Postman

Principal Offensive Security Engineer

Lead · Офис · Сан-Франциско, США · Английский B2

Навыки

  • AI-агенты
  • API (интеграции)
  • Nexus / Artifactory
  • AWS
  • CI/CD
  • GraphQL
  • gRPC
Ещё 14
  • ISO 27001 / PCI DSS
  • Kubernetes
  • Лидерство
  • LLM
  • Machine Learning
  • Room / Realm / CoreData
  • OWASP
  • Ответственность за результат
  • Пентест
  • RAG
  • Роадмап
  • SOC
  • Управление командой
  • YARA / threat intelligence

О компании и продукте

  • The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.
  • The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.
  • We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operate as a key partner to CISO leadership on threat-informed defense strategy.
  • This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.

Задачи

  • Strategy & Program Ownership
  • Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities
  • Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems
  • This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure
  • You will define the methodology, tooling, and engagement frameworks from the ground up
  • Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations
  • Hands-On Technical Leadership
  • Red Team AI Systems at Depth: Go beyond checkbox assessments
  • Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures
  • Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem
  • Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines
  • People Leadership
  • Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning
  • Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML — a rare and competitive talent market
  • Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming
  • Communication & Influence
  • Drive Security Culture through "The Show": Lead live "Exploitable Demonstrations" — technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments
  • Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers
  • Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders
  • Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001)
  • Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings — especially from AI red team engagements — drive measurable improvements in detection, response, and architecture
  • Who Are We?

Требования

  • Experience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads
  • AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems — whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets
  • You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem
  • Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one
  • Experience setting OKRs, managing budgets, and presenting to executive leadership
  • Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments — extended to AI-native architectures
  • AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses)
  • Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems
  • Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF
  • You can present a complex exploit chain — including an AI-specific attack path — to a room of developers in a way that is inspiring, not condescending
  • Engineering Fluency: You prefer building an automated "exploit-as-code" validator over performing the same manual test twice
  • You can architect evaluation harnesses and adversarial test suites for ML models
  • Preferred
  • Industry Presence: Track record of contributions to the offensive security or AI security community — conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups
  • Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications
  • AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator
  • Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation
  • API Security Depth: Experience with API-specific attack methodologies — BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation — reflecting Postman's core product domain
  • Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence
  • You don't run GRC, but you know how to feed it
  • Actual compensation is based on the candidate's skills, qualifications, and experience
  • What Else?
  • Along with that, our wellness programs will help you stay in the best of your physical and mental health

Условия

  • Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500
  • Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster
  • The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded
  • Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners
  • Learn more at postman.com or connect with Postman on X via @getpostman
  • P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman
  • The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package
  • In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend

Паспорт вакансии

История публикации

Появилась в Вакандии30 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели 30 дней назад
Среди похожихНет данных60 из 30 · у похожих вакансий почти одинаковый возраст — сравнивать нечего

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдLeadвычитано из текста вакансии
Формат работыОфисвычитано из текста вакансии
ГеографияСан-Франциско, СШАвычитано из текста вакансии
Зарплата≈ 18 833 USD в месяцнаша оценка, в вакансии не названа

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • greenhouseОсновная публикация · 2026-04-30

Работодатель

Postman

50 активных вакансий · вилка работодателя указана в 40%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеjob-boards.greenhouse.io.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · та же страна

    Rivian · агентство

    Sr. Cybersecurity Engineer

    • Senior
    • Гибрид
    • Атланта, США
    Подробнее