How We Scaled Security Reviews Without Slowing Down Engineering
Blog post from Postman
Postman has revamped its Security Review Process (SRP) to align with its fast-paced development culture without compromising security, addressing challenges faced with their previous model that relied heavily on manual Vulnerability Assessment & Penetration Testing (VAPT). The new SRP v2 introduces a risk-based, automation-first approach integrated into the Software Development Life Cycle (SDLC), which differentiates review processes based on the risk level of releases, thus optimizing resources. It incorporates structured data collection during security reviews, facilitates earlier AppSec involvement, and reduces unnecessary manual interventions for low-risk changes, while ensuring critical services receive thorough scrutiny. The process involves an AppSec Review (ASR) Jira ticket for every major release, mandatory security triage questionnaires, and a security masterplan document to centralize information and streamline security tasks. This evolution has led to significant improvements, such as reduced wait times, increased developer productivity, and reclaimed AppSec capacity, while maintaining robust security oversight through monthly audits and continuous validation. Looking forward, Postman aims to enhance this framework with a data-driven risk matrix and AI-augmented security insights, aiming for a security model that adapts dynamically to the evolving product and threat landscape.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Developer Experience | 1 | 611 | 275 | 100 | +27% |
| LLM | 1 | 5,932 | 1,046 | 223 | -2% |
| RAG | 1 | 941 | 216 | 85 | -48% |
| Real-time | 1 | 6,296 | 1,346 | 246 | -2% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.