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR)\nHands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.\nIn-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud\n\nCommunication & Leadership:\n\nStrong ability to communicate complex security concepts to both technical and non-technical stakeholders.\nExperience working cross-functionally with product, engineering, and operations teams.\nProven leadership in driving security initiatives and integrating security into product development lifecycles.\n\nPreferred Skills: \n\n\nExperience with API security, including OAuth, JWT, and OpenID Connect.\n\n\nKnowledge of container security (Docker, Kubernetes).\n\n\nFamiliarity with security automation tools and methodologies (e.g., SAST, DAST, RASP).\n\n\nTechnical industry certifications such as OSCP, GPEN etc.\n\n\nOur Values\nAt Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.\nWhat Else?\nIf the role is based in the greater San Francisco area, and the we are offering a base salary range of $250,000 to $350,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.\nEqual Opportunity\nPostman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.\n","title":"Staff Security Engineer - San Francisco","validThrough":"2024-11-24","employmentType":"FULL_TIME","image":"https://assets.getpostman.com/common-share/postman-platform-for-api-development-social-card.jpg","hiringOrganization":{"@type":"Organization","name":"Postman","sameAs":"https://www.postman.com","logo":"https://assets.getpostman.com/common-share/postman-platform-for-api-development-social-card.jpg"},"baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","value":"competitive","unitText":"SALARY"}},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","streetAddress":"201 Mission Street, Suite 2375","addressLocality":"San Francisco","addressRegion":"CA","postalCode":"94105","addressCountry":"US"}}}
Create a job alert for this search

Staff Security Engineer • San Francisco, United States

Similar jobs

Remote Platform Security Engineer

Owner.com, Inc.San Francisco, CA, United States
Remote
Full-time

A leading technology firm is seeking a remote Platform Security Engineer to enhance the security of their cloud infrastructure and develop alerting capabilities.You will work with cross-functional ... Show more

 • Promoted

Remote Senior Security Engineer, DevSecOps Content

Practical DevSecOpsSan Francisco, CA, United States
Remote
Full-time

A leading security training provider is seeking a Senior Security Engineer for their content engineering team.This role supports security professionals, builds hands-on content, and integrates secu... Show more

 • Promoted

Security Systems Engineer (Remote)

Cisco Systems, Inc.San Francisco, CA, United States
Remote
Full-time

The application window is expected to close on 10 / 28 / 2025.Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.AI at CiscoWith Cis... Show more

 • Promoted

Remote Corporate Security Engineer (Senior / Staff)

P2PSan Francisco, CA, United States
Remote
Full-time

A leading technology company is searching for a Senior / Staff Security Engineer to enhance the security of its corporate infrastructure.This role involves designing and managing security for corpo... Show more

 • Promoted

AI Security Engineer - Red Team (United States, Remote)

Lakera IncSan Francisco, CA, United States
Remote
Full-time

We're looking for an AI Security Engineer to join our Red Team and help us push the boundaries of AI security.You'll lead cutting-edge security assessments, develop novel testing methodologies, and... Show more

 • Promoted

Remote Lead AI Security Engineer - Autonomous Agents

HyperproofSan Francisco, CA, United States
Remote
Full-time

A leading cybersecurity firm in San Francisco is looking for an experienced AI engineer to design and build intelligent autonomous security testing agents.The role requires 8years of engineering ex... Show more

 • Promoted

Senior Security Engineer - Large-Scale Web, Remote

DshieldSan Francisco, CA, United States
Remote
Full-time

A nonprofit organization is looking for a Senior Software Engineer to enhance security features protecting Wikipedia and its projects.You will work hands-on with engineers and product managers to d... Show more

 • Promoted

Industrial Network Security Engineer - Remote

IBM ComputingSan Francisco, CA, United States
Remote
Full-time

A leading technology consulting firm is seeking a candidate for a role focused on supporting MES solution deployments and solving technical issues related to process automation in manufacturing.Thi... Show more

 • Promoted

Senior Software Engineer, Security (Remote)

MAP SSG IncSan Mateo, CA, United States
Remote
Full-time

About the Role :We are seeking an experienced Software Engineer to join our security team.This role focuses on designing, implementing, and deploying security solutions and guardrails across our ap... Show more

 • Promoted

Remote Cloud Security Engineer -- IAM & Compliance

Parafin Inc.San Francisco, CA, United States
Remote
Full-time

A financial technology company in San Francisco is seeking an experienced security-focused engineer.The ideal candidate will lead security efforts, ensuring a secure infrastructure across cloud env... Show more

 • Promoted

Senior Security Engineer - FinTech DevSecOps (Remote)

Modern Treasury CorpSan Francisco, CA, United States
Remote
Full-time

A financial technology company is seeking a Security Engineer to design and implement security controls for their payment infrastructure.This role involves leading application security, enhancing c... Show more

 • Promoted

Product Security Engineer Cloud and Infrastructure

1X Technologies ASSan Carlos, CA, US
Full-time

Product Security Engineer, Cloud & Infrastructure.We build humanoid robots that work alongside people to solve labor shortages and create abundance.As a Product Security Engineer focused on clo... Show more

Remote Senior Application Security Engineer - Zetachain

ZetachainSan Francisco, CA, United States
Remote
Full-time

Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program.The ideal candidate will be responsibl... Show more

 • Promoted

Remote Platform Security Engineer - Cloud & SIEM

AkkaSan Francisco, CA, United States
Remote
Full-time

A technology company is seeking a hands-on Platform Security Engineer to architect and maintain security solutions.The candidate will partner with teams to build secure services and improve securit... Show more

 • Promoted

Senior Security Engineer - Remote Cloud Detection

LiveRampSan Francisco, CA, United States
Remote
Full-time

A leading data collaboration platform is seeking a skilled Senior Security Engineer in San Francisco.This role involves advancing detection and automation initiatives, collaborating with teams to m... Show more

 • Promoted

Senior Software Engineer, Security (Remote)

Map SsgSan Francisco, CA, United States
Remote
Full-time

About the Role :We are seeking an experienced Software Engineer to join our security team.This role focuses on designing implementing and deploying security solutions and guardrails across our appl... Show more

 • Promoted

Nuclear Engineer

US NavyRichmond, CA, US
Full-time

Nuclear Engineer (Naval Reactors Engineer).Design, regulate, and oversee the Navy’s nuclear propulsion program, including reactor design, fleet operations, and eventual defueling and decommissionin... Show more

 • Promoted

Senior Corporate Security Engineer

AirwallexSan Francisco, CA, US
Full-time

Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses ... Show more

Application Security Engineer - SF - Hybrid Preferred, Remote O.K.

Unit21, Inc.San Francisco, CA, United States
Remote
Full-time

Application Security Engineer - SF - Hybrid Preferred, Remote O.San Francisco, United States Posted on 09 / 18 / 2025At Unit21, we believe that combating financial crime demands a united front.Thro... Show more

 • Promoted

Remote Senior F5 Engineer - TS/SCI Security Clearance

TAD PGS, Inc.San Francisco, CA, United States
Remote
Full-time

A prominent staffing firm is seeking a Senior F5 Engineer for a remote position requiring 50% travel to San Francisco.The ideal candidate must possess an Active Top Secret / SCI Security Clearance ... Show more