Jobs · Information Technology · California

Principal Offensive Security Engineer

Postman · San Francisco, CA · 1 mo ago
Information Technology$275k–$300k/yrFull-time

Postman is the world’s leading API platform, used by more than 45 million developers and 500,000 organizations, including 98% of the Fortune 500. We simplify each step of the API lifecycle and streamline collaboration to help users create better APIs, faster.

About The Team

The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. The Offensive Security team is the "red" pulse of this organization, simulating the adversary to ensure defenses hold up under real-world pressure. The team focuses on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.

The Opportunity

We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program, including building a dedicated Offensive AI Security capability from the ground up. This role involves shaping the offensive security program for the next three years, with a focus on making Postman an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.

Responsibilities

  • Strategy & Program Ownership
    • Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
    • Build and scale a dedicated offensive capability targeting AI/ML systems, including adversarial testing of LLM integrations, agentic workflows, RAG pipelines, and model-serving infrastructure.
    • Develop AI threat intelligence by tracking and operationalizing the rapidly evolving AI threat landscape (e.g., OWASP LLM Top 10, MITRE ATLAS) into internal red team playbooks and detection hypotheses.
  • Hands-On Technical Leadership
    • Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines, targeting prompt injection, tool-use abuse, data exfiltration, training data poisoning, and model manipulation.
    • Design and deploy AI-based penetration testing platforms and autonomous agents for continuous security validation across the API ecosystem.
    • Integrate automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.
  • People Leadership
    • Build, manage, and scale a high-performing team of offensive security engineers, including specialized AI red team operators, providing mentorship and career development.
    • Recruit talent at the intersection of offensive security and AI/ML, including internal cross-skilling paths for existing security engineers.
  • Communication & Influence
    • Drive security culture through live "Exploitable Demonstrations" that show how vulnerabilities could be leveraged, with a focus on demystifying AI-specific attack vectors.
    • Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders.
    • Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).
    • Operate as a senior technical leader across Product Security, Security Operations, and Engineering to drive improvements in detection, response, and architecture.

Requirements

  • Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity.
  • Demonstrated experience attacking AI/ML systems, including adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets.
  • Strategic acumen in building and scaling an offensive security program from the ground up, including setting OKRs, managing budgets, and presenting to executive leadership.
  • Deep understanding of the modern threat landscape and its application to cloud-native, API-first, and AI-native architectures.
  • Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak).
  • Ability to architect evaluation harnesses and adversarial test suites for ML models, with a preference for building automated "exploit-as-code" validators.
  • Familiarity with cloud security primitives, cloud-native attack paths, and container/Kubernetes exploitation, particularly in AWS.
  • Experience with API-specific attack methodologies (e.g., BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation).
  • Understanding of how offensive security outputs map to compliance frameworks (e.g., SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, CMMC).

Preferred Qualifications

  • Track record of contributions to the offensive security or AI security community, such as conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or participation in OWASP/MITRE working groups.
  • Offensive security certifications (e.g., OSCP, OSCE, OSEP, GXPN, GPEN, CRTP) or AI/ML-specific credentials (e.g., GIAC GMAI).
  • Pragmatic storytelling skills to present complex exploit chains, including AI-specific attack paths, in an engaging and inspiring manner.

Pay

The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience.

Benefits

  • Full medical coverage.
  • Flexible PTO.
  • Wellness reimbursement.
  • Monthly lunch stipend.
  • Wellness programs for physical and mental health.
  • Frequent team-building events.
  • Donation-matching program.

Schedule

This role is in-office 5 days a week for all roles based out of Postman’s hubs in the San Francisco Bay Area, Boston, Austin, New York City, Tokyo, and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year.

Similar jobs