EP 30 — Postman's Sam Chehab on Three Unteachable Traits He Hires For episode artwork

EPISODE · Feb 24, 2026 · 27 MIN

EP 30 — Postman's Sam Chehab on Three Unteachable Traits He Hires For

from Future of Data Security · host Qohash

At Postman's scale of 40 million developers generating billions of API requests, Sam Chehab, Head of Security & IT, centers on three enforcement domains: authenticated and encrypted data paths, zero-trust inter-service communication, and runtime instrumentation. His vendor evaluation is just as precise, cutting past feature lists to one demand: show me the architecture diagram and walk through exactly how your solution addresses my threat models.Sam identifies why generative AI creates fundamentally new risk: the combination of private data access, untrusted content processing, and external communication capability. This trifecta explains why browser-based AI is nearly impossible to contain; it touches local machines, queries the open web, and executes actions on your behalf. Sam also covers how he screens for three traits he can't train: initiative to self-direct research, attitude to absorb constant setbacks, and aptitude to process how rapidly this field moves.Topics discussed:Implementing data path integrity, zero-trust inter-service authentication, and runtime instrumentation with immutable logsEvaluating cybersecurity vendors by demanding architecture diagrams and specific threat model solutions rather than feature listsManaging freemium platform security with anomaly detection, rate limiting, and abuse prevention across 40 million developersIdentifying AI security's dangerous trifecta: private data access, untrusted content processing, and external communication capabilities Building MCP generators that enable least-privilege API servers by allowing developers to select only required methods before deploymentUsing AI agents to generate security tests during development, shifting validation from security teams to automated testingApplying security hygiene fundamentals before adopting specialized vendor solutionsHiring security teams based on three unteachable traits: initiative, attitude, and aptitude

At Postman's scale of 40 million developers generating billions of API requests, Sam Chehab, Head of Security & IT, centers on three enforcement domains: authenticated and encrypted data paths, zero-trust inter-service communication, and runtime instrumentation. His vendor evaluation is just as precise, cutting past feature lists to one demand: show me the architecture diagram and walk through exactly how your solution addresses my threat models.Sam identifies why generative AI creates fundamentally new risk: the combination of private data access, untrusted content processing, and external communication capability. This trifecta explains why browser-based AI is nearly impossible to contain; it touches local machines, queries the open web, and executes actions on your behalf. Sam also covers how he screens for three traits he can't train: initiative to self-direct research, attitude to absorb constant setbacks, and aptitude to process how rapidly this field moves.Topics discussed:Implementing data path integrity, zero-trust inter-service authentication, and runtime instrumentation with immutable logsEvaluating cybersecurity vendors by demanding architecture diagrams and specific threat model solutions rather than feature listsManaging freemium platform security with anomaly detection, rate limiting, and abuse prevention across 40 million developersIdentifying AI security's dangerous trifecta: private data access, untrusted content processing, and external communication capabilities Building MCP generators that enable least-privilege API servers by allowing developers to select only required methods before deploymentUsing AI agents to generate security tests during development, shifting validation from security teams to automated testingApplying security hygiene fundamentals before adopting specialized vendor solutionsHiring security teams based on three unteachable traits: initiative, attitude, and aptitude

NOW PLAYING

EP 30 — Postman's Sam Chehab on Three Unteachable Traits He Hires For

0:00 27:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Ask A Spaceman Archives - 365 Days of Astronomy Ask A Spaceman Archives - 365 Days of Astronomy Podcasting Astronomy Every Day of the Year Eat to Live Jenna Fuhrman, Dr. Fuhrman Our health is our most precious gift and smart nutrition can change your life. Each month, join Dr. Fuhrman and his daughter, Jenna Fuhrman as they discuss important topics in the world of nutrition. Eat to Live will change the way you eat and think about food. French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? That Hoarder: Overcome Compulsive Hoarding That Hoarder Hoarding disorder is stigmatised and people who hoard feel vast amounts of shame. This podcast began life as an audio diary, an anonymous outlet for somebody with this weird condition. That Hoarder speaks about her experiences living with compulsive hoarding, she interviews therapists, academics, researchers, children of hoarders, professional organisers and influencers, and she shares insight and tips for others with the problem. Listened to by people who hoard as well as those who love them and those who work with them, Overcome Compulsive Hoarding with That Hoarder aims to shatter the stigma, share the truth and speak openly and honestly to improve lives.

Frequently Asked Questions

How long is this episode of Future of Data Security?

This episode is 27 minutes long.

When was this Future of Data Security episode published?

This episode was published on February 24, 2026.

What is this episode about?

At Postman's scale of 40 million developers generating billions of API requests, Sam Chehab, Head of Security & IT, centers on three enforcement domains: authenticated and encrypted data paths, zero-trust inter-service communication, and runtime...

Can I download this Future of Data Security episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!