Principal Offensive Security Engineer (San Francisco)
$275k - $300kPostdot Technologies
Who Are We?Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.P.S: We highly recommend reading The API-First World graphic novel to understand the bigger picture and our vision at Postman.About the TeamThe Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.The Offensive Security team is the red pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.The OpportunityWe are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operate as a key partner to CISO leadership on threat-informed defense strategy.This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.You will lead a team that doesn't just report vulnerabilities but demonstrates them, using live exploits to build a deep, visceral security culture across the entire engineering organization.What You’ll DoStrategy & Program OwnershipSet Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations.Hands-On Technical LeadershipRed Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.People LeadershipLead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning.Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML — a rare and competitive talent market. Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.Communication & InfluenceDrive Security Culture through The Show: Lead live Exploitable Demonstrations — technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments. Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers.Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders. Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings — especially from AI red team engagements — drive measurable improvements in detection, response, and architecture.About YouExperience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems — whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments — extended to AI-native architectures.AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain — including an AI-specific attack path — to a room of developers in a way that is inspiring, not condescending.Engineering Fluency: You prefer building an automated exploit-as-code validator over performing the same manual test twice. You can architect evaluation harnesses and adversarial test suites for ML models.PreferredIndustry Presence: Track record of contributions to the offensive security or AI security community — conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.API Security Depth: Experience with API-specific attack methodologies — BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation — reflecting Postman's core product domain.Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence. You don't run GRC, but you know how to feed it.The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. What Else?In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We’re building a long-term company with an inclusive culture where everyone can be the best version of themselves. At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, New York City, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated vi
$181k
...About the roleWe are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime’s services... ...requirements of state and local laws, including the San Francisco Fair Chance Ordinance, Cook County Ordinance, NYC...SuggestedFull timePart timeWork at officeLocal areaRemote workNight shift$240k - $310k
...RoleYou will be the foundational technical pillar for security at Candid Health. As our first Principal Security Engineer, you won't just be managing a compliance... ...experience represented within roles.LocationSan Francisco (CA), Denver (CO), New York (NY)Employment TypeFull...PrincipalPart time$230k - $260k
...looking for a hands-on Detection Engineer to build and operate the... ...with Engineering, Corporate Security, and Infrastructure, with... ...-L, EQL, or Panther.Have an offensive security mindset and have led... ...provided below. For roles based in San Francisco or New York City, the...SuggestedPart timeLocal area$146.3k - $257.7k
...generative AI.Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and... ...of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building...SuggestedFull timePart timeWork at officeLocal area$189k - $303k
...more efficient and accessible for all. We’re searching for a Staff Security Engineer, Enterprise Security Architecture.This position is open to the following office locations: Mountain View, San Francisco, Seattle, Pittsburgh, Dallas, Detroit, and Phoenix.In this role,...SuggestedPart timeWork at officeLocal area3 days per week- Principal Cloud Security Operations Engineer (Scripting, AWS, DevOps, CISM, CCSA, CISSP, CCIE Security, CEH) in San Francisco, CA AWS, CEH, CISA, CISSP, DevOps, Python, scripting, Security Operations, SIEM Location: California Job Function: Information Security Date...PrincipalPermanent employmentFull timeWork experience placementRemote workRelocation
$148.5k - $260.1k
...of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain... ...benefits can be found at the following link: to the San Francisco Fair Chance Ordinance and the Los Angeles Fair...Full timePart time$200k - $225k
...our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time... ..., Chicago, IL, Houston, TX, Los Angeles, CA, New York, NY, San Francisco, CA, Seattle, WAIf this job description resonates with you,...Full timePart timeImmediate startRemote work$189k - $303k
...efficient and accessible for all.We're searching for a Staff Security Engineer to join our Enterprise Security Engineering team, reporting... ...is open to the following office locations: Mountain View, San Francisco, Seattle, Pittsburgh, Dallas, Detroit, and Phoenix.Aurora...Part timeWork at officeLocal area3 days per weekEarly shift$150k - $220k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...to identity providers.This role is based in San Francisco, or Sydney or MelbourneResponsibilities:Contribute to...Temporary workPart timeLocal areaWorldwide$180k - $247k
...Secure Every Identity, from AI to HumanIdentity is the key to... ....The Staff Product Security Engineer OpportunityThe Security team... ...This is a hybrid research, offensive and software engineering role... ...for candidates located in the San Francisco Bay area is between: $180,00...Part timeLocal areaWorldwideFlexible hours$130k
...About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security... ...the requirements of state and local laws, including the San Francisco Fair Chance Ordinance, Cook County Ordinance, NYC Fair...Full timePart timeWork at officeLocal areaRemote workNight shift$170k - $205k
