Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Offensive Security Manager

$275k - $300k

Postdot Technologies

Who Are We?

Postman is the world's leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration-enabling users to create better APIs, faster.

The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.

P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.

About the Team

The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.

The Offensive Security team is the "red" pulse of this organization. We don't just find bugs - we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.
The Opportunity

We are looking for a Senior Manager, Offensive Security who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program - including building out a dedicated Offensive AI Security capability from the ground up - and operate as a key partner to CISO leadership on threat-informed defense strategy.

This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.

You will lead a team that doesn't just "report" vulnerabilities but "demonstrates" them, using live exploits to build a deep, visceral security culture across the entire engineering organization.
What You'll Do
Strategy & Program Ownership
  • Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
  • Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.
  • Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape - OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems - translating external research into internal red team playbooks and detection hypotheses for Security Operations.
Hands-On Technical Leadership
  • Red Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines - targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.
  • Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.
  • Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.
People Leadership
  • Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers - including specialized AI red team operators - providing mentorship, career development, and succession planning.
  • Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML - a rare and competitive talent market. Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.
Communication & Influence
  • Drive Security Culture through "The Show": Lead live "Exploitable Demonstrations" - technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments. Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers.
  • Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders. Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).
  • Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings - especially from AI red team engagements - drive measurable improvements in detection, response, and architecture.
About You
  • Experience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.
  • AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems - whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.
  • Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.
  • Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments - extended to AI-native architectures.
  • AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.
  • Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain - including an AI-specific attack path - to a room of developers in a way that is inspiring, not condescending.
  • Engineering Fluency: You prefer building an automated "exploit-as-code" validator over performing the same manual test twice. You can architect evaluation harnesses and adversarial test suites for ML models.
Preferred
  • Industry Presence: Track record of contributions to the offensive security or AI security community - conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.
  • Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.
  • Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.
  • API Security Depth: Experience with API-specific attack methodologies - BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation - reflecting Postman's core product domain.
  • Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence. You don't run GRC, but you know how to feed it.

The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience.


What Else?

In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We're building a long-term company with an inclusive culture where everyone can be the best version of themselves.


At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.
Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
Equal opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.
Vacancy posted 6 hours ago
Similar jobs that could be interesting for youBased on the Senior Offensive Security Manager in San Francisco, CA vacancy
  •  ...ideas into reality. We Are Platform Security professionals develop and deliver solutions...  ...based security, and ERP vulnerability management solutions that minimize the impact of internal...  ...the strategic direction set by senior management as it relates to team goals.... 
    Senior
    Contract work
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    San Francisco, CA
    2 days ago
  •  ...Senior Director of Product Management (Identity Security Posture Management) Saviynt's AI-powered identity platform manages and governs human, non-human and AI access to all of an organization's applications, data, and business processes. Customers trust Saviynt to... 
    Senior
    Temporary work

    Saviynt

    San Francisco, CA
    2 days ago
  •  ...Health & Public Services Security Senior Manager Job Location Negotiable: (Northeast, West, Southwest) (Salary open) - CA - Sacramento, CA - San Francisco, CA - San Jose, NY - New York, TX - Austin Notes: Security H&PS Senior Manager/CL6 – Demand of 2 open – For... 
    Senior
    Local area

    ClifyX

    San Francisco, CA
    13 hours ago
  • $143k - $191k

     ...Senior Data Center Security Site Evaluation Program Manager Livingon, NJ / New York, NY / Sunnyvale, CA / San Francisco, CA / Bellevue, WA / Richmond, VA / Dallas, TX CoreWeave is The Essential Cloud for AI. Built for pioneers by pioneers, CoreWeave delivers a platform... 
    Senior
    Permanent employment
    Contract work
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    San Francisco, CA
    4 days ago
  • $143k - $191k

     ...Senior Data Center Security Initiatives Project Manager Livingston, NJ / New York, NY / Sunnyvale, CA / San Francisco, CA / Bellevue, WA/ Dallas, TX / Richmond, VA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform... 
    Senior
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    San Francisco, CA
    1 day ago
  • $146.4k - $235.38k

