SlipstreamJobsFresh Startup & VC-Backed Jobs

Principal Offensive Security Engineer

Postman - San Francisco, CA, United States - In-office - posted 2026-04-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Postman is the world's leading API platform used by 45+ million developers and 500,000 organizations, including 98% of the Fortune 500. The Information Security organization operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. The company maintains active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance, and is pursuing FedRAMP High and CMMC Level 2 authorization. The Offensive Security team serves as the "red" pulse of the organization, simulating adversaries to validate defenses under real-world pressure. This Principal role owns the strategic direction of Postman's offensive security program and will build out a dedicated Offensive AI Security capability from the ground up, operating as a key partner to CISO leadership on threat-informed defense strategy. Key responsibilities include: defining and executing a multi-year offensive security roadmap aligned to evolving threat landscape and business priorities; standing up and scaling a dedicated offensive capability targeting AI/ML systems, including adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure; tracking and operationalizing the rapidly evolving AI threat landscape (OWASP LLM Top 10, MITRE ATLAS, emerging attack research) into red team playbooks and detection hypotheses; leading structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines targeting prompt injection, tool-use abuse, data exfiltration, training data poisoning, and trust boundary violations; designing and deploying AI-based penetration testing platforms and autonomous agents for continuous security validation across the API ecosystem; integrating automated breach and attack simulation (BAS) into CI/CD pipelines including AI model deployment pipelines; and building, managing, and scaling a high-performing team of offensive security engineers with specialized AI red team operators, providing mentorship, career development, and succession planning. This is a hands-on technical leadership role where you will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make the company an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations. You will lead a team that demonstrates vulnerabilities using live exploits to build a deep security culture across the entire engineering organization.

Similar roles