Senior Offensive Security Manager

Postman Postman · Enterprise · Cupertino, CA +1 · Platform Engineering

Senior Manager, Offensive Security to build and lead Postman's offensive AI security program, focusing on adversarial testing of LLM integrations, agentic workflows, RAG pipelines, and model-serving infrastructure. The role involves setting strategic direction, hands-on technical leadership in AI systems red teaming, architecting autonomous testing, and people leadership.

What you'd actually do

  1. Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
  2. Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.
  3. Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations.
  4. Red Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.
  5. Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning.

Skills

Required

  • Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development)
  • Experience building and leading offensive security programs
  • Deep understanding of AI/ML systems security
  • Experience with adversarial testing of LLM integrations, agentic workflows, RAG pipelines, and model-serving infrastructure
  • Experience developing AI threat intelligence and translating research into playbooks
  • Hands-on experience leading red team engagements against AI systems
  • Experience architecting AI-based penetration testing platforms and autonomous agents
  • Experience with continuous validation and integrating automated breach and attack simulation into CI/CD pipelines
  • Proven ability to build, manage, and scale high-performing teams
  • Experience recruiting talent at the intersection of offensive security and AI/ML
  • Strong communication and influence skills
  • Experience driving security culture through demonstrations
  • Experience translating offensive findings into business-level risk narratives for executive leadership
  • Partnership with GRC on audit evidence and compliance posture

Nice to have

  • Experience with API security
  • Familiarity with Postman's security stack (Wiz, SentinelOne, Okta, Jamf, 1Password)
  • Experience in a multi-cloud environment
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, ISO 42001, HIPAA, FedRAMP, CMMC)

What the JD emphasized

  • building out a dedicated Offensive AI Security capability from the ground up
  • make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations
  • AI/ML systems
  • adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure
  • AI threat intelligence
  • emerging attack research on agentic systems
  • Red Team AI Systems at Depth
  • LLM deployments, AI agents, and model pipelines
  • prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures
  • AI-based penetration testing platforms and autonomous agents
  • AI model deployment pipelines
  • specialized AI red team operators
  • offensive security and AI/ML
  • AI red teaming
  • AI-specific attack vectors
  • AI-specific risk frameworks

Other signals

  • building offensive AI security capability
  • adversarial testing of AI systems
  • agentic workflows
  • LLM integrations