Jobs Companies PayPal Staff Security Engineer, API Security

Sobre esta vaga de Staff Security Engineer, API Security na PayPal

PayPal · Híbrido · Bangalore, Karnataka, India

The Company

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy. 

We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.

We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards.  Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade. 

Our beliefs are the foundation for how we conduct business every day.  We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.

Job Summary:

This role sits at the core of Product and AI Security engineering. This job leverages security expertise to resolve complex security issues, partners with teams to drive security initiatives, applies analytical skills to solve security challenges, contributes to security improvements, and influences security processes.

Job Description:

Essential Responsibilities:

  • Leverage specialized security expertise to identify and resolve complex security issues, recommending best practices and determining new approaches that have an impact on broader security operations, while aligning security strategies with business priorities
  • Partner across teams and key stakeholders to drive security initiatives, leading and solutioning complex projects and programs to strengthen overall security posture.
  • Apply advanced analytical skills and sound judgment to solve security challenges, considering diverse perspectives and innovative solutions. Stay current with industry trends and emerging technologies, understanding their security implications to the company’s context.
  • Directly contribute to improvements within the security domain and occasionally beyond, ensuring decisions lead to meaningful enhancements in security practices.
  • Leverage relationships across teams, both within and outside of security, to influence initiatives and integrate feedback into security processes.

Minimum Qualifications:

  • 5+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.

Additional Responsibilities & Preferred Qualifications:

In your day-to-day role you will be responsible for:

  • Build the end-state API security capability plane: Consolidate today's separate API security lint, gateway traffic visibility, shadow-API detection, and schema (GraphQL/AsyncAPI) security checks into a single, coherent capability that plugs into the org's shared policy-as-code enforcement architecture - the same engine already governing container, static-analysis, and software-composition findings. Design the end state first - this is not a request to bolt on another point tool.
  • Take the pre-release API security gate from draft architecture decision to a shipped control, working with the Staff Engineer who owns enforcement architecture to get the gateway-level hard-block policy enforced end to end. This person unblocks stalled decisions - they do not wait for consensus to form on its own.
  • Own the dynamic application security testing (DAST) tooling strategy end to end: complete the current tool evaluation into a production migration decision, and execute it.
  • Extend API security capability into two domains identified as organizational blind spots - pipeline access & execution control, and systemic artifact consumption verification - treating API security as one instance of the broader supply-chain security problem, not a silo, and enabling them through the shared enforcement architecture rather than a parallel one.
  • Be a force multiplier: mentor engineers across the merged team, unblock stuck initiatives, and drive delivery and innovation without waiting to be told what's next. Standard staff-engineer responsibilities and day-to-day routines apply in full - technical leadership, design review, on-call/escalation, sustaining engineering, and maintenance are shared responsibilities like any other staff engineer, not exceptions carved out for this role.
  • Shape the Roadmap: Work with the engineering manager and tech leads to shape and prioritize the team's backlog, identify emerging business problems before they become fire drills, and think beyond the current scope of the role rather than just executing what's already been defined.

What do you need to bring:

  • Software Engineering: 5+ years building production software with demonstrated staff-level ownership of a platform or system end-to-end, with hands-on coding experience in Python or Go - not just contributing features inside someone else's architecture.
  • API Security Engineering: Deep, hands-on expertise in API architecture (REST, GraphQL, AsyncAPI), authZ/authN (OAuth2 scopes, token/session models), and API gateway or service-mesh internals (Envoy-class systems or equivalent).
  • AI Knowledge: Working knowledge of how AI and agentic traffic is changing the API threat model - AI-driven API abuse patterns, agent-to-API authentication, and the security implications of agentic commerce - enough to reason about it directly, not just defer to the AI security team.
  • Working fluency in policy-as-code approaches to security enforcement and CI/CD security gating - you can write enforcement policy, not just consume someone else's.
  • Practical understanding of DAST/SAST tooling internals, deep enough to evaluate and replace an underperforming tool rather than just operate whatever is already in place.
  • Security fundamentals across product, cloud, and vulnerability management that go a bit deeper than most - you know why a control exists, not just that it exists.
  • Deep knowledge of the OWASP API Security Top 10 and common API abuse patterns (broken object-level authorization, excessive data exposure, resource/rate-limit abuse), and how to design controls that close them - not just cite the list.
  • Hands-on experience with API traffic-protection mechanisms - rate limiting, bot/abuse mitigation, WAF/API gateway policy, and mutual TLS for service-to-service authentication.
  • Working knowledge of API discovery and inventory practices, deep enough to stand up shadow-API detection rather than just consume a vendor's dashboard.

