Postman
Manager, Security Assurance
Postman, San Francisco, California, United States, 94199
Postman
Accelerate API development with Postman's all-in-one platform. Streamline collaboration and simplify the API lifecycle for faster, better results.Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world.We’re looking for an experienced GRC leader to build out and scale our governance, risk, compliance, and privacy functions, as well as design and develop the appropriate programs and frameworks to cover Postman’s cyber risk and security assurance obligations. Your mission will be to lead the operationalization of Postman’s automated governance, risk, and compliance (GRC) programs while also driving efforts to mature and optimize Postman’s security policies, risk management processes, and compliance with standards and regulations such as SOC2, ISO, NIST, GDPR, CCPA, HIPAA, FedRamp, and PCI.Cybersecurity is essential to what we do at Postman. Postman’s security team is responsible for cybersecurity across the entire organization, from employees to partners to customers. We help Postman design, build, deploy, and maintain secure software to ensure we're protecting every customer’s data and their investment in our products. We also focus on providing security intelligence and building tools to enable all “Postmanauts” to feel a shared sense of responsibility for security and privacy concerns. Finally, we aim to constantly improve the security posture of our organization by iterating on our tooling and process.What You’ll Do:
Develop and manage Postman’s security governance framework and cyber risk program to maintain the company’s compliance obligations.Manage and mature Postman’s security policy framework, vendor risk management, and security assurance programs.Recruit and manage a lean team of remote cyber risk professionals to simplify processes and relieve operational burdens.Partner with business and engineering leaders to identify and evaluate risks/controls and make suggestions on mitigation strategies.Work with key stakeholders to help guide the program and drive prioritization of risks for the company.Work with cross-functional teams and leadership to drive organizational adoption efforts.Implement the use of technology to streamline and automate manual controls.Manage legal, regulatory, and contractual compliance obligations.Create and manage the company’s vendor risk management program.About You:
5-7 years of hands-on cyber risk, governance, and compliance leadership.Proven experience developing or maturing GRC programs, preferably within a high-growth Cloud/SaaS environment.Passionate and creative in the use of technology to streamline and automate manual processes.Experience with—and enthusiasm for—working with global, distributed teams.Alignment with Postman’s values.An innate curiosity about how things work.Lots of smiles.Our Values
At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.What Else?
If the role is based in the greater San Francisco area, we are offering a base range of $208,000 to $244,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
#J-18808-Ljbffr
Accelerate API development with Postman's all-in-one platform. Streamline collaboration and simplify the API lifecycle for faster, better results.Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world.We’re looking for an experienced GRC leader to build out and scale our governance, risk, compliance, and privacy functions, as well as design and develop the appropriate programs and frameworks to cover Postman’s cyber risk and security assurance obligations. Your mission will be to lead the operationalization of Postman’s automated governance, risk, and compliance (GRC) programs while also driving efforts to mature and optimize Postman’s security policies, risk management processes, and compliance with standards and regulations such as SOC2, ISO, NIST, GDPR, CCPA, HIPAA, FedRamp, and PCI.Cybersecurity is essential to what we do at Postman. Postman’s security team is responsible for cybersecurity across the entire organization, from employees to partners to customers. We help Postman design, build, deploy, and maintain secure software to ensure we're protecting every customer’s data and their investment in our products. We also focus on providing security intelligence and building tools to enable all “Postmanauts” to feel a shared sense of responsibility for security and privacy concerns. Finally, we aim to constantly improve the security posture of our organization by iterating on our tooling and process.What You’ll Do:
Develop and manage Postman’s security governance framework and cyber risk program to maintain the company’s compliance obligations.Manage and mature Postman’s security policy framework, vendor risk management, and security assurance programs.Recruit and manage a lean team of remote cyber risk professionals to simplify processes and relieve operational burdens.Partner with business and engineering leaders to identify and evaluate risks/controls and make suggestions on mitigation strategies.Work with key stakeholders to help guide the program and drive prioritization of risks for the company.Work with cross-functional teams and leadership to drive organizational adoption efforts.Implement the use of technology to streamline and automate manual controls.Manage legal, regulatory, and contractual compliance obligations.Create and manage the company’s vendor risk management program.About You:
5-7 years of hands-on cyber risk, governance, and compliance leadership.Proven experience developing or maturing GRC programs, preferably within a high-growth Cloud/SaaS environment.Passionate and creative in the use of technology to streamline and automate manual processes.Experience with—and enthusiasm for—working with global, distributed teams.Alignment with Postman’s values.An innate curiosity about how things work.Lots of smiles.Our Values
At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.What Else?
If the role is based in the greater San Francisco area, we are offering a base range of $208,000 to $244,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
#J-18808-Ljbffr