Senior Security Engineer, Detection
2 months ago
Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs-faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.
We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.
The Opportunity
We are seeking an experienced Senior Security Engineer, Detection & Response to join our dynamic security team. In this role, you will provide Level 2 support to our managed Security Operations Center (SOC), monitoring and analyzing security alerts and emerging threats across our corporate, cloud and production environments to identify and respond to potential security incidents and critical vulnerabilities.
You'll work closely with the broader security and IT team and other engineering teams to develop a strong understanding of our ecosystem to enable you to act effectively as an Incident Commander when required, and coordinate incident resolution with cross-functional teams to ensure 24/7 coverage. This understanding will aid you in your threat hunting and forensic investigations to uncover indicators of compromise and patterns of malicious activity, as well as fine-tune and develop additional detection rules, configurations, custom playbooks and automations tailored to our environment in collaboration with our managed SOC.
In the area of vulnerability management, you will monitor security advisories and threat intelligence feeds, and drive proactive actions within the organization. Your collaboration with cross-functional teams will be essential in proactively detecting and responding to security threats and ensuring the overall security of our digital assets.
What You'll Do:
- Security Operations Duties:
- Provide Level 2 support to a managed SOC and support moitoring security alerts and events from various sources, including corporate tools, WAF, security information and event management (SIEM) systems, and AWS to identify potential security incidents, intrusions and vulnerabilities
- Conduct threat huntingand perform forensic investigations to identify indicators of compromise (IOCs) and patterns of malicious activity.
- Coordinate and manager incident resolution with cross-functional teams, including acting as Incident Commander during incidents to help provide 24/7 coverage with other team members.
- Support Cloud Detection & Response platforms to enable various automated notification and containment workflows.
- Detection Engineering:
- Fine-tune and develop detection riles, configurations, and automations based on new threats, lessons learned, or environmental changes.
- Work with the managed SOC to develop custom playbooks.
- Where possible, write scripts and develop custom tools to automate the detection and response processes. Adhere to SSDLC best practices when writing scripts or developing tools.
- Identify any gaps in logging coverage to ensure we maintain the highest visibility into any threats to our environment
- Manage Cloudflare security products for web application security, including WAF rules and DDoS protection.
- Collaborate with cross-functional teams to proactively detect and respond to potential security threats and ensure the overall security of our organization's digital assets.
- Vulnerability Management:
- Monitor security advisories, threat intelligence feeds, and vendor updates for critical threats to drive action back into the enterprise/product organization.
- Education & Experience:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Minimum of 5-7 years of experience in a SOC analyst or security operations role.
- Technical Skills:
- Proficiency in programming and relevant scripting languages such as Python, JavaScript, Bash, and PowerShell.
- Experience with AWS security services and best practices.
- Familiarity with Cloudflare, SentinelOne, Okta, and related security tools.
- Understanding of network protocols, firewalls, and intrusion detection systems.
- Soft Skills:
- Strong analytical and problem-solving abilities.
- Excellent communication skills, both written and verbal.
- Ability to work independently and as part of a team.
- Certifications such as CISSP, CEH, and AWS Certified Security Specialty.
- Experience with infrastructure as code tools (e.g., Terraform).
- Knowledge of DevSecOps practices and CI/CD pipelines.
- Familiarity with regulatory compliance standards (e.g., GDPR, ISO 27001).
At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
What Else?
If the role is based in the greater San Francisco area, and the we are offering a base range of $180,000 to $212,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.
Equal Opportunity
Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.
-
Senior Security Engineer, Detection
1 month ago
San Francisco, United States Postman Full timeSenior Security Engineer, Detection & Response Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly...
-
Senior Security Engineer, Detection
2 months ago
San Francisco, United States Postman Full timeSenior Security Engineer, Detection & ResponsePostman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly...
-
Security Threat Detection Engineer
1 week ago
San Francisco, California, United States NexHealth Full timeWe are seeking a skilled Security Threat Detection Engineer to join our team at NexHealth. As a key member of our cybersecurity team, you will be responsible for identifying and mitigating potential security threats to our systems and data. Your expertise in threat detection and response will play a critical role in protecting our customers' sensitive...
-
Cyber Security Expert in Threat Detection
4 weeks ago
San Francisco, California, United States Cloudflare, Inc. Full timeCloudflare, Inc.Cyber Security Expert in Threat DetectionAbout the JobWe are seeking a highly skilled Cyber Security Expert in Threat Detection to join our team at Cloudflare, Inc. Based in London, this is an exciting opportunity for a Senior Staff or Principal Engineer with a strong background in threat detection and experience leading engineering teams.The...
-
Senior Information Security Analyst
4 days ago
San Francisco, California, United States NexHealth Full timeNexHealth OverviewNexHealth is a healthcare technology company accelerating innovation in the industry. We're committed to simplifying healthcare processes and improving patient outcomes. As a Security Engineer, you'll play a critical role in safeguarding customer data and ensuring the integrity of our platforms.Our Team:We're a collaborative and dynamic...
