SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Postman is the world's leading API platform used by 45+ million developers and 500,000 organizations, including 98% of the Fortune 500. The Information Security organization operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. The company maintains active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance, and is pursuing FedRAMP High and CMMC Level 2 authorization.
The Offensive Security team serves as the "red" pulse of the organization, simulating adversaries to validate defenses under real-world pressure. This Principal role owns the strategic direction of Postman's offensive security program and will build out a dedicated Offensive AI Security capability from the ground up, operating as a key partner to CISO leadership on threat-informed defense strategy.
Key responsibilities include: defining and executing a multi-year offensive security roadmap aligned to evolving threat landscape and business priorities; standing up and scaling a dedicated offensive capability targeting AI/ML systems, including adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure; tracking and operationalizing the rapidly evolving AI threat landscape (OWASP LLM Top 10, MITRE ATLAS, emerging attack research) into red team playbooks and detection hypotheses; leading structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines targeting prompt injection, tool-use abuse, data exfiltration, training data poisoning, and trust boundary violations; designing and deploying AI-based penetration testing platforms and autonomous agents for continuous security validation across the API ecosystem; integrating automated breach and attack simulation (BAS) into CI/CD pipelines including AI model deployment pipelines; and building, managing, and scaling a high-performing team of offensive security engineers with specialized AI red team operators, providing mentorship, career development, and succession planning.
This is a hands-on technical leadership role where you will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make the company an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations. You will lead a team that demonstrates vulnerabilities using live exploits to build a deep security culture across the entire engineering organization.