Lead Security Risk Analyst

2 weeks ago


San Francisco, California, United States Postman, Inc. Full time
Senior Security Risk Analyst

Postman is recognized as the premier collaboration platform for API development, empowering developers and organizations to innovate efficiently. With over 30 million developers and 500,000 organizations utilizing our platform, we are on a mission to connect 100 million developers worldwide.

The Senior Security Risk Analyst will be an integral member of the Security Assurance team, concentrating on enhancing the organization's cybersecurity risk management framework. The ideal candidate will have a robust background in cybersecurity and risk management, demonstrating familiarity with risk management frameworks such as NIST RMF, FAIR, and ISO.

Key Responsibilities:
  • Perform thorough risk evaluations to uncover information security vulnerabilities and potential threats stemming from business activities.
  • Formulate and execute risk management strategies to address identified vulnerabilities.
  • Continuously assess the effectiveness of risk mitigation efforts.
  • Work collaboratively with IT, legal, compliance, and other departments to ensure a unified approach to risk management.
  • Present risk findings and mitigation strategies to stakeholders, including senior management.
  • Prepare comprehensive reports on risk assessments, detailing identified threats and the success of mitigation strategies, ensuring clarity for both technical and non-technical audiences.
  • Regularly update organizational policies and procedures to align with current industry standards and compliance requirements.
  • Engage actively with IT Procurement and Legal to enhance Third-Party Risk Management and vendor oversight.
  • Contribute to compliance initiatives to uphold standards such as ISO 27001/27701, HIPAA, NIST, FedRAMP, GDPR, CCPA, and SOC 2.
  • Collaborate with business leaders and technical teams to assess and manage security risks, recommending improvements to support organizational growth.
  • Act as a mentor within the team, providing expert advice and fostering a culture of security awareness.
  • Utilize technical expertise and communication skills to guide engineers and technologists on security best practices.
  • Adopt a results-oriented approach to compliance engineering, employing effective problem-solving skills.
Qualifications:
  • A minimum of ten years of experience in cybersecurity governance, risk management, and compliance.
  • Relevant certifications such as CRISC, CISSP, CISM, or CISA are advantageous.
  • Proficient in risk management frameworks, including NIST RMF, FAIR, and ISO.
  • Experience with GRC programs, particularly in a Cloud/SaaS context.
  • Strong technical knowledge related to management information systems and internal controls.
  • Self-driven and organized, with a proven track record of meeting deadlines.
  • Exceptional interpersonal skills with the ability to build relationships across diverse teams.
Company Values

At Postman, we foster a culture of curiosity and transparency, valuing honest communication about both successes and challenges. Our inclusive environment ensures that every team member is recognized as a vital contributor to our collective success.

Compensation and Benefits

For roles based in the greater San Francisco area, we offer a competitive salary range along with a comprehensive benefits package, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Compensation is determined based on skills, qualifications, and experience.

Postman is an Equal Employment Opportunity and Affirmative Action Employer, committed to diversity and inclusion in the workplace.



  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman is recognized as the premier collaboration platform for API development, streamlining each phase of API creation and enhancing teamwork to foster superior APIs more efficiently. With over 30 million developers and 500,000 organizations utilizing Postman globally, we are dedicated to our mission of connecting 100 million...


  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman is recognized as the premier collaboration platform for API development. Our innovative features simplify every phase of API creation and enhance teamwork, enabling the development of superior APIs more efficiently. With over 30 million developers and 500,000 organizations globally utilizing Postman, we are committed to...


  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman, Inc. stands as a premier collaboration platform dedicated to API development. Our innovative features simplify the API building process and enhance teamwork, enabling the creation of superior APIs more efficiently. With over 30 million developers and 500,000 organizations utilizing Postman globally, we are on a mission to...


  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman, Inc. stands as a premier collaboration platform for API development, empowering developers and organizations globally. With over 30 million developers and 500,000 organizations utilizing our platform, we are committed to enhancing our mission of connecting 100 million developers in an API-centric world.The Senior Security...


  • San Francisco, California, United States Postman, Inc. Full time

    Senior Security Risk AnalystPostman is recognized as the premier collaboration platform for API development, empowering developers and organizations to innovate in an API-first environment. With over 30 million developers and 500,000 organizations utilizing our platform, we are committed to enhancing our mission of connecting 100 million developers...


  • San Francisco, California, United States Western Alliance Bank Full time

    Job Title: Lead Financial Risk Analyst - Technology Lending Location: CA - San Francisco, Spear Role Overview: The Lead Financial Risk Analyst in Technology Lending is tasked with analyzing, overseeing, and maintaining comprehensive financial data on existing and potential technology clients. This role supports the underwriting process for Relationship...


