Full-Time

Senior Security Engineer

Application Security

Posted on 2/8/2025

Postman

Postman

1,001-5,000 employees

API development, testing, docs, monitoring platform

Compensation Overview

$210k - $240k/yr

+ Equity package

San Francisco, CA, USA

Hybrid

3 days in-office per week required for SF Bay Area role.

Category
IT & Security (2)
,
Required Skills
Git
AWS
Requirements
  • Experience working as a Senior Security Engineer with deep involvement in securing modern web Applications and APIs.
  • Experience conducting threat modeling, security reviews and risk assessments.
  • Solid project management experience leading initiatives that have measurably improved the security of organizations.
  • Proficient in one or more high-level programming languages.
  • Proficient with common developer tools and processes such as Github, CI/CD, containers and orchestration, IaaS/PaaS, APIs, Websockets, Databases, Front-End and Back-End systems.
  • Experience securing Data to meet various privacy framework and regulation requirements.
  • Deep understanding and experience in securing AWS environments.
  • Experience in deploying AppSec tools (e.g., SAST, SCA, WAF etc) throughout the stages of the SDLC to ensure the most relevant vulnerabilities are surfaced and false positives are kept to a minimum.
  • Understanding of web security mechanisms (such as SOP, CORS, CSP, Subresource Integrity, and same-site cookies).
  • Strong understanding of various authentication/authorization protocols e.g. OAuth, SAML and JWT
Responsibilities
  • Mentor junior security engineers and security champions on security best practices and techniques.
  • Improve our security tooling and processes.
  • Conduct security talks and training sessions.
  • Identify critical flaws and weaknesses in our web applications, services and our cloud infrastructure then design and implement strategic solutions to remediate them.
  • Write and review technical proposals, architectural diagrams, application code and IaC.
  • Use automated and manual testing techniques to gain a better understanding of the environment and reduce false negatives.
  • Reduce manual security review efforts by improving our tooling and processes.
  • Improve the scope of our assessments by adding new techniques and new categories of vulnerability assessments.
  • Consolidate and track vulnerabilities across our organization and our supply chain to assist in identifying areas to focus our security uplift efforts.
  • Review and define requirements for developing and deploying secure products; create guidelines and standards to meet these requirements.
  • Work closely with the team to build systems that protect against and eradicate entire classes of vulnerabilities.

Postman provides an API development platform that helps developers, teams, and organizations design, test, document, and monitor APIs. Its tools cover the full API lifecycle: creating API schemas, sending and automating requests, validating responses, generating documentation, and watching API performance in real time. Work happens in shared workspaces so teams can collaborate on API collections, environments, and tests. Pricing is subscription-based with a free tier to attract individuals and convert them to paid plans, plus premium features and enterprise solutions for larger organizations. Compared to others, Postman combines design, testing, documentation, and monitoring in one platform with strong collaboration and a broad user base, making it easier for teams to manage APIs across different projects. The company’s goal is to simplify building and using APIs, enabling real-time data exchange and scalable API development for organizations of all sizes.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$434M

Headquarters

San Francisco, California

Founded

2014

Simplify Jobs

Simplify's Take

What believers are saying

  • 80% of enterprises will use GenAI APIs by 2026, driving Agent Mode adoption.
  • Agent Mode users show consistently higher engagement and retention rates.
  • Git-native Workspaces enable seamless collaboration across distributed development teams.

What critics are saying

  • Claude dependency on Anthropic; pricing shifts or deprioritization eliminate core differentiator.
  • Microsoft Azure integration enables Microsoft to build competing API capabilities in-house.
  • Fortune 500 customers increasingly build proprietary internal API platforms, reducing enterprise ARR.

What makes Postman unique

  • Agent Mode AI integrates Claude, OpenAI, and Microsoft models for unified API workflows.
  • Serves 500,000 organizations including 98% of Fortune 500 with 40M+ developers.
  • Acquired Fern and liblab to consolidate design, testing, documentation, and SDK generation.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Postman who can refer or advise you

Benefits

Accidental Death & Dismemberment Insurance.

Dental Insurance.

Disability Insurance.

Flexible Spending Account (FSA)

Health Savings Account (HSA)

Life Insurance.

Mental Health Care.

Occupational Accident Insurance.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

2%
The Associated Press
Mar 31st, 2026
Postman integrates Anthropic's Claude to bring AI-native API development to 40M developers

Postman, the API platform used by over 40 million developers, has integrated Anthropic's Claude model to power its Agent Mode feature. The AI assistant runs on Amazon Bedrock, providing enterprise-grade security and compliance controls. Agent Mode operates within developers' Postman workspaces, using Claude's reasoning capabilities to generate API collections, debug requests, maintain documentation and keep code synchronised. Developers can also access Postman workspaces directly from Anthropic's tools, including Claude Code and Claude.ai. The integration allows developers to search workspaces, generate client code, run API tests and create mock servers without switching tools. Postman, which serves 500,000 organisations including 98% of Fortune 500 companies, reports that users engaging with Agent Mode show consistently higher usage rates.

The Associated Press
Mar 12th, 2026
Dynatrace and Postman integrate AI-powered observability into API workflows with Agent Mode

Dynatrace has expanded its partnership with Postman to integrate AI-powered observability into Postman's Agent Mode, enabling developers to access real-time production data directly within their API workflows. The Dynatrace Model Context Protocol Server is now available in the Postman API Network. The integration allows developers to connect Agent Mode with Dynatrace observability data, surfacing trusted telemetry and correlating API behaviour with live production information. Teams can test APIs, analyse failures and resolve issues using natural language within a single workflow, reducing friction between development and operations. Postman Agent Mode is an AI agent that helps teams build, test and manage APIs using context from existing collections, code and governance standards. The Dynatrace MCP Server is now available via the Postman API Network.

Pulse 2.0
Jan 8th, 2026
Postman acquires Fern to expand API documentation and SDK capabilities

Postman has acquired Fern, a developer experience company specialising in API documentation and SDK generation, though financial terms were not disclosed. The deal aims to enhance Postman's API collaboration platform as companies increasingly treat APIs as products. Founded in 2022 and based in New York, Fern offers two core products: Fern Docs for customisable API documentation and Fern SDK Generator, which produces client SDKs across nine programming languages. More than 200 companies, including Square, Auth0 and Twilio, use its tools. The entire Fern team will join Postman whilst maintaining Fern's existing product, brand and roadmap. Postman's platform serves over 40 million developers and approximately 500,000 organisations worldwide, including 98% of the Fortune 500, providing Fern with significant distribution reach.

Business Wire
Nov 17th, 2025
Postman Acquires liblab to Accelerate Vision for a Unified API Lifecycle Platform

Postman, the world’s leading API collaboration platform, today announced its acquisition of liblab, a platform for developers that automates the generation a...

Business Wire
Nov 14th, 2025
Postman Acquires liblab to Accelerate Vision for a Unified API Lifecycle Platform

SAN FRANCISCO--(BUSINESS WIRE)--Postman, the world’s leading API collaboration platform, today announced its acquisition of liblab, a platform for developers that automates the generation and maintenance of Software Development Kits (SDKs). With this acquisition, Postman continues to expand its platform to cover the entire API lifecycle—from design and testing to documentation and consumption, enabling developers to build, connect, and consume APIs faster than ever before. “SDKs are essential t

INACTIVE