Jobs
>
San Francisco

    Senior Security Compliance Analyst - San Francisco, CA, United States - Postman

    Default job background
    Description

    Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million connected developers & serving companies as they seek to innovate in an API-first world. Our customers are doing more and more astounding things with the Postman product every day, and as a result, we are growing rapidly.

    We highly recommend reading The "API-First World" graphic novel to understand the bigger picture & our vision at Postman.

    About The Role

    The Senior Security Compliance Engineer at Postman will play a crucial role within the Security Assurance team, focusing on bolstering the company's security framework by implementing, managing, and enhancing compliance programs across a broad spectrum of standards, including ISO 27k, HIPAA , NIST , FedRAMP, GDPR , CCPA , and SOC 2. This position is pivotal in ensuring Postman's adherence to regulatory and contractual mandates and instrumental in driving security and compliance initiatives that contribute to the company's growth. The ideal candidate will bring a blend of technical acumen and strategic insight, capable of effectively communicating with stakeholders and guiding team members in alignment with senior management's vision. With a strong emphasis on process and results and robust problem-solving and communication skills, the Senior Security Compliance Engineer will play a crucial role within the organization, offering expertise and leadership to ensure Postman's continued success and security resilience.

    What You'll Do

    • Lead and orchestrate significant compliance projects to integrate and uphold standards such as ISO 27001/27701, HIPAA , NIST , FedRAMP, GDPR , CCPA , and SOC 2, ensuring Postman's alignment with regulatory and contractual obligations.
    • Actively contribute to the creation, administration, and continual enhancement of Postman's Information Security program, compliance frameworks, risk management practices, privacy protocols, and overall security stance, in line with the strategic direction set by senior management.
    • Foster collaboration with business leaders and technical teams to identify, evaluate, and manage security risks and controls, recommending strategies for mitigation and improvement to support Postman's growth and sales enablement.
    • Lead the coordination and execution of compliance audit processes, collaborating with external auditors and internal stakeholders to ensure comprehensive and timely adherence to audit requirements.
    • Regularly review and update Postman's policy and procedural documentation to reflect current industry best practices and compliance standards, ensuring the Security Assurance team's activities are aligned with organizational goals.
    • Produce detailed and accurate reports on compliance initiatives and activities, offering insights and updates to stakeholders and contributing to the transparency and effectiveness of the Security Assurance team's efforts.
    • Serve as a mentor and key point of escalation within the team, providing expert guidance, resolving complex issues, and promoting a culture of security awareness and compliance across the organization.
    • Leverage extensive technical knowledge and communication skills to effectively interact with engineers and technologists, providing clear guidance and recommendations on security and compliance best practices.
    • Demonstrate a process-oriented, results-driven approach to compliance engineering, employing effective problem-solving and communication skills to serve as a subject matter expert and trusted advisor within Postman.

    About You

    • Minimum of ten years of experience in cybersecurity governance, risk management, and compliance.
    • Relevant certifications such as CISSP , CRISC , CISA , or CISM is a plus
    • Experience with GRC programs, including ISO 27001, HIPAA , and FedRAMP, preferably in a Cloud/SaaS environment.
    • Proficient in technical knowledge related to management information systems, audits, and internal controls.
    • Capable of identifying compliance and security gaps and formulating and implementing mitigation plans.
    • Self-motivated and organized, with a proven ability to meet deadlines.
    • Excellent interpersonal skills and the ability to build relationships across departments and cultures.

    Our Values

    At Postman, we create with the same curiosity that we see in our users. We value transparency & honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.

    What Else?

    If the role is based in the greater San Francisco area, and the reasonably estimated salary for this role ranges from $190,000 - $215,000 plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience. In addition to our pay-on-performance philosophy, we offer a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Salaries will vary outside of the listed metropolitan areas & the U.S.

    Equal Opportunity

    Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.

    #J-18808-Ljbffr

  • Robert Walters

    Compliance Analyst

    1 day ago


    Robert Walters San Francisco, United States

    Compliance Analyst · Our client, an established and well-performing investment manager in San Francsico CA, is seeking a Compliance Analyst to join their team. · As a Compliance Analyst, you will play a crucial role in maintaining the integrity of our client's operations. Your re ...

  • Larson Maddox

    Compliance Analyst

    5 days ago


    Larson Maddox San Francisco, CA, United States

    A Menlo Park Based Hedge Fund is seeking a Compliance Analyst with experience working for a registered investment adviser to join our compliance team. · This role will report to the General Counsel / Chief Compliance Officer (GC/CCO). · The Analyst will be responsible for: · Deve ...

  • Paymentwall

    Compliance Analyst

    5 days ago


    Paymentwall San Francisco, United States

    We are looking for a Compliance Analyst to join our team in San Francisco. This role is a great opportunity for candidates looking to have hands-on experience working in a licensed fintech company. · As a Compliance Analyst, you'll be working with our global compliance team and p ...

  • Robert Walters

    Compliance Analyst

    5 days ago


    Robert Walters San Francisco, United States

    Compliance Analyst · Our client, an established and well-performing investment manager in San Francsico CA, is seeking a Compliance Analyst to join their team. · As a Compliance Analyst, you will play a crucial role in maintaining the integrity of our client's operations. Your ...

