Home / Companies / Postman / Blog / Post Details
Content Deep Dive

How We Scaled Security Reviews Without Slowing Down Engineering

Blog post from Postman

Post Details
Company
Date Published
Author
Anurag Mewar
Word Count
1,841
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

Postman has revamped its Security Review Process (SRP) to align with its fast-paced development culture without compromising security, addressing challenges faced with their previous model that relied heavily on manual Vulnerability Assessment & Penetration Testing (VAPT). The new SRP v2 introduces a risk-based, automation-first approach integrated into the Software Development Life Cycle (SDLC), which differentiates review processes based on the risk level of releases, thus optimizing resources. It incorporates structured data collection during security reviews, facilitates earlier AppSec involvement, and reduces unnecessary manual interventions for low-risk changes, while ensuring critical services receive thorough scrutiny. The process involves an AppSec Review (ASR) Jira ticket for every major release, mandatory security triage questionnaires, and a security masterplan document to centralize information and streamline security tasks. This evolution has led to significant improvements, such as reduced wait times, increased developer productivity, and reclaimed AppSec capacity, while maintaining robust security oversight through monthly audits and continuous validation. Looking forward, Postman aims to enhance this framework with a data-driven risk matrix and AI-augmented security insights, aiming for a security model that adapts dynamically to the evolving product and threat landscape.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Developer Experience 1 611 275 100 +27%
LLM 1 5,932 1,046 223 -2%
RAG 1 941 216 85 -48%
Real-time 1 6,296 1,346 246 -2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.