...build with us at Crusoe.About the Role:Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver... ...Crusoe manages and secures endpoints. This role is onsite in San Francisco, CA, Sunnyvale, CA or Denver CO.What You'll Be Working On:...Temporary workPart time$188.75k - $242.68k
...across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Security Engineering is the engineering function inside the Plaid security org that focuses on developing...Part timeWork experience placementLocal area$208k - $312k
...move from idea to production with speed, security, and exceptional developer experience.... ...the Role:We are looking for a Security Engineer to join our Detection Response team. In... ...you to outfit your space as needed.The San Francisco, CA base pay range for this role is $20...Part timeWork at officeRemote workWork from homeWorldwideMonday to FridayFlexible hoursShift work$144.8k - $261.45k
...The next big idea could be yours.The Opportunity The Adobe Security Engineering Partnerships (SEP) team is seeking a Senior Product... ...to criminal penalties and civil liability.SummaryLocation: San Francisco; Denver; McLean; Austin; San Jose; New YorkType: Full time...Full timeTemporary workPart timeLocal areaWorldwide$160k - $250k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...know.Compensation Range: $160K - $250KLocationUS - San Francisco; AU - SydneyEmployment TypeFull timeLocation...Temporary workPart timeLocal areaWorldwide$227.2k - $304.7k
...Technology is a global organization of engineers, product developers, designers, technologists... ...and Star Wars. We are looking for a Sr Principal Product Manager, Sports Commerce to... ...hiring range for this position in San Francisco, CA and Glendale, CA is $227,200 to $30...PrincipalPart time$208k - $312k
...move from idea to production with speed, security, and exceptional developer experience.... ...re looking for a Senior (IC4) software engineer with a strong security background to... ...you to outfit your space as needed.The San Francisco, CA base pay range for this role is $20...Full timePart timeWork from homeWorldwideFlexible hours$204k - $280.5k
...join ours.About this roleThe Enterprise Security team at Faire owns the tools and... ...and AI governance. As our Staff Security Engineer focusing on Enterprise AI, you will own... ...of new tools or practices.Salary Range:San Francisco: the pay range for this role is $204,00...Part timeWork experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week- ..., or workflows you use today.ROLE OVERVIEWAs an Enterprise Security Engineer at Benchling you’ll be joining a team responsible for building... ..., state and local law, including but not limited to the San Francisco Fair Chance Ordinance.Compensation Range: $189K - $256KLocationSan...Part timeWork at officeLocal areaFlexible hours3 days per week
$168k - $240k
...more impactful work and the evolution of Slalom.The Role: M&A Principal/Senior PrincipalWhat You’ll Do:* Delivery areas include:*... ...targeted base salary pay range for Principal in Silicon Valley and San Francisco is $168,000 to $240,000. And for Boston, LA, White Plains,...PrincipalTemporary workPart timeWork at officeLocal areaImmediate start$172.5k - $260.1k
...committed to making people’s working lives more secure. We are serious about protecting our... ...you will be doingAs a Senior Software Engineer on the Vulnerability Management team,... ...be found at the following link: to the San Francisco Fair Chance Ordinance and the Los Angeles...Permanent employmentFull timePart time$192k - $240k
...and support you need to grow your career.Engineering at BrexEngineering at Brex is about... ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...’ll workThis role will be based in our San Francisco office. We are a hybrid environment...Part timeWork at officeRemote workWork from home$210k - $256.67k
...GA, Bridgewater, NJ, Chicago, IL, Dallas, TX, New York, NY, San Francisco, CA, Seaton, ILCountryUSAState / Region / ProvinceAnywhere in... ...UtilitiesSkillsetProcess|Consulting processes|Technology Consulting process Job RoleSenior Principal - Business ConsultingAuto req ID: 145272BR...PrincipalFull timeTemporary workPart timeRemote work$210k - $230k
...on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses... ...interview process.About the Role:We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning...Full timePart timeWork at officeLocal areaRemote work2 days per week3 days per week$227.2k - $304.7k
...Job Posting Title:Sr Principal, Executive Operations - Ads & Data PlatformsReq ID:10151... ...Technology is a global organization of engineers, product developers, designers, technologists... ...The hiring range for this position in San Francisco, CA is $227,200 - $304,700. The base...PrincipalFull timePart time- ...SingleStore engineers build the real-time data platform powering some of the world’s most... ...SummaryWe are seeking a Senior/Principal Software Engineer to join the Engineering... ...is venture-backed and headquartered in San Francisco with offices in Sunnyvale, Raleigh, Seattle...PrincipalPart time
$200k - $300k
...Job Title: Principal SoC Verification Engineer - SystemVerilog / UVM, AMBAJob Location: Los Altos, CA, or San Francisco, CA - hybridCompensation: $200K - $300K base DOE plus equityRequirements: SoC Verification (Full-Chip & Block-Level), SystemVerilog / UVM, AMBA Protocols...PrincipalPart time$178.88k - $320.65k
...lead our skilled team of software and ML engineers in the design, development, and... ...software development, code quality, and security standardsActively participate in coding... ...internally (not on this external site).SummaryLocation: San Francisco, CA, USAType: Full time...PrincipalFull timeTemporary workPart timeFor contractors
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Offensive Security Engineer (San Francisco). Be the first to apply!
- senior director engineering San Francisco, CA
- chief engineer San Francisco, CA
- senior principal engineer San Francisco, CA
- engineering director San Francisco, CA
- senior chief engineer San Francisco, CA
- director systems engineering San Francisco, CA
- principal infrastructure engineer San Francisco, CA
- data center chief engineer San Francisco, CA
- senior civil engineer project manager San Francisco, CA
- general engineer San Francisco, CA
























