← Back to job listings
PO
Senior Governance, Risk, and Compliance Engineer
Postman · San Francisco, United States
About The Role
Join Postman, a leading API platform, as a Senior Governance, Risk, and Compliance Engineer. In this hands-on technical role, you will design and operate GRC automation, build integrations between GRC workflows and internal systems, and lead key compliance initiatives. You will partner with various stakeholders to shape Postman's GRC strategy and serve as a trusted technical advisor on risk and compliance. Enjoy benefits such as unlimited PTO, health care coverage, and career development opportunities.
- Design, build, and operate GRC automation across evidence collection, control testing, risk tracking, and compliance reporting.
- Lead SOC 2, ISO 27001, HIPAA, and FedRAMP initiatives, owning at least one certification end-to-end.
- Drive continuous controls monitoring and automated evidence collection, and improve audit readiness through automation and process optimization.
- The ideal candidate has experience implementing and maturing compliance programs, including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and FedRAMP, and can translate security and risk requirements into practical engineering solutions
- Experience with AI-assisted workflows or LLM-powered tooling
- Strong communication skills translating risk into engineering requirements
- Bachelor's degree or equivalent experience
- 6+ years of cybersecurity GRC experience in high-growth technology environments
- Knowledge of SOC 2, ISO 27001, HIPAA, GDPR, CCPA, and/or FedRAMP
- Proficiency in Python, JavaScript, or similar for production-grade automation
- Experience integrating GRC tooling with ticketing, identity, asset management, and cloud platforms
- Experience implementing and maturing GRC programs with pragmatic, engineered solutions
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring