Principal Offensive Security Engineer
San Francisco, United States · On-site · Full-time
- Posted 3w ago
- From Postman’s careers page
- Location
- San Francisco, United States
- Work mode
- On-site
- Type
- Full-time
- Level
- Principal
- Experience
- 8+ years
- Department
- Information Technology
Opens the listing on postman.wd108.myworkdayjobs.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Who Are We?:
Postman is the world's leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore.
About the Team:
The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. The Offensive Security team is the "red" pulse of this organization, focusing on continuous security validation, AI-augmented adversary emulation, and offensive AI security research.
The Opportunity:
We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program, including building out a dedicated Offensive AI Security capability from the ground up, and operate as a key partner to CISO leadership on threat-informed defense strategy.
What You'll Do:
Strategy & Program Ownership
- Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
- Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems, including adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure.
- Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape, translating external research into internal red team playbooks and detection hypotheses for Security Operations.
Hands-On Technical Leadership
- Red Team AI Systems at Depth: Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines, targeting prompt injection, tool-use abuse, data exfiltration, training data poisoning, and trust boundary violations in multi-agent architectures.
- Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across the API ecosystem.
- Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.
People Leadership
- Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers, including specialized AI red team operators.
- Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML.
Communication & Influence
- Drive Security Culture through "The Show": Lead live Exploitable Demonstrations for engineering teams, with emphasis on demystifying AI-specific attack vectors for non-ML engineers.
- Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders.
- Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering.
About You:
- Experience: Minimum of 8 years in offensive security with at least 4 years in a people management or leadership capacity, including managing managers or tech leads.
- AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems, including adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets.
- Strategic Acumen: Demonstrated ability to build and scale an offensive security program, setting OKRs, managing budgets, and presenting to executive leadership.
- Adversarial Mindset: Deep understanding of the modern threat landscape as applied to cloud-native, API-first, and AI-native environments.
- AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools and AI red team frameworks, and understanding of how to manage non-deterministic AI outputs.
- Pragmatic Storytelling: Ability to present complex exploit chains to developers in an inspiring, non-condescending way.
- Engineering Fluency: Ability to build automated exploit-as-code validators and architect evaluation harnesses and adversarial test suites for ML models.
Preferred:
- Industry Presence: Contributions to the offensive security or AI security community, such as conference talks, tool releases, published research, CVEs, or working group participation.
- Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent. AI/ML-specific credentials are a differentiator.
- Cloud Security Expertise: Familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.
- API Security Depth: Experience with BOLA, BFLA, mass assignment, GraphQL abuse, and gRPC exploitation.
- Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence.
Compensation:
The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience.
What Else?:
Postman offers pay-on-performance, a flexible schedule, full medical coverage, flexible PTO, wellness reimbursement, a monthly lunch stipend, team-building events, and a donation-matching program. Postman values in-person collaboration and is in office 5 days a week for all roles based out of its hubs in San Francisco Bay Area, Boston, Austin, New York City, Tokyo, and London.
Equal Opportunity:
Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
Skills they ask for
Pick one to see other roles that ask for it.
About Postman
The AI-native API platformPostman provides an API platform for developing, testing, managing, and distributing APIs and services.
See all 32 roles at PostmanMore roles at Postman
See all 32- Software Engineer (Frontend), Automation TestingBengaluru · HybridSoftware Development · HybridBengaluru, India1d
- Software Engineer (Backend), Automation TestingBengaluru · On-siteSoftware Development · On-siteBengaluru, India1d
- Principal Software Engineer, Business PlatformSan Francisco · Principal · On-siteSoftware Development · Principal · On-siteSan Francisco, United States3d
- Senior Fullstack EngineerAustin · Senior · On-siteSoftware Development · Senior · On-siteAustin, United States3d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.