Full-Time

Principal Offensive Security Engineer

Postman

Postman

1,001-5,000 employees

API development, testing, docs, monitoring platform

Compensation Overview

$275k - $300k/yr

+ Equity

San Francisco, CA, USA

In Person

In-office 5 days/week for SF Bay Area hub; Bangalore transitioning from 3 to 5 days/week by year-end.

Category
IT & Security
Required Skills
Vulnerability Analysis
Penetration Testing

Get referred to Postman

See people who can refer or advise you

Requirements
  • Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.
  • Demonstrated experience attacking AI/ML systems — whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.
  • Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.
  • Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments — extended to AI-native architectures.
  • Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.
  • You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain — including an AI-specific attack path — to a room of developers in a way that is inspiring, not condescending.
  • You prefer building an automated
Responsibilities
  • Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
  • Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.
  • Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations.
  • Red Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.
  • Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.
  • Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.
  • Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning.
  • Recruit for the Future: Identify and hire talent at intersection of offensive security and AI/ML — build pipeline including internal development paths for existing security engineers to cross-skill into AI red teaming.
  • Drive Security Culture through
Desired Qualifications
  • Industry Presence: Track record of contributions to the offensive security or AI security community — conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.
  • Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.
  • Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.
  • API Security Depth: Experience with API-specific attack methodologies — BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation.
  • Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence.

Postman provides an API development platform that helps developers, teams, and organizations design, test, document, and monitor APIs. Its tools cover the full API lifecycle: creating API schemas, sending and automating requests, validating responses, generating documentation, and watching API performance in real time. Work happens in shared workspaces so teams can collaborate on API collections, environments, and tests. Pricing is subscription-based with a free tier to attract individuals and convert them to paid plans, plus premium features and enterprise solutions for larger organizations. Compared to others, Postman combines design, testing, documentation, and monitoring in one platform with strong collaboration and a broad user base, making it easier for teams to manage APIs across different projects. The company’s goal is to simplify building and using APIs, enabling real-time data exchange and scalable API development for organizations of all sizes.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$434M

Headquarters

San Francisco, California

Founded

2014

Get referred to Postman

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Postman won AWS AI Competency on 2026-06-17, validating enterprise AI positioning.
  • Postman added Microsoft Foundry, Azure API Management, and Teams integrations on 2026-04-16.
  • Fern and liblab acquisitions in 2025-2026 expand monetizable surface area across the API lifecycle.

What critics are saying

  • Microsoft Foundry and Azure API Management make Postman redundant inside enterprise stacks.
  • AWS Bedrock and Kiro integrations deepen platform dependence on hyperscalers and their roadmaps.
  • If AI coding tools absorb API workflows, Postman becomes a niche utility by 2028.

What makes Postman unique

  • Postman unifies API design, testing, documentation, and consumption across 40 million developers.
  • Agent Mode and MCP turn Postman into AI-native API infrastructure inside development workflows.
  • Fern and liblab acquisitions extend Postman from collaboration into SDKs and documentation.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Accidental Death & Dismemberment Insurance.

Dental Insurance.

Disability Insurance.

Flexible Spending Account (FSA)

Health Savings Account (HSA)

Life Insurance.

Mental Health Care.

Occupational Accident Insurance.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

1%
Associated Press
Jun 17th, 2026
Postman achieves AWS AI Competency and launches Kiro integration for AI-native API development

Postman, used by over 40 million developers and 500,000 organisations including 98% of the Fortune 500, has achieved AWS AI Competency in the Agentic AI Tools category. The designation recognises Postman's expertise in enabling organisations to build, test and manage APIs that power AI systems on AWS. The company introduced a new integration with Kiro, AWS's agentic IDE, alongside deeper integrations with Amazon Bedrock and Amazon API Gateway. Postman's MCP server enables developers to access API context, generate code, run tests and create mock servers directly within Kiro. Postman's AI assistant, Agent Mode, now runs on Anthropic Claude via Amazon Bedrock, providing enterprise-grade security and compliance. The company also announced general availability of its API Catalog integration with Amazon API Gateway.

Yahoo Finance
Apr 16th, 2026
Postman expands AI model choice with Microsoft Foundry, integrates Azure API Management

Postman has announced a collaboration with Microsoft to expand AI capabilities and API governance tools for developers. The company's Agent Mode now supports OpenAI models on Microsoft Foundry, giving teams flexibility in choosing AI models whilst maintaining security and compliance controls. The partnership introduces integrations with Azure API Management and Microsoft Teams to enhance collaboration. Agent Mode, an AI-powered assistant built into Postman, provides reasoning capabilities from leading model providers and is designed to streamline API workflows across the full development lifecycle. The collaboration aims to help enterprise development teams move from API discovery to production with unified, AI-powered tools. Postman CEO Abhinav Asthana said the integration gives platform engineering teams flexibility to deploy AI workflows without sacrificing governance and test coverage needed for trustworthy agents at scale.

Associated Press
Mar 31st, 2026
Postman integrates Anthropic's Claude to bring AI-native API development to 40M developers

Postman, the API platform used by over 40 million developers, has integrated Anthropic's Claude model to power its Agent Mode feature. The AI assistant runs on Amazon Bedrock, providing enterprise-grade security and compliance controls. Agent Mode operates within developers' Postman workspaces, using Claude's reasoning capabilities to generate API collections, debug requests, maintain documentation and keep code synchronised. Developers can also access Postman workspaces directly from Anthropic's tools, including Claude Code and Claude.ai. The integration allows developers to search workspaces, generate client code, run API tests and create mock servers without switching tools. Postman, which serves 500,000 organisations including 98% of Fortune 500 companies, reports that users engaging with Agent Mode show consistently higher usage rates.

Associated Press
Mar 12th, 2026
Dynatrace and Postman integrate AI-powered observability into API workflows with Agent Mode

Dynatrace has expanded its partnership with Postman to integrate AI-powered observability into Postman's Agent Mode, enabling developers to access real-time production data directly within their API workflows. The Dynatrace Model Context Protocol Server is now available in the Postman API Network. The integration allows developers to connect Agent Mode with Dynatrace observability data, surfacing trusted telemetry and correlating API behaviour with live production information. Teams can test APIs, analyse failures and resolve issues using natural language within a single workflow, reducing friction between development and operations. Postman Agent Mode is an AI agent that helps teams build, test and manage APIs using context from existing collections, code and governance standards. The Dynatrace MCP Server is now available via the Postman API Network.

Pulse 2.0
Jan 8th, 2026
Postman acquires Fern to expand API documentation and SDK capabilities

Postman has acquired Fern, a developer experience company specialising in API documentation and SDK generation, though financial terms were not disclosed. The deal aims to enhance Postman's API collaboration platform as companies increasingly treat APIs as products. Founded in 2022 and based in New York, Fern offers two core products: Fern Docs for customisable API documentation and Fern SDK Generator, which produces client SDKs across nine programming languages. More than 200 companies, including Square, Auth0 and Twilio, use its tools. The entire Fern team will join Postman whilst maintaining Fern's existing product, brand and roadmap. Postman's platform serves over 40 million developers and approximately 500,000 organisations worldwide, including 98% of the Fortune 500, providing Fern with significant distribution reach.