Principal Offensive Security Engineer
Job description
About the role
Postman is on the lookout for a visionary leader to shape and implement our offensive security initiatives, particularly focusing on the development of a new Offensive AI Security practice. In this role, you will oversee a team of engineers dedicated to conducting adversarial assessments on AI systems, large language model (LLM) integrations, and agentic workflows. Your primary responsibility will be to convert complex vulnerabilities into practical insights that can enhance our engineering processes and fortify our defenses against evolving threats.
Key facts
What you'll do
- Lead the development of a comprehensive offensive security strategy that encompasses Red Team, Purple Team, and ongoing validation efforts over multiple years.
- Create and expand offensive capabilities tailored for AI and machine learning systems, including the establishment of retrieval-augmented generation (RAG) pipelines and model-serving infrastructure.
- Spearhead adversarial testing campaigns targeting AI agents and LLM implementations to uncover vulnerabilities such as prompt injection, training data manipulation, and misuse of tools.
- Design and implement automated penetration testing frameworks, integrating breach and attack simulation into continuous integration and continuous deployment (CI/CD) pipelines.
- Oversee and mentor a team of offensive security engineers, emphasizing recruitment and professional growth in AI red teaming methodologies.
- Conduct live demonstrations of exploits to raise awareness and educate engineering teams about potential security threats.
- Collaborate with executive leadership and governance, risk, and compliance (GRC) teams to translate technical findings into narratives that convey business risks and compliance requirements.
- Engage with cross-functional teams to ensure security best practices are integrated into the development lifecycle.
- Stay current with the latest trends in offensive security, particularly in AI and machine learning, to continuously refine and adapt security strategies.
- Foster a culture of security awareness within the organization, promoting proactive security measures among all employees.
Requirements
- A minimum of 8 years of experience in offensive security roles, including red teaming, penetration testing, or vulnerability research.
- At least 4 years of experience in a leadership capacity, with a track record of managing teams or technical leads.
- Demonstrated success in building or significantly enhancing an offensive security program.
- In-depth technical knowledge of attacking AI and machine learning systems, particularly in LLM red teaming and exploitation of agentic systems.
- Familiarity with AI-enhanced penetration testing tools and frameworks, such as Microsoft PyRIT, Garak, or custom fuzzing tools.
- Excellent communication skills, with the ability to articulate complex exploit scenarios to non-technical stakeholders and executive leadership.
Nice to have
- A recognized presence in the industry, including speaking engagements at conferences, published research, or contributions to organizations like OWASP and MITRE.
- Relevant certifications such as OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or GIAC GMAI.
- Extensive knowledge of cloud security, particularly in relation to AWS, container security, and Kubernetes exploitation.
- Experience with API-specific attack techniques, including broken object-level authorization (BOLA), broken function-level authorization (BFLA), mass assignment vulnerabilities, and GraphQL abuse.
- Understanding of how to align offensive security findings with compliance frameworks such as SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC.
Skills & tools
- AI/ML Red Teaming: Expertise in prompt injection, RAG poisoning, and confusion of tool usage.
- Security Stack: Proficient in tools such as Wiz, SentinelOne, Okta, Jamf, and 1Password.
- Frameworks: Familiar with OWASP LLM Top 10, MITRE ATLAS, and ISO 42001.
- Tools: Experience with PentestGPT, Horizon3, Microsoft PyRIT, and Garak.
Practical notes
At Postman, we operate under a performance-based pay structure and require employees to work in the office five days a week at our locations. Our benefits package includes comprehensive medical coverage, flexible paid time off, wellness reimbursement, a monthly lunch stipend, and a donation-matching program. As a privately held company, we are supported by notable investors such as Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners.