Manager, Security Assurance

3 Months ago • 5-7 Years • Cyber Security • $208,000 PA - $244,000 PA

Job Summary

Job Description

Postman is looking for an experienced GRC leader to build out and scale our governance, risk, compliance, and privacy functions, as well as design and develop the appropriate programs and frameworks to cover Postman’s cyber risk and security assurance obligations. You will lead the operationalization of Postman’s automated governance, risk, and compliance (GRC) programs while also driving efforts to mature and optimize Postman’s security policies, risk management processes, and compliance with standards and regulations such as SOC2, ISO, NIST, GDPR, CCPA, HIPAA, FedRamp and PCI.
Must have:
  • 5-7 years of hands-on cyber risk, governance, and compliance leadership
  • Proven experience developing or maturing GRC programs
  • Experience with—and enthusiasm for—working with global, distributed teams
Good to have:
  • Passionate and creative in the use of technology to streamline and automate manual processes
  • Alignment with Postman’s values
Perks:
  • full medical coverage
  • flexible PTO
  • wellness reimbursement
  • monthly lunch stipend

Job Details

Who Are We?

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

The Opportunity

We’re looking for an experienced GRC leader to build out and scale our governance, risk, compliance, and privacy functions, as well as design and develop the appropriate programs and frameworks to cover Postman’s cyber risk and security assurance obligations. Your mission, should you choose to accept it, will be to lead the operationalization of Postman’s automated governance, risk, and compliance (GRC) programs while also driving efforts to mature and optimize Postman’s security policies, risk management processes, and compliance with standards and regulations such as SOC2, ISO, NIST, GDPR, CCPA, HIPAA, FedRamp and PCI.

Cybersecurity is essential to what we do at Postman. Postman’s security team is responsible for cybersecurity across the entire organization, from employees to partners to customers. We help Postman design, build, deploy, and maintain secure software to ensure we're protecting every customer’s data and their investment in our products. We also focus on providing security intelligence and building tools to enable all “Postmanauts” (i.e., everyone who works at Postman) to feel a shared sense of responsibility for security and privacy concerns. Finally, we aim to constantly improve the security posture of our organization by iterating on our tooling and process.

What You’ll Do:

  • Develop and manage Postman’s security governance framework and cyber risk program to maintain the company’s compliance obligations 

  • Manage and mature Postman’s security policy framework, vendor risk management, and security assurance programs.

  • Recruit and manage a lean team of remote cyber risk professionals to simplify processes and relieve operational burdens

  • Partner with business and engineering leaders to identify and evaluate risks/controls and make suggestions on mitigation strategies

  • Work with key stakeholders to help guide the program and drive prioritization of risks for the company

  • Work with cross-functional teams and leadership to drive organizational adoption efforts

  • Implement the use of technology to streamline and automate manual controls 

  • Manage legal, regulatory, and contractual compliance obligations

  • Create and manage the company’s vendor risk management program

About You:

  • 5-7 years of hands-on cyber risk, governance, and compliance leadership

  • Proven experience developing or maturing GRC programs, preferably within a high-growth Cloud/SaaS environment

  • Passionate and creative in the use of technology to streamline and automate manual processes 

  • Experience with—and enthusiasm for—working with global, distributed teams

  • Alignment with Postman’s values (you can find them listed on our careers page)

  • An innate curiosity about how things work

  • Lots of smiles

Our Values

At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

What Else?

If the role is based in the greater San Francisco area, and the we are offering a base range of $208,000 to 244,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.

Equal Opportunity

Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

 

Similar Jobs

Every matrix - Middle Manual QA Engineer

Every matrix

Lviv, Lviv Oblast, Ukraine (Hybrid)
2 Months ago
Zeta - Software Development Engineer in Test I / II

Zeta

Hyderabad, Telangana, India (On-Site)
4 Months ago
Postman - Technical Support Engineer (East Coast)

Postman

United States (Hybrid)
3 Months ago
Postman - Enterprise Account Executive

Postman

Toronto, Ontario, Canada (On-Site)
4 Months ago
Fluence - Cybersecurity Engineer (m/f/d)