  • San Francisco, California, United States Kandji Full time

    About KandjiKandji is a leading provider of enterprise-grade Apple device management and security solutions. Our platform empowers organizations to centrally manage and secure their Apple devices, freeing up IT and InfoSec teams from manual, repetitive work.Our vision is to create a seamless and secure experience for Apple users, leveraging connected...


  • San Francisco, California, United States Goeverbright Full time

    Position OverviewThe Senior Risk Analyst will play a pivotal role in enhancing risk management and safeguarding revenue through various projects and processes. This role involves utilizing automation, advanced algorithms, analytics, and modeling techniques to monitor performance metrics and identify previously unrecognized conditions, ultimately driving...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Role OverviewThe **Senior Vendor Risk Analyst** will be responsible for collaborating with various stakeholders to initiate, define, and strategize assessments of both new and existing vendor partnerships.Key Responsibilities- Conduct thorough assessments either on-site at vendor facilities or remotely through virtual meetings.- Evaluate completed...

  • IT Security Analyst

    1 week ago


    San Francisco, California, United States U.S. Court of Appeals, Ninth Circuit Full time

    About the RoleThe IT Security Analyst (Assessments) plays a critical role in ensuring the security and integrity of the U.S. Court of Appeals, Ninth Circuit's information systems. This position is responsible for continuously identifying, tracking, sharing, and supporting operational IT security requirements across the Ninth Circuit.Key...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Role OverviewThe **Senior Vendor Risk Analyst** will be responsible for collaborating with various stakeholders to initiate, define, and strategize assessments of controls related to both new and existing vendor partnerships.Key Responsibilities- Conduct thorough assessments either on-site at vendor facilities or remotely through virtual meetings.- Evaluate...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Role OverviewThe **Senior Vendor Risk Analyst** will be responsible for collaborating with various stakeholders to initiate, define, and strategize control assessments for both new and existing vendor partnerships.Key ResponsibilitiesConduct thorough assessments either on-site at vendor locations or remotely through virtual meetings.Evaluate completed...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Position OverviewThe Senior Vendor Risk Analyst will be responsible for collaborating with various stakeholders to initiate, define, and strategize assessments of controls related to both new and ongoing vendor partnerships.Key ResponsibilitiesConduct thorough assessments either on-site at vendor facilities or remotely through virtual meetings.Review...


  • San Francisco, California, United States Direct Staffing Inc Full time

    Position Overview:As a Senior Risk Assessment Analyst, you will be responsible for collaborating with various stakeholders to initiate, define, and strategize control evaluations for both new and existing vendor partnerships.Key Responsibilities:Conduct thorough assessments either on-site at vendor locations or remotely through virtual meetings.Review...

  • Senior Risk Analyst

    2 weeks ago


    San Francisco, California, United States Federal Reserve Bank Full time

    Company Federal Reserve Bank of San Francisco We are the San Francisco Fed, dedicated public servants with a mission to enhance the nation's monetary, financial, and payment systems to foster a robust economy for all Americans. Our commitment to community engagement drives us to understand and serve the diverse populations of the Twelfth District. We value...


  • San Francisco, California, United States DoorDash USA Full time

    About DoorDashAt DoorDash, we are committed to building a reliable logistics platform that serves consumers, merchants, and drivers around the clock. Our team is dedicated to ensuring that our global infrastructure remains secure and efficient.Position OverviewThe Governance, Risk, and Compliance (GRC) team is in search of a skilled Third-Party Risk Analyst....

  • Credit Risk Analyst

    6 days ago


    San Francisco, California, United States Cardless Full time

    About the RoleWe're seeking a highly skilled Risk Analyst to join our team at Cardless, a leading fintech company. As a Risk Analyst, you will play a critical role in developing and implementing our credit and underwriting policies, as well as our fraud defenses.Key ResponsibilitiesDevelop and manage credit policies for our partner brands and new business...


  • San Francisco, California, United States Visa Full time

    Company OverviewVisa stands at the forefront of the payments and technology sector, facilitating over 259 billion secure transactions annually across more than 200 countries and territories. Our mission is to connect the globe through innovative, reliable, and secure payment solutions, empowering individuals, businesses, and economies to prosper. We are...


  • San Francisco, California, United States DoorDash USA Full time

    About DoorDashAt DoorDash, we are committed to creating the most reliable logistics platform for delivery services. Our team is dedicated to ensuring that our global infrastructure operates seamlessly, providing uninterrupted service to our diverse marketplace of consumers, merchants, and drivers.Position OverviewThe Governance, Risk, and Compliance (GRC)...

  • Security Officer

    1 week ago


    San Francisco, California, United States Inter-Con Security Systems, Inc. Full time

    Job SummaryWe are seeking a highly skilled Security Officer to join our team at Inter-Con Security Systems, Inc. As a Security Officer, you will be responsible for providing security services to our clients, ensuring the safety and security of their facilities and assets.Key ResponsibilitiesConduct regular patrols of assigned facilities, including high-risk...