     ...business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped...  ...(CLM). What you'll do Docusign is looking for a Senior Security Risk Manager to join our Security Governance, Risk & Compliance... 
    Senior
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    San Francisco, CA
    5 days ago
  • $160k - $230k

     ...solar system. Today, Astranis satellites provide dedicated, secure networks to highly-sophisticated customers across the globe—...  ...153,000 sq. ft. headquarters in Northern California, USA. SENIOR OFFENSIVE SECURITY ENGINEER As a Senior Offensive Security Engineer,... 
    Senior
    Permanent employment
    Flexible hours

    Astranis

    San Francisco, CA
    3 days ago
  • $180k - $250k

     ...the future of work. Join us as we reinvent work, so people everywhere can do their best work. About The Role As an Offensive Security Engineer within HP IQ's Product Security team, you will partner closely with engineering teams to identify, validate, and mitigate... 
    Senior
    Full time
    Temporary work
    Local area
    Flexible hours

    HP

    San Francisco, CA
    2 days ago
  • $181k

     ...About the role We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime's services...  ...this role, you can expect to Independently manage complete red team exercises. Partner with Engineering... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Night shift

    Chime Financial, Inc

    San Francisco, CA
    4 days ago
  • $170.6k - $390k

     ...place in the world to grow your career in information security! The opportunity The Senior Network Security Architect is a strategic and hands‑on...  ...operations teams. Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a... 
    Senior
    Summer holiday
    Remote work
    Flexible hours

    EY

    San Francisco, CA
    1 day ago
  • $264k - $300k

     ...At Asana, security is foundational to our mission of helping teams work together effortlessly. Our Security organization protects Asana...  ...and maintain trust at scale. We are seeking an Engineering Manager, Security to lead and grow our Security Engineering organization... 
    Senior
    Work at office
    Local area
    Work from home
    Worldwide

    Asana

    San Francisco, CA
    2 days ago
  • $143k - $210k

     ...Senior Product Manager, Security & Infra Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/San Francisco, CA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables... 
    Senior
    Temporary work
    Remote work
    Flexible hours

    CoreWeave

    San Francisco, CA
    11 hours ago
  • $260k - $346k

     ...Your Impact at LILA Cloud Security & Compliance Lead is responsible for the end-to-end security, governance, risk management, and regulatory compliance of Lila Sciences' cloud environments and research workflows. You'll own cloud security architecture, policy frameworks... 
    Senior
    Full time
    Contract work
    Work at office
    Local area
    Flexible hours

    Lila Sciences

    San Francisco, CA
    12 hours ago
  • $280k - $385k

    A leading data and AI company seeks senior leaders to define the strategy for its security platform, focusing on Authentication. Candidates should have extensive...  ...for fostering a secure user experience while managing a talented team in a high-impact environment. #J-18... 
    Senior
    Remote work

    Databricks

    San Francisco, CA
    4 days ago
  • An innovative tech platform is seeking a Senior Principal Software Engineer to lead the development of its next-gen API Platform. The...  ...backend software development experience and extensive knowledge in API design, cloud platforms, and security protocols. #J-18808-Ljbffr
    Senior
    Remote work

    jobright.com

    San Francisco, CA
    5 days ago
  • $157k - $281.93k

    A leading design software company seeks a Senior Principal Content Strategist. This role involves defining content strategy for AI-driven experiences, partnering with cross-functional teams, and establishing content governance standards. Candidates should have over 12... 
    Senior

    Autodesk

    San Francisco, CA
    1 day ago
  • $110k - $130k

     ...Senior Operations Manager San Francisco, California, United States About the Job Senior Operations Manager We're seeking a Senior Operations Manager with in-depth knowledge and expertise in cold chain delivery, particularly with cryogenics at temperatures as low... 
    Senior

    Global Selecta

    San Francisco, CA
    2 days ago
  • $248k - $270.75k

     ...Position We are seeking a dynamic and experienced Senior Director, Information Security to lead our cybersecurity and compliance efforts. Reporting...  ...with a strong track record in information security management. They possess extensive knowledge of cybersecurity technologies... 
    Senior
    Summer holiday

    Eikon Therapeutics

    Millbrae, CA
    6 hours ago
  •  ...Senior / Staff / Principal Machine Learning Engineer Location: Onsite San Francisco (5 days onsite AND hybrid options) We have multiple startups interested in talent. Here is a generic summary. Instead of a perfect job description, we present talented individuals... 
    Senior

    Lead Allies Inc.