Fluence

Erlangen, Bavaria, Germany (Hybrid)
4 Months ago
Zoom - Security Remediation Engineer

Zoom

(Remote)
4 Months ago
ByteDance - Cloud Security Architect, BytePlus

ByteDance

Singapore (On-Site)
3 Months ago
Netflix - Manager, Content Security Vendor Program

Netflix

Los Angeles, California, United States (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

UST - Security Testing--Tester II - Software Testing

UST

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Postman - Account Development Representative (Dutch Speaking)

Postman

Central Sulawesi, Indonesia (Remote)
3 Months ago
Experian - Senior Software Engineer- Test

Experian

Hyderabad, Telangana, India (Hybrid)
5 Months ago
PhonePe - System Integrator

PhonePe

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Meetelise - Associate Solutions Engineer

Meetelise

New York, New York, United States (On-Site)
3 Months ago
PENN Interactive - Senior QA Automation Engineer

PENN Interactive

Philadelphia, Pennsylvania, United States (Hybrid)
4 Months ago
Groww - SDET Manager

Groww

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Social Discovery Group - Senior Automation QA Engineer

Social Discovery Group

Serbia (Remote)
4 Months ago
Beckman Coulter Life Sciences - Test & Metrology Engineer

Beckman Coulter Life Sciences

Bengaluru, Karnataka, India (Remote)
5 Months ago
Postman - Senior Platform Engineer, Observability Agent

Postman

San Francisco, California, United States (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in San Francisco, California, United States

Barbaricum - Senior Systems Engineer

Barbaricum

Alexandria, Virginia, United States (On-Site)
4 Months ago
Infoblox - Staff Software Engineer

Infoblox

Washington, United States (Hybrid)
2 Months ago
Next Level Business Services - Solution Architect

Next Level Business Services

Philadelphia, Pennsylvania, United States (On-Site)
4 Months ago
The Walt Disney Company - Sr Solutions Engineer (Project Hire)

The Walt Disney Company

Seattle, Washington, United States (On-Site)
3 Months ago
Smarsh - Account Executive, SLED

Smarsh

United States (Remote)
4 Months ago
Microsoft - Data Science: Internship Opportunities - Redmond

Microsoft

Redmond, Washington, United States (On-Site)
1 Month ago
Electronic Arts - Executive Assistant

Electronic Arts

Orlando, Florida, United States (On-Site)
2 Months ago
HHA Exchange - Director of Growth Marketing

HHA Exchange

New York, New York, United States (Remote)
4 Months ago
INSPYR Solutions - Game Designer 2

INSPYR Solutions

Santa Monica, California, United States (On-Site)
5 Months ago
Zoox - Equipment Engineering Internship/Co-Op

Zoox

Fremont, California, United States (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

CAE - Software Engineer, Datalink

CAE

Tampa, Florida, United States (On-Site)
5 Months ago
Warner Bros Discovery - Sr. Security Engineer, Penetration Testing

Warner Bros Discovery

Atlanta, Georgia, United States (Hybrid)
2 Months ago
PwC - Consultoría | Manager Ciberseguridad

PwC

Madrid, Community Of Madrid, Spain (On-Site)
4 Months ago
Anthology  Inc  - Security Risk Analyst

Anthology Inc

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Arrow Electronics - Analyst - SecOps

Arrow Electronics

Karnataka, India (On-Site)
3 Months ago
Google - Cloud Technical Solutions Engineer, Security

Google

Pune, Maharashtra, India (On-Site)
3 Months ago
Saviynt - Sr. Engineer, Solutions Engineering

Saviynt

United States (Remote)
4 Months ago
Meta - Security Engineer Intern, Product

Meta

Bellevue, Washington, United States (On-Site)
3 Months ago
Luxoft - Information Security Compliance Specialist

Luxoft

Ukrainka, Kyiv Oblast, Ukraine (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Central Sulawesi, Indonesia (Remote)

Toronto, Ontario, Canada (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

New York, New York, United States (On-Site)

Bengaluru, Karnataka, India (On-Site)

San Francisco, California, United States (Hybrid)

Bengaluru, Karnataka, India (On-Site)

View All Jobs

Get notified when new jobs are added by Postman

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug