Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Offensive Security Engineer

$275k - $300k

Postdot Technologies

Who Are We?Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.About the TeamThe Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.The OpportunityWe are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operate as a key partner to CISO leadership on threat-informed defense strategy.This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.You will lead a team that doesn't just "report" vulnerabilities but "demonstrates" them, using live exploits to build a deep, visceral security culture across the entire engineering organization.What You’ll DoStrategy & Program OwnershipSet Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations.Hands-On Technical LeadershipRed Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.People LeadershipLead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning.Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML — a rare and competitive talent market. Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.Communication & InfluenceDrive Security Culture through "The Show": Lead live "Exploitable Demonstrations" — technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments. Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers.Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders. Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings — especially from AI red team engagements — drive measurable improvements in detection, response, and architecture.About YouExperience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems — whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments — extended to AI-native architectures.AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain — including an AI-specific attack path — to a room of developers in a way that is inspiring, not condescending.Engineering Fluency: You prefer building an automated "exploit-as-code" validator over performing the same manual test twice. You can architect evaluation harnesses and adversarial test suites for ML models.PreferredIndustry Presence: Track record of contributions to the offensive security or AI security community — conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.API Security Depth: Experience with API-specific attack methodologies — BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation — reflecting Postman's core product domain.Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence. You don't run GRC, but you know how to feed it.The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. What Else?In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We’re building a long-term company with an inclusive culture where everyone can be the best version of themselves. At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, New York City, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.Our ValuesAt Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.Equal opportunityPostman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Principal Offensive Security Engineer in San Francisco, CA vacancy
  • $181k

    About the roleWe are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime’s services, applications, and infrastructure to discover security issues and report them to our internal technology teams. This... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work

    Chime

    San Francisco, CA
    2 days ago
  • $240k - $310k

    The RoleYou will be the foundational technical pillar for security at Candid Health. As our first Principal Security Engineer, you won't just be managing a compliance checklist—you will architect, build, and scale the technical systems that protect our customers and their... 
    Principal

    Candid Health

    San Francisco, CA
    2 days ago
  • $347k

     ...artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products....  ...robust security culture.About the RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec) team.... 
    Principal
    Work at office
    Local area
    Flexible hours

    OpenAI

    San Francisco, CA
    4 days ago
  •  ...priorities. We can hire people in any country where we have a legal entity. Responsibilities Roles DescriptionThe Principal Enterprise Security Engineer serves as the senior technical authority and strategic thought leader across corporate architecture, SaaS platforms... 
    Principal
    Work at office
    Local area

    Atlassian

    San Francisco, CA
    1 day ago
  •  ...ingenuity of the world’s largest community of security researchers to continuously discover,...  ...point in the security industry. Offensive security is no longer optional - it is the...  ...respect, and accountability.Senior Security Engineer, Detection and ResponseRemote Location:... 
    Suggested
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    1 day ago
  • $153k - $376k

     ...shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the...  ...insights and security tooling.Help run penetration testing and offensive security exercises against Figma’s AI infrastructure,... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours

    Figma

    San Francisco, CA
    2 days ago
  • $230k - $260k

     ....We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows...  ...closely with Engineering, Corporate Security, and Infrastructure, with broad latitude...  ..., SPL, YARA-L, EQL, or Panther.Have an offensive security mindset and have led purple... 
    Local area

    Notion Labs

    San Francisco, CA
    2 days ago
  • $160k - $220k

     ...Join to apply for the Senior Application Security Engineer role at Zip The simple task of buying software, services, or tools at work has...  ...such as SOC 2, ISO 27001, and FedRAMP Hands‑on experience in offensive security (e.g., through bug bounty programs or CTFs) Perks &... 
    Full time
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    1 day ago
  • $160k - $240k

     ...with the help of AI agents, companies can secure the resources they need to innovate...  ...integrity of our customers' data. As a Security Engineer, you'll take on a dynamic, high-impact...  ...and ISO 42001 Hands-on experience in offensive security (eg, through bug bounty... 
    Permanent employment
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    3 days ago
  • $117.2k - $176.7k

     ...the future of Salesforce.The ExperienceThe Product Security team is seeking a Mobile Security Engineer who will own the security posture of Salesforce's mobile...  ...Mobile Device Security Analyst (GMOB), or general offensive certifications such as Offensive Security Certified... 
    Full time

    Salesforce

    San Francisco, CA
    2 days ago
  • $188k - $282k

     ...getting started. Role Overview As a Senior Software Engineer on the Product Security team at Harvey, you'll be a key technical contributor...  ...platform. Our security program is driven by our collective offensive security experience: breaking into systems at other... 
    Work experience placement

    Harvey

    San Francisco, CA
    2 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI

    San Francisco, CA
    1 day ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems... 
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    1 day ago
  • $234.4k - $385k

     ...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are...  ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and... 
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    1 day ago
  • $160k - $240k

     ..., operate, and scale onchain infrastructure. The platform secures over €100B in assets and powers critical operations—including...  ...over 400 global institutions. Our client is seeking a Principal Security Engineer to lead product security across the entire ecosystem. In... 
    Principal
    Full time
    Local area
    Remote work
    Flexible hours

    MLabs

    San Francisco, CA
    6 days ago
  •  ...IT Security Engineer Location(s): Santa Clara, CA; San Francisco, CA; San Diego, CA This position reports to: Director of IT Security...  ...analytical mind for problem solving, abstract thought, and offensive security tactics. Strong interpersonal skills (written and... 

    ClifyX

    San Francisco, CA
    1 day ago
  •  ...Security Engineer LiteLLM is the world's most popular AI Gateway, trusted by top companies like Adobe, Netflix, and NASA. Our platform...  ...level security, maintain secure CI/CD processes, and focus on offensive security improvements. Responsibilities Own all... 
    Worldwide

    BerriAI

    San Francisco, CA
    20 hours ago
  • $230k - $385k

     ...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are...  ...security culture.About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects... 
    Work at office
    Local area
    Flexible hours

    OpenAI

    San Francisco, CA
    2 days ago
  • $189k - $303k

     ...get crucial goods where they need to go, and make mobility more efficient and accessible for all. We’re searching for a Staff Security Engineer, Enterprise Security Architecture.This position is open to the following office locations: Mountain View, San Francisco, Seattle... 
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    San Francisco, CA
    1 day ago
  • $148.5k - $260.1k

     ...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain the security of using AI tooling securely.In this role,... 
    Full time

    Salesforce

    San Francisco, CA
    1 day ago
  • $180k - $247k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of...  ...to you.The Staff Product Security Engineer OpportunityThe Security team's mission is...  ...scale defense. This is a hybrid research, offensive and software engineering role centered on... 
    Local area
    Worldwide
    Flexible hours

    Okta

    San Francisco, CA
    2 days ago
  • $250k - $285k

     ...with us at Crusoe.About This RoleWe’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s...  ...engineering teams rely on.You’ll operate at the intersection of offensive security, AI systems, and production engineering; owning... 
    Temporary work

    Crusoe

    San Francisco, CA
    2 days ago
  •  ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on senior security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of... 
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    San Francisco, CA
    4 days ago
  •  ...Persona builds identity verification infrastructure where security isn't a layer we add later, it's core to everything we ship. When...  ...generalist security team. You'll work alongside experienced security engineers to defend Persona's people, devices, and systems against... 
    Full time
    For contractors
    Internship
    Work at office
    Work from home
    Relocation package
    Monday to Friday
    Flexible hours

    Persona Identities, Inc

    San Francisco, CA
    2 days ago
  •  ...Corporate Security Engineer Millions of people rely on Notion to do their most important work. Protecting that trust starts with protecting the people who build Notion: our employees, their laptops, their identities, and the SaaS apps they rely on every day. We are... 
    Local area

    Notion, LLC

    San Francisco, CA
    3 days ago
  • $300k - $405k

     ...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build...  .... In this role, you will have the opportunity to shape our security capabilities from the ground up alongside our world-class research... 
    Full time
    Work at office
    Visa sponsorship
    Flexible hours

    Anthropic

    San Francisco, CA
    1 day ago
  • $220k

     ...Combinator, Bessemer Venture Partners, and Craft Ventures.The Security Team @ PaveSecurity at Pave protects the world's largest real-time...  ...everyone flexes across domains. As Pave's Corporate Security Engineer, you'll own the corporate side of that mission: identity and access... 
    Work at office
    Flexible hours
    3 days per week

    Trove Information Technologies

    San Francisco, CA
    1 day ago
  • $200k - $225k

     ...looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time representative on JLL's Falcon team, owning the product's security... 
    Full time
    Local area
    Immediate start
    Remote work

    Jones Lang LaSalle

    San Francisco, CA
    2 days ago
  • $130k

    About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security, infrastructure security, enterprise security, and security/compliance automation. This is a hands-on, high-impact role for... 
    Full time
    Work at office
    Local area
    Remote work

    Chime

    San Francisco, CA
    4 days ago
  • $189k - $303k

     ...get crucial goods where they need to go, and make mobility more efficient and accessible for all.We're searching for a Staff Security Engineer to join our Enterprise Security Engineering team, reporting to the Technical Lead Manager of Security Engineering.This position... 
    Work at office
    Local area
    3 days per week
    Early shift

    Aurora Innovation

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Offensive Security Engineer. Be the first to apply!