Postman

Postman

Principal Offensive Security Engineer

San Francisco, California, United States · Principal

Sponsorship not specified$275k-$300kDetected 82 days ago
AWSKubernetesCI/CDGraphQLgRPCMachine LearningLLMsRAGAgentic AICybersecurityPenetration TestingSOC OperationsComplianceOKRsSupply ChainPostmanHIPAAResearchLeadershipCommunicationCollaborationMentoringPublic Speaking

About the role

  • The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations.
  • We are a team of builders, not checkbox-checkers.
  • We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization.

Responsibilities

  • Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems.
  • Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape - OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems - translating external research into internal red team playbooks and detection hypotheses for Security Operations.
  • Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines - targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.
  • Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.
  • Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers - including specialized AI red team operators - providing mentorship, career development, and succession planning.
  • Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.
  • Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).
  • Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration-enabling users to create better APIs, faster.
  • Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners.
  • Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about.

Requirements

  • Experience setting OKRs, managing budgets, and presenting to executive leadership.
  • Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses).
  • Experience with API-specific attack methodologies - BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation - reflecting Postman's core product domain.

Nice to have

  • You can architect evaluation harnesses and adversarial test suites for ML models.

Skills

  • Governance Risk & Compliance (GRC), Product Security, and Security Operations.
  • Stand up and scale a dedicated offensive capability targeting AI/ML systems.

Compensation

  • The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package.

Benefits

  • P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.
  • The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package.
  • The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.

Company info

  • We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker.
  • The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded.
  • At Postman we value in person collaboration.
  • We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, Tokyo and London.

This listing is sourced directly from Postman's careers page and normalized into a canonical job model.