See all roles

Staff Security Engineer job at Postman in San Francisco, CA, Boston, MA, Bangalore, KA, India, Hyderabad, TG, India, London, ENG, United Kingdom, New York, NY

Work from home Full-time role Hiring

Title: Staff Security Engineer Location: San Francisco, California, United States Job Description: Who Are We? Postman is the world’s leading API platform, used by more than 40 million developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. The Opportunity As a Staff Security Engineer at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats. What You’ll Do Security Architecture Design: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies. Threat Modeling & Risk Assessment: Lead threat modelling and risk assessments to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies. Technology Review & Evaluation: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements. Security Strategy: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives. Incident Response: Work closely with the SOC to understand gaps in product architecture. Mentorship & Leadership: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices. About You Experience: 10+ years in a security architecture role with a focus on software products and platforms. Experience working within fast-paced, cloud-native environments. Proven experience with securing distributed systems, microservices, and APIs. Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR) Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines. In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud) Communication & Leadership: Strong ability to communicate complex security concepts to both technical and non-technical stakeholders. Experience working cross-functionally with product, engineering, and operations teams. Proven leadership in driving security initiatives and integrating security into product development lifecycles. Preferred Skills: Experience with API security, including OAuth, JWT, and OpenID Connect. Knowledge of container security (Docker, Kubernetes). Familiarity with security automation tools and methodologies (e.g., SAST, DAST, RASP). Technical industry certifications such as OSCP, GPEN etc… The reasonably estimated base salary for this role ranges from $250,000 to $275,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. What Else? In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We’re building a long-term company with an inclusive culture where everyone can be the best version of themselves. At Postman, we embrace a hybrid work model. For all roles based out of San Francisco Bay Area, Boston, Bangalore, Hyderabad, London, and New York, employees are expected to come into the office 3-days a week. We were thoughtful in our approach which is based on balancing flexibility and collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our hybrid office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom. Our Values At Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can. Equal opportunity Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman. Apply tot his job Apply To this Job

You might like

Remote Cybersecurity Engineer (API / Web App Security)

Work from home Full-time role

[Remote] API Tester

Work from home Full-time role

Remote Software Tester jobs – Full‑Time QA Engineer (Remote) based in Cary town, North Carolina – Selenium, Cypress & API Testing – $80‑$95k – Agile / Scrum Team – Contract‑to‑Hire

Work from home Full-time role

Apple Virtual Service Advisor (Work At Home) $24/Hr – MySmartPros

Work from home Full-time role

Apple Support (Home) Advisor ?? Work from Home Jobs/Remote

Work from home Full-time role

Remote Apple Advisor $25/Hour

Work from home Full-time role

[Remote] Associate Solution Consultant – Tech Alliances

Work from home Full-time role

Application Architect

Work from home Full-time role

Manager, Application Security

Work from home Full-time role

No Surprises Act Arbitrator

Work from home Full-time role

Part-Time Remote Customer Support Specialist – Delivering Exceptional Service Experience with blithequark

Work from home Full-time role

Data Scientist III - Financial Crimes Modeling

Work from home Full-time role

Contract Employment Litigation Attorney (Remote)

Work from home Full-time role

Senior Paid Media Manager

Work from home Full-time role

Experienced Full Stack Customer Service Representative – Remote Customer Support for arenaflex

Work from home Full-time role

Salesforce Developer (OmniStudio Certified) in Plano, TX – (job id: 1682734209)

Work from home Full-time role

Experienced Customer Service Representative – Delivering Exceptional Support Experiences for arenaflex Customers (Fully Remote)

Work from home Full-time role

Senior Client Service Manager

Work from home Full-time role

Experienced Live Chat Support Specialist – Delivering Exceptional Customer Experiences at arenaflex

Work from home Full-time role

Experienced Full Stack Remote Patient Monitoring-Home Telehealth Case Manager Nurse - Telehealth Nursing Opportunity in Portland, Oregon

Work from home Full-time role