yandex
postman
Страна
США
Зарплата
250 000 $ – 275 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
В офисеПолная занятость

Staff Security Engineer

Оценка ИИ

Отличная вакансия в компании-единороге с высокой зарплатой, сильным брендом и сложными техническими задачами. Единственный минус для некоторых — требование работы из офиса 5 дней в неделю.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена требованием к опыту более 10 лет, необходимостью глубокой экспертизы в безопасности API и облачных технологий, а также лидерской ролью в крупной международной компании.

Анализ зарплаты

Медиана245 000 $
Рынок210 000 $ – 285 000 $
Оценка ИИ

Предлагаемая зарплата ($250k - $275k) находится на верхнем уровне рыночного диапазона для Staff-позиций в Сан-Франциско, что в сочетании с опционами делает предложение крайне конкурентоспособным.

Сопроводительное письмо

Dear Postman Hiring Team,

I am writing to express my strong interest in the Staff Security Engineer position. With over a decade of experience in security architecture and a deep focus on cloud-native environments, I have consistently demonstrated my ability to secure complex distributed systems and APIs. My background in integrating DevSecOps principles into CI/CD pipelines and my expertise in AWS and Kubernetes align perfectly with Postman's mission to provide a secure and robust API platform.

Throughout my career, I have led threat modeling initiatives and developed long-term security strategies that balance rigorous protection with business agility. I am particularly drawn to Postman's commitment to an API-first world and would welcome the opportunity to mentor your engineering teams while evolving the security architecture of your world-class product line. I am eager to bring my technical leadership and passion for security to your San Francisco office.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в postman уже сейчас

Присоединяйтесь к лидеру индустрии API и станьте ключевым архитектором безопасности для 45 миллионов пользователей!

Описание вакансии

Who Are We?

Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.

The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.

P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.

The Opportunity

As a Staff Security Engineer at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.

What You’ll Do

  • Security Architecture Design: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies.
  • Threat Modeling & Risk Assessment: Lead threat modelling and risk assessments to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.
  • Technology Review & Evaluation: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.
  • Security Strategy: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.
  • Incident Response: Work closely with the SOC to understand gaps in product architecture.
  • Mentorship & Leadership: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.

About You

  • Experience:

+ 10+ years in a security architecture role with a focus on software products and platforms.

+ Experience working within fast-paced, cloud-native environments.

+ Proven experience with securing distributed systems, microservices, and APIs.

+ Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR)

+ Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.

+ In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud)

  • Communication & Leadership:

+ Strong ability to communicate complex security concepts to both technical and non-technical stakeholders.

+ Experience working cross-functionally with product, engineering, and operations teams.

+ Proven leadership in driving security initiatives and integrating security into product development lifecycles.

  • Preferred Skills:

+ Experience with API security, including OAuth, JWT, and OpenID Connect.

+ Knowledge of container security (Docker, Kubernetes).

+ Familiarity with security automation tools and methodologies (e.g., SAST, DAST, RASP).

+ Technical industry certifications such as OSCP, GPEN etc…

The reasonably estimated base salary for this role ranges from $250,000 to $275,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience.

What Else?

In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We’re building a long-term company with an inclusive culture where everyone can be the best version of themselves.

At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.

Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

Equal opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Security Architecture
  • Cloud Security
  • API Security
  • Threat Modeling
  • Risk Assessment
  • DevSecOps
  • CI/CD
  • AWS
  • Azure
  • Google Cloud Platform
  • ISO 27001
  • SOC 2
  • GDPR
  • OAuth
  • JWT
  • OpenID Connect
  • Docker
  • Kubernetes
  • SAST
  • DAST
  • RASP

Возможные вопросы на собеседовании

Проверка опыта работы с основным продуктом компании и понимания специфических рисков.

Какие наиболее критические уязвимости вы видите в архитектуре современных публичных API и как бы вы их минимизировали в Postman?

Оценка навыков стратегического планирования и интеграции безопасности в процессы разработки.

Опишите ваш подход к внедрению DevSecOps в зрелую инженерную культуру: с чего вы начнете и как будете измерять успех?

Проверка практического опыта в моделировании угроз.

Проведите краткий сеанс threat modeling для микросервисной архитектуры, использующей OAuth 2.0 и JWT. На что вы обратите внимание в первую очередь?

Оценка лидерских качеств и умения работать с кросс-функциональными командами.

Как вы убеждаете команду разработчиков внедрить критическое изменение в архитектуру безопасности, если это замедляет выпуск новой фичи?

Проверка знаний в области комплаенса и стандартов.

Как вы обеспечиваете соответствие архитектуры требованиям GDPR и SOC 2 при работе в мультиоблачной среде (AWS/Azure/GCP)?

Похожие вакансии

SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
250 000 ₽ – 450 000 ₽

Эксперт по защите периметра (WAF)

УдалённоРоссия
WAF · Wallarm · Positive Technologies Application Firewall · NGFW · IPS · Vulnerability Assessment · Network Security
+7 навыков
Квазар
до 350 000 ₽

DevOps-инженер/ИБ (devops engineer, information security)

УдалённоРоссия
TCP/IP · DNS · DHCP · HTTPS · SMTP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · ELK · Wazuh · Grafana · Bash · PowerShell · Python · VMware · Proxmox · Hyper-V · KVM · SoC
+24 навыков
Атом Безопасность
200 000 ₽ – 400 000 ₽

Application Security Еngineer (AppSec)

УдалённоРоссия
C++ · Rust · JavaScript · Python · TypeScript · SAST · DAST · SCA · ASOC · CI/CD · GitLab CI · Docker · Fuzzing · Threat Modeling
+14 навыков
ХАКСКИ КОНСАЛТИНГ
280 000 ₽ – 350 000 ₽

Инженер по сетевой безопасности

УдалённоРоссия
NGFW · UTM · Proxy · IDS · IPS · VPN · ACL · iptables · Routing · Switching · Network Security · IP
+12 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

postman
Страна
США
Зарплата
250 000 $ – 275 000 $