Jobs and Careers
PO

Senior Security Compliance Analyst

Postman
San Francisco, United Statesfull_timeVerifiedPosted 15 Apr 2024
💰 $215,000/yr($190,000/yr$215,000/yr)

About the role

Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

About The Role

The Senior Security Compliance Engineer at Postman will play a crucial role within the Security Assurance team, focusing on bolstering the company's security framework by implementing, managing, and enhancing compliance programs across a broad spectrum of standards, including ISO 27k, HIPAA, NIST, FedRAMP, GDPR, CCPA, and SOC 2. This position is pivotal in ensuring Postman's adherence to regulatory and contractual mandates and instrumental in driving security and compliance initiatives that contribute to the company's growth. The ideal candidate will bring a blend of technical acumen and strategic insight, capable of effectively communicating with stakeholders and guiding team members in alignment with senior management's vision. With a strong emphasis on process and results and robust problem-solving and communication skills, the Senior Security Compliance Engineer will play a crucial role within the organization, offering expertise and leadership to ensure Postman's continued success and security resilience.

What You’ll Do

  • Lead and orchestrate significant compliance projects to integrate and uphold standards such as ISO 27001/27701, HIPAA, NIST, FedRAMP, GDPR, CCPA, and SOC 2, ensuring Postman's alignment with regulatory and contractual obligations.

  • Actively contribute to the creation, administration, and continual enhancement of Postman's Information Security program, compliance frameworks, risk management practices, privacy protocols, and overall security stance, in line with the strategic direction set by senior management.

  • Foster collaboration with business leaders and technical teams to identify, evaluate, and manage security risks and controls, recommending strategies for mitigation and improvement to support Postman's growth and sales enablement.

  • Lead the coordination and execution of compliance audit processes, collaborating with external auditors and internal stakeholders to ensure comprehensive and timely adherence to audit requirements.

  • Regularly review and update Postman's policy and procedural documentation to reflect current industry best practices and compliance standards, ensuring the Security Assurance team's activities are aligned with organizational goals.

  • Produce detailed and accurate reports on compliance initiatives and activities, offering insights and updates to stakeholders and contributing to the transparency and effectiveness of the Security Assurance team's efforts.

  • Serve as a mentor and key point of escalation within the team, providing expert guidance, resolving complex issues, and promoting a culture of security awareness and compliance across the organization.

  • Leverage extensive technical knowledge and communication skills to effectively interact with engineers and technologists, providing clear guidance and recommendations on security and compliance best practices.

  • Demonstrate a process-oriented, results-driven approach to compliance engineering, employing effective problem-solving and communication skills to serve as a subject matter expert and trusted advisor within Postman.

About You

  • Minimum of ten years of experience in cybersecurity governance, risk management, and compliance.

  • Relevant certifications such as CISSP, CRISC, CISA, or CISM is a plus

  • Experience with GRC programs, including ISO 27001, HIPAA, and FedRAMP, preferably in a Cloud/SaaS environment.

  • Proficient in technical knowledge related to management information systems, audits, and internal controls.

  • Capable of identifying compliance and security gaps and formulating and implementing mitigation plans.

  • Self-motivated and organized, with a proven ability to meet deadlines.

  • Excellent interpersonal skills and the ability to build relationships across departments and cultures.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Postman

View company profile →