    San Francisco, CA
    1 day ago
  •  ...Senior / Staff / Principal Backend Engineer Location: Onsite San Francisco We have...  ...responsible for ensuring the efficient and secure functioning of web applications and...  ...handling user requests, processing data, and managing application logic. Database Management... 
    Senior
    Remote work

    Lead Allies Inc.

    San Francisco, CA
    11 days ago
  •  ...Senior / Staff / Principal Frontend Engineer Location: Onsite San Francisco We have multiple startups interested in talent. Here is a generic summary. Instead of a perfect job description, we present talented individuals to companies and allow them to share how... 
    Senior

    Lead Allies Inc.

    San Francisco, CA
    1 day ago
  • $200k - $280k

     ...Senior Manager - Network and Information Security Emeryville or Santa Clara, California Atomic Machines is ushering in a new era of micromanufacturing with its Matter Compiler™ technology platform. This platform enables new classes of micromachines to be designed and... 
    Senior
    Contract work

    Atomic Machines

    Emeryville, CA
    1 day ago
  • A leading global workforce solutions company is seeking a Senior Security Operations & DevSecOps Lead. This remote role includes leading security operations, implementing security monitoring tools, and conducting vulnerability assessments. The ideal candidate will have... 
    Senior
    Remote work

    ManpowerGroup Global, Inc.

    San Francisco, CA
    4 days ago
  • $142.31k - $177.88k

     ...Salary Range: $142,307 to $177,884 YOUR ROLE The Ground Product Sr. Manager provides senior operational leadership and strategic direction for CEVA’s ground transportation operations. This position is accountable for end-to-end oversight of service delivery, financial... 
    Senior
    Work at office

    CEVA Logistics

    San Francisco, CA
    4 days ago
  •  ...About the Role The Senior Director - Reliability Operations, is a strategic leader...  ...This role oversees all ITIL-based service management functions, Site Reliability Engineering...  ...'s capabilities including IT, HR, Security, and Enterprise Operations. Lead a platform... 
    Senior

    Gap Inc.

    San Francisco, CA
    4 days ago
  • $120k - $150k

     ...Contract Lifecycle Management (CLM) Data Management & Governance Digital Realty is seeking a driven and detail-oriented CLM Data Management & Governance professional to join its Contract Management team within the global Legal function. This role plays a critical part... 
    Senior
    Contract work
    Work at office

    Digital Realty

    San Francisco, CA
    1 day ago
  •  ...Senior Director Of Workplace Operations Our search team has been engaged by Earthjustice...  ...space planning, including sourcing and managing the performance of third-party brokers,...  ...and CapEx planning, and safety and security. Act as the organization-wide point of... 
    Senior
    Work at office
    Relocation
    Shift work

    Keller Executive Search

    San Francisco, CA
    1 day ago
  •  ...Senior Marketing Operations Manager | SaaS / AI / Developer Tools | Remote (Preferred: San Francisco)Intalex is partnered with a fast-growing SaaS Developer-tool startup that's revolutionizing the way developers integrate AI into real-world applications. They're well-funded... 
    Senior
    Work at office
    Remote work

    Intalex

    San Francisco, CA
    4 days ago
  •  ...experienced, strategic, and execution-oriented Senior Event Center & Operations Lead to oversee day-to-day management, operational excellence, and event execution standards...  ...complex venue logistics including catering, security, facilities coordination, vendors, run-of-show... 
    Senior
    Work at office
    Work from home

    Marvel Marketers

    San Francisco, CA
    4 days ago
  •  ...Job Description Senior Data Engineer Principal, Lead on site Client is building a global consumer neobank, merging banking, payments, and crypto into a single product. Our initial focus is emerging markets, where traditional banking and local currencies fail... 
    Senior
    Local area
    Flexible hours

    Simple Solutions

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Offensive Security Manager. Be the first to apply!