Staff Security Engineer

Postman
San Francisco, California, United States$250k – $275kPosted 23 February 2026

Job Description

<div class="content-intro"><h2><strong>Who Are We?</strong></h2> <p>Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.</p> <p>The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.</p> <p>P.S: We highly recommend reading <a href="https://api-first-world.com/">The "API-First World" graphic novel</a> to understand the bigger picture and our vision at Postman.</p></div><h2><strong>The Opportunity</strong></h2> <p>As a Staff Security Engineer at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.</p> <h2><strong>What You’ll Do</strong></h2> <ul> <li> <p><strong>Security Architecture Design</strong>: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies.</p> </li> <li> <p><strong>Threat Modeling Risk Assessment</strong>: Lead threat modelling and risk assessments to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.</p> </li> <li> <p><strong>Technology Review Evaluation</strong>: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.</p> </li> <li> <p><strong>Security Strategy</strong>: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.</p> </li> <li> <p><strong>Incident Response</strong>: Work closely with the SOC to understand gaps in product architecture. </p> </li> <li> <p><strong>Mentorship Leadership</strong>: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.</p> </li> </ul> <h2 id="m_-1384246093076033171gmail-Required-Qualifications:"><strong>About You</strong></h2> <ul> <li> <p><strong>Experience</strong>:</p> <ul> <li> <p>10+ years in a security architecture role with a focus on software products and platforms.</p> </li> <li> <p>Experience working within fast-paced, cloud-native environments.</p> </li> <li> <p>Proven experience with securing distributed systems, microservices, and APIs.</p> </li> <li> <p>Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR)</p> </li> <li> <p>Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.</p> </li> <li> <p>In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud)</p> </li> </ul> </li> <li> <p><strong>Communication Leadership</strong>:</p> <ul> <li> <p>Strong ability to communicate complex security concepts to both technical and non-technical stakeholders.</p> </li> <li> <p>Experience working cross-functionally with product, engineering, and operations teams.</p> </li> <li> <p>Proven leadership in driving security initiatives and integrating security into product development lifecycles.</p> </li> </ul> </li> <li id="m_-1384246093076033171gmail-Preferred-Skills:"><strong ... (truncated, view full listing at source)