Staff Security Architect

3 Months ago • 15 Years + • Cyber Security • $250,000 PA - $350,000 PA

About the job

Job Description

Postman seeks a Staff Security Architect to lead security architecture across its product lines. You'll design secure systems, conduct threat modeling, and collaborate with product teams to ensure robust security. Experience with cloud technologies and DevSecOps is essential.
Must have:
  • Security Architecture
  • Cloud Technologies
  • Threat Modeling
  • DevSecOps
Good to have:
  • API Security
  • Container Security
  • Security Automation
  • Industry Certifications
Perks:
  • Competitive Equity
  • Comprehensive Benefits

Who Are We?

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

The Opportunity

As a Staff Security Architect at Postman, you will be responsible for developing, maintaining, and evolving the security architecture across Postman’s product lines. This role requires a deep understanding of security principles, cloud technologies, and product security best practices. You will work closely with product teams, engineering, and DevOps to integrate security into the architecture, ensuring robust protection against threats.

What You’ll Do:

  • Security Architecture Design: Collaborate with product teams to maintain a security architecture framework that supports the secure deployment of Postman products and services. This includes in advising GRC / Legal on Security policies.

  • Threat Modeling & Risk Assessment: Lead threat modeling and risk assessment to identify security vulnerabilities in existing and new systems. Recommend appropriate mitigation strategies.

  • Technology Review & Evaluation: Evaluate new technologies and architectures from a security perspective, ensuring they meet security requirements.

  • Security Strategy: Contribute to the development of long-term security strategy and roadmaps, ensuring alignment with product goals and business objectives.

  • Incident Response: Work closely with the SOC to understand gaps in product architecture. 

  • Mentorship & Leadership: Mentor and provide guidance to junior security engineers and architects on security architecture principles and best practices.

About You:

Experience:

  • 15+ years in a security architecture role with a focus on software products and platforms.
  • Experience working within fast-paced, cloud-native environments.
  • Proven experience with securing distributed systems, microservices, and APIs.
  • Demonstrated knowledge of security frameworks, industry standards, and regulations (EX: ISO 27001, SOC 2, GDPR)
  • Hands-on experience with DevSecOps principles and integration of security within CI/CD pipelines.
  • In-depth knowledge of cloud security best practices on the following platforms (AWS, Azure, Google Cloud

Communication & Leadership:

  • Strong ability to communicate complex security concepts to both technical and non-technical stakeholders.
  • Experience working cross-functionally with product, engineering, and operations teams.
  • Proven leadership in driving security initiatives and integrating security into product development lifecycles.

Prefered Skills: 

  • Experience with API security, including OAuth, JWT, and OpenID Connect.

  • Knowledge of container security (Docker, Kubernetes).

  • Familiarity with security automation tools and methodologies (e.g., SAST, DAST, RASP).

  • Technical industry certifications such as OSCP, GPEN etc.

Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

What Else?

If the role is based in the greater San Francisco area, and the we are offering a base salary range of $250,000 to $350,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.

Equal Opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

View Full Job Description
$250.0K - $350.0K/yr (Outscal est.)
$300.0K/yr avg.
San Francisco, California, United States

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Central Sulawesi, Indonesia (Remote)

San Francisco, California, United States (On-Site)

Toronto, Ontario, Canada (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

New York, New York, United States (On-Site)

Bengaluru, Karnataka, India (On-Site)

San Francisco, California, United States (Hybrid)

San Francisco, California, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Postman

Similar Jobs

Codeninja - Senior PHP Engineer / Lead

Codeninja, Pakistan (On-Site)

Demonware - Data Engineering Co-op

Demonware, Canada (Hybrid)

Crunchyroll - Senior Software Engineer

Crunchyroll, (Remote)

Zscaler - Senior Backend Engineer

Zscaler, India (Hybrid)

Ajmera Infotech - SENIOR ASP.NET DEVELOPER

Ajmera Infotech, India (On-Site)

PwC - Intern/ Trainee

PwC, India (On-Site)

PwC - Digital Asset Manager

PwC, Jordan (On-Site)

Infoblox - Resident Engineer

Infoblox, United States (On-Site)

Zones - SOC Analyst L2

Zones, India (On-Site)

PwC - IT Project Management

PwC, Portugal (On-Site)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

ByteDance - Senior Site Reliability Engineer, ML System

ByteDance, United States (On-Site)

Ubisoft - Fullstack Engineer Assistant

Ubisoft, France (On-Site)

Take-Two Interactive - Data Engineer (AWS DevOps)

Take-Two Interactive, India (On-Site)

PlayStation Global - Manager - Data Engineering

PlayStation Global, Germany (On-Site)

Demonware - Data Engineering Co-op

Demonware, Canada (Hybrid)

Avalara - Senior Site Reliability Engineer

Avalara, India (Remote)

Get notifed when new similar jobs are uploaded

Jobs in San Francisco, California, United States

Regent Craft - Aerodynamics Engineering Intern - (CFD)

Regent Craft, United States (On-Site)

PTW - Video Game Tester - Gaming

PTW, United States (On-Site)

CD Project Red - Lead Technical Artist

CD Project Red, United States (Hybrid)

On Location - Account Manager, USC Athletics

On Location, United States (On-Site)

Blinkhealth - Pharmacy Insurance Claims Specialist (ON SITE)

Blinkhealth, United States (On-Site)

Samsung Semiconductor - NVMe Test Engineer (Contractor)

Samsung Semiconductor, United States (Hybrid)

Axinous - Senior Data Center Operations (DCO) Engineer

Axinous, United States (Remote)

Keywords Studios (Player Support) - Business Development Manager - Audio Development

Keywords Studios (Player Support), United States (On-Site)

Fluence - Lead Engineer - Advanced Battery Modules

Fluence, United States (Hybrid)

Next Level Business Services - SQL Developer

Next Level Business Services, United States (On-Site)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Ziff Davis - Enterprise Security Director

Ziff Davis, United States (On-Site)

ARHS - Application Security Expert

ARHS, Netherlands (On-Site)

ByteDance - Senior SRE Architect, Security Engineering

ByteDance, Singapore (On-Site)

Microsoft - Principal Product Manager

Microsoft, (Remote)

Warner Bros Discovery - Sr. Cybersecurity Engineer

Warner Bros Discovery, United States (Hybrid)

Get notifed when new similar jobs are uploaded