What is a Security Engineer at Postman?
As a Security Engineer at Postman, you will play a critical role in securing the world's leading API collaboration platform. With millions of developers and organizations relying on Postman to build, test, and manage their APIs, the security of both the cloud infrastructure and the desktop client is paramount. This position is not about theoretical compliance; it is a highly technical, hands-on role dedicated to defending a massive ecosystem against sophisticated threats.
You will be tasked with identifying vulnerabilities, reverse engineering application builds, and designing robust defense mechanisms. Whether you are analyzing the desktop client's architecture or securing cloud-native services, your work directly protects sensitive API keys, environment variables, and proprietary schemas. The scale of Postman means that even minor security enhancements you implement will have a massive, compounding impact on the global developer community.
This role is ideal for engineers who possess an offensive security mindset and a deep curiosity about how systems fail. You will join a collaborative, fast-paced team that values proactive threat hunting and practical problem-solving. Expect to work closely with product and engineering teams to ensure that security is seamlessly integrated into every stage of the software development lifecycle.


