Staff Security Architect

3 weeks ago


San Francisco, United States Postman Full time

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

As a Principal Security Architect at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.

What You’ll Do:

Security Architecture Design: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes advising GRC / Legal on Security policies.

Threat Modeling & Risk Assessment: Lead threat modeling and risk assessment to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.

Technology Review & Evaluation: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.

Security Strategy: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.

Incident Response: Work closely with the SOC to understand gaps in product architecture.

Mentorship & Leadership: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.

About You:

Experience:

  • 15+ years in a security architecture role with a focus on software products and platforms.
  • Experience working within fast-paced, cloud-native environments.
  • Proven experience with securing distributed systems, microservices, and APIs.
  • Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR).
  • Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.
  • In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud).
  • Strong ability to communicate complex security concepts to both technical and non-technical stakeholders.
  • Experience working cross-functionally with product, engineering, and operations teams.
  • Proven leadership in driving security initiatives and integrating security into product development lifecycles.

Preferred Skills:

  • Experience with API security, including OAuth, JWT, and OpenID Connect.
  • Knowledge of container security (Docker, Kubernetes).
  • Familiarity with security automation tools and methodologies (e.g., SAST, DAST, RASP).
  • Technical industry certifications such as OSCP, GPEN, etc.
Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

What Else?

If the role is based in the greater San Francisco area, we are offering a base salary range of $250,000 to $350,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

#J-18808-Ljbffr

  • San Francisco, California, United States CloudSploit by Aqua Security Full time

    About the RoleWe are seeking a seasoned Cloud Security Solutions Architect to join our team at CloudSploit by Aqua Security. As a Cloud Security Solutions Architect, you will be responsible for providing subject-matter expertise on the security of running software containers, which are rapidly being adopted in enterprise deployments. You will drive technical...

  • Solution Architect

    3 weeks ago


    San Francisco, United States Aqua Security Full time

    Description As a Solution Architect at Aqua, you will be responsible for providing subject-matter expertise on the security of running software containers (Docker and other formats), which are rapidly being adopted in enterprise deployments. You will drive technical relationships with all stakeholders and support sales opportunities. You will work closely...

  • Security Architect

    5 days ago


    San Francisco, United States ZipRecruiter Full time

    Job DescriptionIntroduction:Are you a technical wizard with a passion for designing secure systems that can withstand the most sophisticated cyber threats? Do you thrive on creating robust architectures that balance security with business needs? If you’re a proactive, innovative thinker with a deep understanding of security principles, then our client has...

  • Security Architect

    3 months ago


    San Francisco, United States Unreal Gigs Full time

    Introduction:Are you a technical wizard with a passion for designing secure systems that can withstand the most sophisticated cyber threats? Do you thrive on creating robust architectures that balance security with business needs? If you’re a proactive, innovative thinker with a deep understanding of security principles, then our client has an exciting...

  • Security Architect

    3 days ago


    San Francisco, United States BlueVoyant Full time

    Client Security ArchitectLocation: Remote in the United StatesUnited States Citizenship RequiredSummary:The Client Security Architect must have experience working across a wide variety of security solutions and technologies. Must be able to maintain and troubleshoot solutions that enable security configurations, administration, management, and support. Must...

  • Security Architect

    2 days ago


    San Francisco, United States BlueVoyant Full time

    Client Security ArchitectLocation: Remote in the United StatesUnited States Citizenship RequiredSummary:The Client Security Architect must have experience working across a wide variety of security solutions and technologies. Must be able to maintain and troubleshoot solutions that enable security configurations, administration, management, and support. Must...

  • Security Architect

    3 weeks ago


    San Francisco, United States Unreal Gigs Full time

    Introduction:Are you a technical wizard with a passion for designing secure systems that can withstand the most sophisticated cyber threats? Do you thrive on creating robust architectures that balance security with business needs? If you’re a proactive, innovative thinker with a deep understanding of security principles, then our client has an exciting...


  • San Francisco, United States IDENTIFY SECURITY Full time

    We are currently seeking a Staff Embedded Security Engineer. This position requires an experienced professional with a proven track record of cyber security development achievements. Our ideal candidate exhibits a can–do attitude and approaches his or her work with vigor and determination. Candidates will be expected to demonstrate excellence in their...


  • San Francisco, United States airbnb, Inc. Full time

    Airbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more...


  • San Francisco, United States Tbwa ChiatDay Inc Full time

    Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected...


  • San Francisco, United States IDENTIFY SECURITY Full time

    We are seeking a highly skilled Staff Application Security Engineer with a strong background in cloud software service management and application security to join our dynamic team. In this role, you will play a crucial part in ensuring the reliability, scalability, and security of our software systems and digital experiences. You will work closely with the...


  • San Francisco, United States Databricks Full time

    RDQ224R256 Product Security Mission: The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified...


  • San Francisco, United States Databricks Full time

    Product Security Mission: The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified...


  • San Francisco, United States BlueVoyant Full time

    Microsoft Security Solutions ArchitectLocation: Remote - West Coast United StatesOverview:BlueVoyant is seeking a Microsoft Security Solutions Architect to join our dynamic pre-sales team, dedicated to our Microsoft Alliance. This role focuses on conducting Security Operations Diagnostics as part of our prescriptive pre-sales strategy, assisting clients in...


  • San Francisco, United States BlueVoyant Full time

    Microsoft Security Solutions ArchitectLocation: Remote - West Coast United StatesOverview:BlueVoyant is seeking a Microsoft Security Solutions Architect to join our dynamic pre-sales team, dedicated to our Microsoft Alliance. This role focuses on conducting Security Operations Diagnostics as part of our prescriptive pre-sales strategy, assisting clients in...

  • Solution Architect

    2 months ago


    San Francisco, United States CloudSploit by Aqua Security Full time

    About The Position As a Solution Architect at Aqua, you will be responsible for providing subject-matter expertise on the security of running software containers (Docker and other formats), which are rapidly being adopted in enterprise deployments. You will drive technical relationships with all stakeholders and support sales opportunities. You will...

  • Solution Architect

    3 weeks ago


    San Francisco, United States Aqua Security Software Ltd. Full time

    DescriptionAs a Solution Architect at Aqua, you will be responsible for providing subject-matter expertise on the security of running software containers (Docker and other formats), which are rapidly being adopted in enterprise deployments. You will drive technical relationships with all stakeholders and support sales opportunities. You will work closely...


  • San Francisco, United States BlueVoyant Full time

    Client Security ArchitectLocation: Remote in the United StatesUnited States Citizenship RequiredSummary:The Client Security Architect must have experience working across a wide variety of security solutions and technologies. Must be able to maintain and troubleshoot solutions that enable security configurations, administration, management, and support. Must...


  • San Francisco, California, United States Contrast Security Full time

    About the RoleWe are seeking a highly technical Senior Product Manager to join our foundational services group at Contrast Security. As a key member of our team, you will define and deliver the next generation of our application security platform, supporting a broad variety of application security use cases from development to production.This is a highly...


  • San Francisco, United States Amazon Full time

    Sr. Partner Solutions Architect - SecurityJob ID: 2828540 | Amazon Web Services, Inc.Amazon Web Services is leading the next paradigm shift in computing and is looking for a world class candidate for the role of Partner Solution Architect, Security, within our Amazon Partner Organization (APO) to work with our strategic security Independent Software Vendors...