Subsidiary:

PayPal

Travel Percent:

0

PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes.  Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal email domains. If you suspect fraudulent activity, please report it immediately.  To learn more about how to identify and avoid recruitment fraud please visit https://careers.pypl.com/contact-us

For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in-person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.

Our Benefits:

At PayPal, we’re committed to building an equitable and inclusive global economy. And we can’t do this without our most important asset-you. That’s why we offer comprehensive, choice-based programs, to support all aspects of personal wellbeing—physical, emotional, and financial—delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.

Who We Are:

Click Here to learn more about our culture and community.

Commitment to Diversity and Inclusion 

PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law.  In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities.  If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at [email protected].  

Belonging at PayPal: 

Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued. We are proud to have a diverse workforce reflective of the merchants, consumers, and communities that we serve, and we continue to take tangible actions to cultivate inclusivity and belonging at PayPal.

Any general requests for consideration of your skills, please Join our Talent Community.

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates. Please don’t hesitate to apply.

Pronto para se candidatar à PayPal?
Candidatar-se à PayPal

Sobre a PayPal

When applying for a job you are required to create an account, if you have already created an account - click Sign In. Creating an account will allow you to follow the progress of your applications. Our system does have some requirements that will help us process your application, below are some guidelines for creation of your account: Provide full legal First Name/Family Name – this is important for us to ensure our future hires have the right system set up. Please Capitalize first letter of your First and Last Name. Please avoid using fully capitalized text for your First and/or Last Name. NOTE: If your name is hyphenated or has multiple capitalization, please use the same format as your g

Ver todas as vagas na PayPal →

Vagas semelhantes

OS
AI Security Engineer / Architect
o9 Solutions
⚡ Candidate-se cedo Bangalore, Karnataka, India Presencial
● Nova 👁 Vista ✓ Candidatada há 6d
Harness
Senior Security Engineer - Customer Engineering
Harness
⚡ Candidate-se cedo Bengaluru, Karnataka, India Presencial
● Nova 👁 Vista ✓ Candidatada há 3sem
Danaher
Senior Engineer, Application Security
Danaher
⚡ Candidate-se cedo Pune, Maharashtra, India Presencial
● Nova 👁 Vista ✓ Candidatada há 4sem
Danaher
Senior Engineer, AI Security & Automation
Danaher
⚡ Candidate-se cedo Pune, Maharashtra, India Presencial
● Nova 👁 Vista ✓ Candidatada há 4sem
Danaher
Lead Engineer Manufacturing Security
Danaher
⚡ Candidate-se cedo Pune, Maharashtra, India Presencial
● Nova 👁 Vista ✓ Candidatada há 4sem
Harness
Staff Security Research Engineer
Harness
⚡ Candidate-se cedo Bengaluru, Karnataka, India Presencial
● Nova 👁 Vista ✓ Candidatada há 2m
Allwyn UK
Data & AI Security Engineer (6 Months FTC)
Allwyn UK
⚡ Candidate-se cedo Watford, England, United Kingd... Presencial
● Nova 👁 Vista ✓ Candidatada há 4h
KC
Senior AI Engineer - Security
Kiwi.com
⚡ Candidate-se cedo Barcelona Híbrido
● Nova 👁 Vista ✓ Candidatada há 4h
Aspora
Senior Information Security Engineer
Aspora
⚡ Candidate-se cedo Bangalore Presencial
● Nova 👁 Vista ✓ Candidatada há 4h

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na PayPal

Ver todas as vagas na PayPal →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis