Principal Offensive Security Engineer
$275k - $300kPostman
Who Are We?Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.About the TeamThe Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.The OpportunityWe are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operate as a key partner to CISO leadership on threat-informed defense strategy.This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.You will lead a team that doesn't just "report" vulnerabilities but "demonstrates" them, using live exploits to build a deep, visceral security culture across the entire engineering organization.What You’ll DoStrategy & Program OwnershipSet Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations.Hands-On Technical LeadershipRed Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.People LeadershipLead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning.Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML — a rare and competitive talent market. Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.Communication & InfluenceDrive Security Culture through "The Show": Lead live "Exploitable Demonstrations" — technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments. Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers.Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders. Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings — especially from AI red team engagements — drive measurable improvements in detection, response, and architecture.About YouExperience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems — whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments — extended to AI-native architectures.AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain — including an AI-specific attack path — to a room of developers in a way that is inspiring, not condescending.Engineering Fluency: You prefer building an automated "exploit-as-code" validator over performing the same manual test twice. You can architect evaluation harnesses and adversarial test suites for ML models.PreferredIndustry Presence: Track record of contributions to the offensive security or AI security community — conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.API Security Depth: Experience with API-specific attack methodologies — BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation — reflecting Postman's core product domain.Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence. You don't run GRC, but you know how to feed it.The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. What Else?In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We’re building a long-term company with an inclusive culture where everyone can be the best version of themselves. At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, New York City, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.Our ValuesAt Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.Equal OpportunityPostman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.SummaryLocation: San Francisco, CA, USType: Full time
$300k - $320k
...growing group of committed researchers, engineers, policy experts, and business leaders working... ...AI systems. About the Team The Security Engineering team's mission is to... ...hands-on experience in red teaming and offensive security operations ~ Deep expertise in...SuggestedVisa sponsorship$220k - $280k
...-office by design. For example, our engineering team in India works primarily from our... .... Role We’re looking for a Principal Information Security Engineer to lead and elevate security... ...assisted and agent-based tooling to scale offensive security testing beyond what a small...PrincipalWork at officeRemote workHome officeFlexible hours- ...aware that all official communication will only be sent from @Rippling.com addresses.About the roleRippling is looking for a Principal Security Engineer to tackle some of the most complex, cross-cutting security challenges across our technical ecosystem. Reporting directly...PrincipalWork at office3 days per week
$172.5k - $313.7k
...in the right place! Agentforce is the future of AI, and you are the future of Salesforce.Job Title: Principal Engineer, Product SecurityThe ExperienceThe Product Security team sits within Trust & Security, partnering closely with engineering across Salesforce's fastest-...PrincipalFull time$240k - $310k
The Role You will be the foundational technical pillar for security at Candid Health. As our first Principal Security Engineer, you won't just be managing a compliance checklist—you will architect, build, and scale the technical systems that protect our customers and their...Principal- Principal Engineer, Product Security Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it is changing...Principal
$172.5k - $344.7k
...era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. Job Title: Principal Engineer, Product Security The Experience The Product Security team sits within Trust & Security, partnering closely with engineering...PrincipalFull time- ...across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services... ...on IoT hardware in the field. As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our...Full timeRemote work
- Senior Cloud, AI & Data Security Engineer We are seeking an enthusiastic and passionate professional for a Senior Cloud, AI & Data Security Engineer role who wants to design and implement security solutions for systems and services across AWS, Azure, and AI/ML platforms...Principal
$184k - $304k
...hire. This position is ineligible for employment Visa sponsorship. Job Description Overall Purpose The Principal Platform Security Engineer is a hands-on enterprise technical leader responsible for defining the long-term technical vision, secure target states...PrincipalHourly payFull timeWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...Team to continuously stress-test our own infrastructure. As a security engineer, you won't just be ticking compliance boxes; you will be... ..., gas metering, and precompiles. Proven track record of offensive security, such as high rankings in CTFs (e.g., Paradigm CTF)...Full time
$166.6k - $212.8k
...underserved communities around the world.We are a specialized security team that sits inside a global satellite communications business... ...- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 4+ years of IT Security experience- 1+ years...Permanent employmentLocal areaImmediate startFlexible hoursShift work$200k - $300k
...Job Description Job Description Senior/Staff Security Engineer Company: Init Intelligence Location: San Francisco, CA - in person... ...: container security, kernel-level hardening, microVMs Offensive security or penetration testing experience Has run or owned...Full timeH1bWork at officeVisa sponsorshipMonday to Friday$188.75k - $242.68k
...Washington D.C., Raleigh, London, and Amsterdam.The Platform Security team (PlatSec) defends Plaid against attackers. We own laptop... ...teamSoftware security review, SDLC, vulnerability discovery, and/or offensive security experienceOur mission at Plaid is to unlock financial...Work experience placementWork at officeLocal area- ...Description Job Description About the Role This is a founding security engineering position at a fast-growing AI/ML infrastructure company,... ...through CVEs, security tooling, or bug bounty work. ~ Offensive security experience (bug bounty, pentesting, or red-team...Visa sponsorshipRelocation package
- ...Discord is seeking a Senior Software Engineer for the Application Security team to protect user accounts. You will design and implement full‑stack security solutions, strengthen session security, and own authentication services for hundreds of millions of users. With...Remote job
- ...Serve as a subject matter expert in network security, focusing on firewalls, VPNs, and routing/switching technologies within cloud-native AI infrastructure. Manage and update firewall configurations across the enterprise network to align with security needs. Deploy...
$268k - $321k
...Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable, pre-IPO fintech company on a mission to empower... ...define the strategy, sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI agents writing code alongside...Local area$172k - $215k
...to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Security Engineer on the Security Operations team, you will help Ripple detect, investigate, and respond to security threats across our...Full timeWork at officeLocal area- ...The role involves owning application security for a multi-tenant AI platform and embedding security controls into the software development... ...need over 4 years of experience in security or software engineering with proficiency in GCP, Python, and Kubernetes. Experience with...
$155.58k - $320.32k
...read more about our AI interview philosophy and how we use AI in our recruiting process here.We’re looking for a Senior Security Software Engineer to provide technical leadership within Security Operations. You’ll own and evolve foundational platforms that help Pinterest...Work at officeLocal areaRemote workRelocationRelocation package- ...and help support some of the most important innovation happening in healthcare today! The Role We’re looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our...Flexible hours
- ...Overview We are looking for a seasoned Senior / Staff Network Security Engineer to spearhead our security strategy and defend our fast-growing cloud platform. You will design and deploy advanced safeguards concentrated on the network perimeter, ensuring our edge remains...Full time
$200k - $330k
...This is a senior individual contributor role owning application security for a rapidly scaling, multi-tenant AI agent platform that... ...enterprise customers. You will sit at the intersection of product engineering and security, embedding secure practices across the full...$128.9k - $180k
...at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you. WHAT YOU'LL DO As a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees, their assets, and work locations using various tools and technologies...Full timeWork at officeFlexible hours$172.5k - $313.7k
...the agentic era? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce.The MeshMesh Security Engineer safeguards the platform and its customers by building security into every layer of the system, from infrastructure to application...Full time- ...official communication will only be sent from @Rippling.com addresses. About The Role We're looking for a hands‑on senior security engineer to play a key role in building Rippling's Product Security program. Rippling's product's scope provides a unique set of...Work at officeRelocation3 days per week1 day per week
- ...what’s best for our customers. Cohere is a team of researchers, engineers, designers, and more, who are passionate about their craft.... ...is a requirement for building great products. As a Senior Security Engineer you will Serve as trusted advisor to team’s leadership...Full timeWork at officeRemote workFlexible hours
$166k - $185k
...our founding vision and unlock world-class medicine through world-class operations. About The Role We're looking for a Security Engineer to own the design and buildout of Qventus' cloud and data security tooling. This role will be responsible for driving engineering...Local area$74.79 - $86.4 per hour
...Daly City, CA 94014 Position Type: Full Time Salary Range: $74.79 - $86.40 Hourly SUMMARY OF POSITION The Senior Security Engineer is responsible for designing, implementing, and governing NEMS enterprise security architecture across all clinic sites, data...Hourly payFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Offensive Security Engineer. Be the first to apply!
- principal developer San Francisco, CA
- principal security engineer San Francisco, CA
- senior director engineering San Francisco, CA
- director of product engineering San Francisco, CA
- data center chief engineer San Francisco, CA
- engineering director San Francisco, CA
- principal network engineer San Francisco, CA
- hotel chief engineer San Francisco, CA
- principal cloud engineer San Francisco, CA
- principal infrastructure engineer San Francisco, CA