-
Senior Security Engineer
1 month ago
San Francisco, United States Incode Technologies Full timeThe OpportunityWe are looking for a trustworthy and proactive Senior Security Engineer to be the technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations...
-
Senior Software Engineer, Platform
1 month ago
San Francisco, United States Material Security Full timeAs a Senior Software Engineer for Platform at Material Security, you’ll build and own ambitious projects spanning our highest-scale systems. You’ll be responsible for balancing the reliability, performance, and resource-consumption of Material’s core platform services and subsystems. Responsibilities Build a sophisticated and flexible attachment...
-
Senior Software Engineer, Platform
3 weeks ago
San Francisco, United States Material Security Full timeAs a Senior Software Engineer for Platform at Material Security, youll build and own ambitious projects spanning our highest-scale systems. Youll be responsible for balancing the reliability, performance, and resource-consumption of Materials core platform services and subsystems. Responsibilities Build a sophisticated and flexible attachment processing...
-
Security Engineer, Detection
1 month ago
San Francisco, United States Grammarly Full timeGrammarly Grammarly makes AI writing convenient. Work smarter with personalized AI guidance and text generation on any app or website. Grammarly offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation,...
-
Senior Security Engineer, Detection
2 months ago
San Francisco, United States Tbwa ChiatDay Inc Full timeSenior Security Engineer, Detection & ResponseWho Are We?Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to...
-
Senior Software Engineer, Platform
1 month ago
San Francisco, United States Material Security Full timeAs a Senior Software Engineer for Platform at Material Security, you’ll build and own ambitious projects spanning our highest-scale systems. You’ll be responsible for balancing the reliability, performance, and resource-consumption of Material’s core platform services and subsystems.ResponsibilitiesBuild a sophisticated and flexible attachment...
-
Security Engineer, Detection
2 months ago
San Francisco, United States Grammarly Full timeGrammarlyGrammarly makes AI writing convenient. Work smarter with personalized AI guidance and text generation on any app or website.Grammarly offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation, and...
-
Senior Security Engineer Leader
2 weeks ago
San Francisco, California, United States ZipRecruiter Full timeAbout This Role:This Senior/Staff Security Operations Engineer will play a critical role in safeguarding Crusoe, our customers, and ensuring our security posture remains robust against emerging threats. The ideal candidate will lead the detection strategy, creation, tuning, validation, and correlation to maintain effective detections against an ever-changing...
-
Senior Security Engineer Lead
2 weeks ago
San Francisco, California, United States Crusoe Full timeAbout UsCrusoe is building the World's Favorite AI-first Cloud infrastructure company. We're committed to creating a sustainable and responsible technology ecosystem that powers the future of AI innovation. As a member of our team, you'll have the opportunity to drive meaningful change and contribute to a purpose-driven mission.Job DescriptionWe're seeking a...
-
Cloud Security Engineer, Threat Detection
2 weeks ago
San Francisco, California, United States Postman Full timeEstimated Salary Range$180,000 - $212,000 per year.Why Work at Postman?At Postman, we strive to create a workplace where everyone feels valued, included, and empowered to do their best work. We believe that diversity, equity, and inclusion are essential to our success, and we're committed to creating a workplace where everyone can thrive.What We're Looking...
-
Senior Backend Security Engineer
2 weeks ago
San Francisco, California, United States Oleria Security Full timeWe are looking for a talented Senior Backend Security Engineer to join our team. As an early hire, you will have the opportunity to build and architect our systems and platforms, including development practices and processes. Your expertise in backend development and cybersecurity will be crucial in helping us achieve our goal of providing adaptive and...
-
Principal Systems Engineer
3 weeks ago
San Francisco, United States Cloudflare Inc. Full timeAbout Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without...
-
Digital Security Leader
7 days ago
San Francisco, California, United States Postman Full timeProtecting Digital Assets in a Fast-Paced EnvironmentWe're seeking an experienced Senior Security Engineer, Detection & Response to join our dynamic security team. As part of this role, you will provide Level 2 support to our managed Security Operations Center (SOC), monitoring and analyzing security alerts and emerging threats across our corporate, cloud,...
-
Senior Security Systems Engineer and Developer
4 weeks ago
San Francisco, California, United States Microbiz Security Full timeJob OverviewWe are seeking a skilled Senior Security Systems Engineer and Developer to join our team at Microbiz Security, a leading provider of security solutions in the San Francisco area. As a key member of our technical staff, you will be responsible for designing, installing, and servicing advanced security systems.
-
Principal Systems Engineer, Application Security
2 months ago
San Francisco, United States Cloudflare Inc Full timeAbout UsAt Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without...