Jobs and Careers
PO

Senior GRC Engineer

Postman
San Francisco, USAfull_timePosted 27 Jul 2026

About the role

<div class="content-intro"><h2><strong>Who Are We?</strong></h2> <p>Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.</p> <p>The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.</p> <p>P.S: We highly recommend reading <a href="https://api-first-world.com/">The "API-First World" graphic novel</a> to understand the bigger picture and our vision at Postman.</p></div><h2>The Opportunity&nbsp;</h2> <p>The Security GRC team is responsible for the overall security posture of Postman by ensuring compliance with applicable regulations and contractual obligations and maintaining effective and efficient governance, risk, and compliance programs. In addition, the Security GRC team is directly involved with supporting and enabling Sales and driving security and compliance initiatives to further the growth of Postman.</p> <p>We seek a Senior GRC Engineer who combines deep GRC expertise with strong engineering skills to build and scale automation across governance, risk, and compliance. This is a hands-on technical role focused on designing and operating GRC tooling, integrations, and AI-assisted workflows that reduce manual effort while improving security assurance. The ideal candidate has experience implementing and maturing compliance programs, including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and FedRAMP, and can translate security and risk requirements into practical engineering solutions.</p> <p>As a senior member of the Security GRC team, you will partner with Security, Engineering, IT, Legal, Sales, and other stakeholders to shape Postman's GRC strategy. You will own key compliance initiatives, drive continuous controls monitoring, build scalable automation, and serve as a trusted technical advisor on risk and compliance.</p> <h2><strong>What You'll Do</strong></h2> <ul> <li>Design, build, and operate GRC automation across evidence collection, control testing, risk tracking, and compliance reporting.</li> <li>Build integrations between GRC workflows and internal systems using code, workflow automation, low-code platforms, or AI-assisted tooling.</li> <li>Lead SOC 2, ISO 27001, HIPAA, and FedRAMP initiatives, owning at least one cer

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Postman

View company profile →