
Sr Analyst, Cybersecurity Threat
PayPal · Posted Sep 23
Online payment processing, digital wallet, money transfer, and financial services
Get a personal compatibility score
Add a resume for personal matches
About the role
The Offensive Security team helps protect PayPal and its brands by testing products, applications, infrastructure, and emerging technologies, working with engineering teams to identify security issues, explain the risk, and support effective remediation. The team performs authorized testing across web, mobile, API, thick client, cloud, and infrastructure environments throughout the product development life cycle. This role combines hands-on penetration testing with vulnerability validation, reviewing findings from AI assisted code reviews and other automated security tools, reproducing potential vulnerabilities, and assessing their exploitability and business impact.
What you will do
- Independently apply security best practices to enhance and optimize cyber threat management, ensuring robust protection and efficiency, while beginning to understand and align security measures with business objectives.
- Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture and cyber threat management.
- Analyze and resolve security challenges by adapting standard cyber threat management processes and exploring alternative approaches to address complex threats.
- Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
- Collaborate with key partners to gather and incorporate feedback, driving continuous improvements in cyber threat management.
- Scope and perform penetration tests from planning through reporting and remediation support.
- Perform hands-on testing of web applications, mobile applications, APIs, thick client applications, and internal infrastructure.
- Review and validate potential vulnerabilities identified through AI assisted code reviews and other automated security tools.
- Reproduce findings and assess exploitability, business impact, severity, remediation priority, and whether a finding is a false positive.
- Perform secure source code reviews and identify complex vulnerabilities, including business logic flaws.
- Test authentication, authorization, session management, OAuth, OIDC, JWT, CSP, cryptography, and other application security controls.
- Understand cloud environments, APIs, identity flows, and common attacker techniques.
- Evaluate AI and ML systems and use automation to improve the efficiency and depth of testing.
- Communicate findings with clear context, reproduction steps, attack scenarios, and practical remediation guidance.
- Support engineering teams through remediation and closure of security findings.
- Assess systems against requirements such as PCI DSS and provide actionable remediation guidance.
- Conduct security research and contribute to other Offensive Security initiatives as needed.
Skills used in this role
What the employer is looking for
- 3+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.
- Bachelor's degree or higher in Information Security, Computer Science, or a related technical discipline.
- At least five years of hands-on penetration testing experience, including the ability to manage assessments from scoping through reporting and remediation support.
- Strong experience in web application penetration testing, with hands-on experience testing mobile applications, APIs, and thick client applications.
- Experience with secure source code review and identifying complex vulnerabilities, including business logic flaws.
- Knowledge of application security, cloud environments, identity flows, and the MITRE ATT&CK framework.
- Experience with testing approaches such as PTES and OWASP.
- Proficiency in at least one scripting language, such as Python, PowerShell, or Perl.
- Software development experience in a language such as Java or Node.js is preferred.
- Strong writing, communication, attention to detail, and critical thinking skills.
- Security certifications such as OSWE, OSCP, GPEN, GWAPT, or CEH are a plus.
- We value diverse perspectives and encourage
Benefits and support
- Generous paid time off
- Healthcare coverage for you and your family
- Resources to create financial security and support your mental health
- Balanced hybrid work model offering 3 days in the office and 2 days at your choice of either the PayPal office or your home workspace
About PayPal
PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system that supports online money transfers globally. It serves as an electronic alternative to traditional paper methods, providing merchant processing, digital wallets, and peer-to-peer payment services through major brands like Venmo, Braintree, and Xoom.
- Industry
- Financial Technology
- Company size
- 23800 employees
- Founded
- 1998
- Location
- San Jose, California, USA
- Funding stage
- Public Company
Funding
Public Company · $216M raised
- 2022-07-26Post IPO
Leadership
President & Chief Executive Officer
Jamie Miller
Chief Financial & Operating Officer
Srini Venkatesan
Chief Technology Officer
Recent coverage
PR Newswire
PayPal Releases 2026 Holiday Shopping Survey Highlighting Consumer Flexibility and Value2026-09-30
Barchart
How to Play PYPL Stock Amid New Takeover Rumors and Strategic Restructuring2026-09-30
GuruFocus
PayPal Holdings Inc Stock Up 3.0% and Still Undervalued According to GF Score2026-10-06
The Motley Fool
Are PayPal Shares Too Cheap to Ignore Right Now?2026-10-02