  • Larson Maddox

    Compliance Analyst

    1 week ago


    Larson Maddox San Francisco, United States

    3 days ago · Be among the first 25 applicants · A Hedge Fund is seeking a · Compliance Professional · with experience working for a registered investment adviser. · This role will report to the General Counsel / Chief Compliance Officer (GC/CCO). · Essential Duties And Respo ...

  • Weights and Biases

    Compliance Analyst

    1 day ago


    Weights and Biases San Francisco, United States

    At Weights & Biases, our mission is to build the best developer tools for AI developers. Weights & Biases is a series C company with $250 million in funding and a rapidly growing user base. Our platform is an essential piece of the daily work for machine learning engineers, from ...

  • Larson Maddox

    Compliance Analyst

    1 week ago


    Larson Maddox San Francisco, United States

    5 days ago Be among the first 25 applicants A Hedge Fund is seeking a Compliance Professional with experience working for a registered investment adviser.This role will report to the General Counsel / Chief Compliance Officer (GC/CCO).Essential Duties And ResponsibilitiesMaintain ...

  • Parafin Inc

    Compliance Analyst

    5 days ago


    Parafin Inc San Francisco, United States

    About Us: · At Parafin, our mission is to grow small businesses. · Small businesses are the backbone of our economy, yet banks do not have their back. Parafin is a technology company that builds infrastructure which enables small businesses to get easy access to financial servi ...

  • Motion Recruitment

    Compliance Analyst

    1 week ago


    Motion Recruitment San Francisco, United States

    Compliance Analyst · San Francisco, California · **100% Remote** · Contract · $36.67/hr - $36.67/hr · Our large crypto company is looking for a contract Compliance Analyst. This is a remote contract position. · The Global Complaints team is divided into three units, namely Consum ...

  • Motion Recruitment

    Compliance Analyst

    5 days ago


    Motion Recruitment San Francisco, United States

    Ourlarge cryptocompany is looking for a contractCompliance Analyst.This is aremote contract position. · The Global Complaints team is divided into three units, namely Consumer Complaints, Regulatory Complaints and Litigation Support. Each unit is made up of L2 complaints analyst ...

  • BPCE

    Compliance Analyst

    4 days ago


    BPCE San Francisco, United States

    Overview: · The Compliance Analyst - RIA provides registered investment adviser compliance support to the Legal and Compliance Department. The position will primarily assist with the administration of the Code of Ethics Compliance Program; assess, draft, and perform on-site audit ...

  • Wandb

    Compliance Analyst

    3 days ago


    Wandb San Francisco, United States

    At Weights & Biases, our mission is to build the best developer tools for AI developers. Weights & Biases is a series C company with $250 million in funding and a rapidly growing user base. Our platform is an essential piece of the daily work for machine learning engineers, from ...

  • Sunrun

    Compliance Analyst

    7 minutes ago


    Sunrun San Francisco, United States

    Everything we do at Sunrun is driven by a determination to transform the way we power our lives. We know that starts at the individual employee level. We strive to foster an environment you can thrive in through our commitment to diversity, inclusion and belonging. · As an Compl ...

  • Parafin Inc

    Compliance Analyst

    4 days ago


    Parafin Inc San Francisco, United States

    About Us: · At Parafin, our mission is to grow small businesses. · Small businesses are the backbone of our economy, yet banks do not have their back. Parafin is a technology company that builds infrastructure which enables small businesses to get easy access to financial servi ...

  • US Tech Solutions

    Compliance Analyst

    1 week ago


    US Tech Solutions San Francisco, United States

    Duties · : · The Global Complaints team is divided into three units, namely Consumer Complaints, Regulatory Complaints and Litigation Support. Each unit is made up of L2 complaints analysts responsible for production work - they are expected to accurately review and respond to ...

  • Parafin Inc

    Compliance Analyst

    2 days ago


    Parafin Inc San Francisco, United States

    Job Description · Job Description · About Us: · At Parafin, our mission is to grow small businesses. · Small businesses are the backbone of our economy, yet banks do not have their back. Parafin is a technology company that builds infrastructure which enables small businesses ...

  • Vercel Corp

    Compliance Analyst

    5 days ago


    Vercel Corp San Francisco, United States

    Vercel · Vercel's Frontend Cloud gives developers the frameworks, workflows, and infrastructure to build a faster, more personalized Web. · View company page · Vercel's Frontend Cloud provides the developer experience and infrastructure to build, scale, and secure a faster, mo ...

  • Weights & Biases

    Compliance Analyst

    2 days ago


    Weights & Biases San Francisco, California, United States Full time

    At Weights & Biases, our mission is to build the best developer tools for AI developers. Weights & Biases is a series C company with $250 million in funding and a rapidly growing user base. Our platform is an essential piece of the daily work for machine learning engineers, from ...

  • Parafin

    Compliance Analyst

    14 hours ago


    Parafin San Francisco, United States

    Job Description · Job DescriptionAbout Us: · At Parafin, our mission is to grow small businesses. · Small businesses are the backbone of our economy, yet banks do not have their back. Parafin is a technology company that builds infrastructure which enables small businesses to ge ...

  • Living Talent Company

    Compliance Analyst

    5 days ago


    Living Talent Company San Francisco, United States

    Investment Management Firm (100B+ AUM) Fulltime Hybrid, 3 days in office in Chicago Loop Full relocation availableBase + Bonus 140k - 160k Robust benefits package Job Details:Code, test, and implement investment compliance rules in Charles River IMS (CRIMS)Interpret investment ag ...