Postman
Senior Security Analyst
Postman, San Francisco, California, United States, 94199
Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.The Senior Security Analyst at Postman will play a crucial role within the Security Assurance team, focusing on bolstering the company's cybersecurity risk management program. The ideal candidate will possess a strong background in cybersecurity and field security management, with working knowledge and experience in risk management frameworks such as NIST RMF, FAIR, and ISO. This role will be pivotal in identifying, analyzing, and mitigating potential risks to our information systems and assets. The Senior Security Analyst will collaborate with various departments to ensure the security and integrity of our data and systems. The ideal candidate will bring a blend of technical acumen and strategic insight, capable of effectively communicating with stakeholders and guiding team members in alignment with senior management's vision.What You’ll Do:
Conduct comprehensive risk assessments to identify information security risks, potential threats, and vulnerabilities resulting from business operations.Conduct Field Security Analytics.Develop and implement risk management strategies and frameworks to mitigate identified risks.Continuously monitor and evaluate the effectiveness of risk mitigation measures.Collaborate with IT, legal, compliance, and other departments to ensure cohesive and comprehensive risk management practices.Communicate risk findings, mitigation strategies, and security requirements to stakeholders, including senior management.Develop and present detailed reports on risk assessments, including identified threats, vulnerabilities, and the effectiveness of implemented mitigation measures. Ensure these reports are understandable to technical and non-technical stakeholders, including senior management.Regularly review and update Postman's policy and procedural documentation to reflect current industry best practices and compliance standards, ensuring the Security Assurance team's activities are aligned with organizational goals.Take an active role and work in concert with IT Procurement and Legal in the design, management, and maturation of Third-Party Risk Management and vendor management.Contribute to significant compliance projects to integrate and uphold standards such as ISO 27001/27701, HIPAA, NIST, FedRAMP, GDPR, CCPA, and SOC 2, ensuring Postman's alignment with regulatory and contractual obligations.Foster collaboration with business leaders and technical teams to identify, evaluate, and manage security risks and controls, recommending strategies for mitigation and improvement to support Postman's growth and sales enablement.Serve as a mentor and key point of escalation within the team, providing expert guidance, resolving complex issues, and promoting a culture of security awareness and risk management across the organization.Leverage extensive technical knowledge and communication skills to effectively interact with engineers and technologists, providing clear guidance and recommendations on security and compliance best practices.Demonstrate a process-oriented, results-driven approach to compliance engineering, employing effective problem-solving and communication skills to serve as a subject matter expert and trusted advisor within Postman.About You:
Minimum of ten years of experience in cybersecurity governance, risk management, and compliance, with a focus on risk assessments/management.Relevant certifications such as CRISC, CISSP, CISM, or CISA is a plus.Knowledge and experience with risk management frameworks, including NIST RMF, FAIR, and ISO.Experience with GRC programs, including ISO 27001, HIPAA, and FedRAMP, preferably in a Cloud/SaaS environment.Proficient in technical knowledge related to management information systems, audits, and internal controls.Self-motivated and organized, with a proven ability to meet deadlines.Excellent interpersonal skills and the ability to build relationships across departments and cultures.Our Values
At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
#J-18808-Ljbffr
Conduct comprehensive risk assessments to identify information security risks, potential threats, and vulnerabilities resulting from business operations.Conduct Field Security Analytics.Develop and implement risk management strategies and frameworks to mitigate identified risks.Continuously monitor and evaluate the effectiveness of risk mitigation measures.Collaborate with IT, legal, compliance, and other departments to ensure cohesive and comprehensive risk management practices.Communicate risk findings, mitigation strategies, and security requirements to stakeholders, including senior management.Develop and present detailed reports on risk assessments, including identified threats, vulnerabilities, and the effectiveness of implemented mitigation measures. Ensure these reports are understandable to technical and non-technical stakeholders, including senior management.Regularly review and update Postman's policy and procedural documentation to reflect current industry best practices and compliance standards, ensuring the Security Assurance team's activities are aligned with organizational goals.Take an active role and work in concert with IT Procurement and Legal in the design, management, and maturation of Third-Party Risk Management and vendor management.Contribute to significant compliance projects to integrate and uphold standards such as ISO 27001/27701, HIPAA, NIST, FedRAMP, GDPR, CCPA, and SOC 2, ensuring Postman's alignment with regulatory and contractual obligations.Foster collaboration with business leaders and technical teams to identify, evaluate, and manage security risks and controls, recommending strategies for mitigation and improvement to support Postman's growth and sales enablement.Serve as a mentor and key point of escalation within the team, providing expert guidance, resolving complex issues, and promoting a culture of security awareness and risk management across the organization.Leverage extensive technical knowledge and communication skills to effectively interact with engineers and technologists, providing clear guidance and recommendations on security and compliance best practices.Demonstrate a process-oriented, results-driven approach to compliance engineering, employing effective problem-solving and communication skills to serve as a subject matter expert and trusted advisor within Postman.About You:
Minimum of ten years of experience in cybersecurity governance, risk management, and compliance, with a focus on risk assessments/management.Relevant certifications such as CRISC, CISSP, CISM, or CISA is a plus.Knowledge and experience with risk management frameworks, including NIST RMF, FAIR, and ISO.Experience with GRC programs, including ISO 27001, HIPAA, and FedRAMP, preferably in a Cloud/SaaS environment.Proficient in technical knowledge related to management information systems, audits, and internal controls.Self-motivated and organized, with a proven ability to meet deadlines.Excellent interpersonal skills and the ability to build relationships across departments and cultures.Our Values
At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
#J-18808-Ljbffr