Staff Security Engineer

1 month ago


San Francisco, United States Postman Full time
Who Are We?

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs-faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.
The Opportunity

As a Staff Security Engineer at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman's product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.
What You'll Do:

  • Security Architecture Design: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies.
  • Threat Modeling & Risk Assessment: Lead threat modeling and risk assessment to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.
  • Technology Review & Evaluation: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.
  • Security Strategy: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.
  • Incident Response: Work closely with the SOC to understand gaps in product architecture.
  • Mentorship & Leadership: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.
About You:

Experience:
  • 15+ years in a security architecture role with a focus on software products and platforms.
  • Experience working within fast-paced, cloud-native environments.
  • Proven experience with securing distributed systems, microservices, and APIs.
  • Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR)
  • Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.
  • In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud
Communication & Leadership:
  • Strong ability to communicate complex security concepts to both technical and non-technical stakeholders.
  • Experience working cross-functionally with product, engineering, and operations teams.
  • Proven leadership in driving security initiatives and integrating security into product development lifecycles.
Preferred Skills:
  • Experience with API security, including OAuth, JWT, and OpenID Connect.
  • Knowledge of container security (Docker, Kubernetes).
  • Familiarity with security automation tools and methodologies (e.g., SAST, DAST, RASP).
  • Technical industry certifications such as OSCP, GPEN etc.
Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
What Else?

If the role is based in the greater San Francisco area, and the we are offering a base salary range of $250,000 to $350,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.
Equal Opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

  • San Francisco, United States IDENTIFY SECURITY Full time

    We are currently seeking a Staff Embedded Security Engineer. This position requires an experienced professional with a proven track record of cyber security development achievements. Our ideal candidate exhibits a can–do attitude and approaches his or her work with vigor and determination. Candidates will be expected to demonstrate excellence in their...


  • San Francisco, United States IDENTIFY SECURITY Full time

    We are seeking a highly skilled Staff Application Security Engineer with a strong background in cloud software service management and application security to join our dynamic team. In this role, you will play a crucial part in ensuring the reliability, scalability, and security of our software systems and digital experiences. You will work closely with the...


  • San Francisco, CA, United States IDENTIFY SECURITY Full time

    We are currently seeking a Staff Embedded Security Engineer . This position requires an experienced professional with a proven track record of cyber security development achievements. Our ideal candidate exhibits a can-do attitude and approaches his or her work with vigor and determination. Candidates will be expected to demonstrate excellence in their...


  • San Francisco, California, United States Microbiz Security Full time

    Job OverviewWe are seeking a skilled Senior Security Systems Engineer and Developer to join our team at Microbiz Security, a leading provider of security solutions in the San Francisco area. As a key member of our technical staff, you will be responsible for designing, installing, and servicing advanced security systems.


  • San Francisco, United States Amplitude Full time

    Amplitude is a leading digital analytics platform that helps companies unlock the power of their products. More than 3,200 customers, including Atlassian, Jersey Mike's, NBCUniversal, Shopify, and Under Armour, rely on Amplitude to gain self-service visibility into the entire customer journey. Amplitude guides companies every step of the way as they capture...


  • San Francisco, United States Amplitude Full time

    Amplitude is a leading digital analytics platform that helps companies unlock the power of their products. More than 3,200 customers, including Atlassian, Jersey Mike's, NBCUniversal, Shopify, and Under Armour, rely on Amplitude to gain self-service visibility into the entire customer journey. Amplitude guides companies every step of the way as they capture...


  • San Francisco, United States Amplitude Full time

    Amplitude is a leading digital analytics platform that helps companies unlock the power of their products. More than 3,200 customers, including Atlassian, Jersey Mike's, NBCUniversal, Shopify, and Under Armour, rely on Amplitude to gain self-service visibility into the entire customer journey. Amplitude guides companies every step of the way as they capture...


  • San Francisco, United States Postman Full time

    Who Are We? Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs-faster. More than 35 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million...


  • San Francisco, United States Postman Full time

    Who Are We? Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs-faster. More than 35 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million...


  • San Francisco, United States airbnb, Inc. Full time

    Airbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more...


  • San Francisco, United States Security Bank & Trust Full time

    Harvey is a secure AI platform for professionals in law, tax, and finance that augments productivity and automates complex workflows. Harvey uses algorithms with reasoning-adept LLMs that have been customized by our expert team of lawyers, engineers, and research scientists. We’ve found product market fit and are scaling our team very quickly. Some reasons...


  • San Francisco, United States Ellation, Inc. Full time

    About the roleCrunchyroll Games hold a special significance for our fans, serving as a vibrant gateway to immersive experiences deeply rooted in beloved anime worlds. With each game, fans are transported into captivating narratives and given the opportunity to interact firsthand with their favorite characters and settings.As a Staff Security Engineer,...


  • San Francisco, United States Amplitude Full time

    Amplitude is a leading digital analytics platform that helps companies unlock the power of their products. More than 3,200 customers, including Atlassian, Jersey Mike's, NBCUniversal, Shopify, and Under Armour, rely on Amplitude to gain self-service visibility into the entire customer journey. Amplitude guides companies every step of the way as they capture...


  • San Francisco, United States Rippling Full time

    RipplingRippling eliminates the friction from running a business, combining HR, IT, and Finance apps on a unified data platform. Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever,...


  • San Francisco, United States Rippling Full time

    Senior Staff Infrastructure Security EngineerRippling eliminates the friction from running a business, combining HR, IT, and Finance apps on a unified data platform.Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and...


  • San Francisco, United States Crusoe Energy Inc Full time

    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.We aim to align the long term interests of the climate with the future of global computing infrastructure. As data centers consume an exponentially growing power footprint to deliver technology to all connected devices, we are inspired by making sure...


  • San Francisco, United States ZipRecruiter Full time

    Job DescriptionCrusoe is building the World’s Favorite AI-first Cloud infrastructure company. We’re pioneering vertically integrated, purpose-built AI infrastructure solutions trusted by Fortune 500 companies to power their most advanced AI applications.Crusoe is redefining AI cloud infrastructure, with a mission to align the future of computing with the...


  • San Francisco, California, United States Oleria Security Full time

    Lead the Charge in Cloud Security with OleriaWe're seeking a seasoned Cloud Security Engineer to spearhead our AI/ML initiatives, driving innovation and excellence in cloud identity security. This is an exceptional opportunity for a visionary leader to shape the future of cloud security.About the RoleAs a Principal Applied AI/ML Engineer at Oleria Security,...


  • san francisco, United States Code Red Partners Full time

    Code Red is Partnered with one of the most innovative companies in the world. They have raised $100M+ funding and are backed by leading investors like a16z. The CISO is ready to make the first core security team hires, with great impact and scope. We are hiring a Device Security Engineer.What you’ll do:secure embedded devices by innovating + applying...


  • san francisco, United States Code Red Partners Full time

    Code Red is Partnered with one of the most innovative companies in the world. They have raised $100M+ funding and are backed by leading investors like a16z. The CISO is ready to make the first core security team hires, with great impact and scope. We are hiring a Device Security Engineer.What you’ll do:secure embedded devices by innovating + applying...