Senior GRC Engineer
Job description
About the role
This role owns and scales Postman's security and compliance posture through automation. The position emphasizes hands-on design and operation of tools that reduce manual effort while strengthening security assurance.
Software engineers turn product ideas into working code. Engineers work in small teams, review each other's work, and ship in small batches. Most teams follow agile practices such as sprints and daily standups. Engineers also write tests, fix bugs, and improve performance. The field values clear communication as much as technical skill. Engineers spend part of every week on planning, code review, and debugging, not just writing new code. The ability to explain a technical decision in plain words separates strong engineers from the rest.
Key facts
-
Location: USA
-
Engagement: Full-time in-office role, five days a week in hubs including San Francisco, with specific schedules for Bangalore.
-
Compensation: Base salary range of $180,000 to $200,000, plus equity.
-
Team: Member of the Security GRC team.
- Years: Requires 6+ years of cybersecurity GRC experience.
- Visa: Roles are contingent on eligibility to work in the United States.
- Degree: Bachelor's degree or equivalent experience is required.
What you'll do
This work lowers manual effort and gives security assurance to internal stakeholders.
This enables reliable data flow across risk, security, and IT operations.
Specific compliance programs are driven from design through audit completion.
Continuous controls monitoring and automated evidence collection are driven to maintain real-time visibility into security and compliance status. These processes support timely responses for auditors and internal teams.
Risk and security requirements are translated into practical engineering solutions for technology and business teams.
Audit readiness is improved through automation and process optimization, ensuring documentation and evidence remain current and accessible. This supports efficient and predictable audit cycles.
Teammates are mentored, and GRC strategy is influenced by sharing expertise and proposing scalable approaches. Guidance shapes how the Security GRC team manages risk and compliance over time.
Requirements
Bring 6+ years of cybersecurity GRC experience from high-growth technology environments. This background ensures familiarity with fast-paced product development and evolving compliance needs.
Demonstrate experience implementing and maturing GRC programs using pragmatic, engineered solutions. A track record of turning frameworks into operational controls is expected.
Show knowledge of SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and/or FedRAMP standards and their application in cloud environments. This knowledge helps align Postman's platforms with recognized frameworks.
Write production-grade automation using Python, JavaScript, or similar languages. Code directly supports evidence collection, reporting, and monitoring workflows.
Experience integrating GRC tooling with ticketing, identity, asset management, and cloud platforms. This enables cohesive workflows across security, IT, and operations tools.
Familiarity with AI-assisted workflows or LLM-powered tooling that supports compliance tasks. Exploration of how emerging tools can improve efficiency and accuracy in GRC processes is part of the role.
Communicate risk clearly to technical and non-technical audiences, translating complex requirements into engineering tasks. This clarity ensures shared understanding across teams.
Hold a Bachelor's degree or demonstrate equivalent professional experience through a combination of learning and work history. This baseline supports the depth of responsibility in the role.
Practical notes
You will work in-office five days a week at designated hubs, with schedules aligned to team and regional needs.
Travel is not expected as part of this role, and remote work options follow the in-office model described above.
Good to know
The role works with modern GRC platforms, automation frameworks, and integrations used to manage security and compliance at scale.
Engineering and security collaboration is central, focusing on how controls and evidence are implemented and monitored.
Risk assessment methods and compliance frameworks guide decisions that affect product and operational workflows.
Automation reduces manual evidence gathering and supports continuous monitoring rather than point-in-time reporting.
Strong written and verbal communication is essential for aligning risk language with engineering priorities.