PayPal logo

Sr Analyst, Cybersecurity Threat

PayPal · Posted Sep 23

Online payment processing, digital wallet, money transfer, and financial services

Chennai, Tamil Nadu, IndiaFull-timeOnsiteSenior Level5+ years₹25.0L–₹40.0L yearly100+ applicants
Financial TechnologyPaymentsDigital WalletsOnline PaymentsPublic Company
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

The Offensive Security team helps protect PayPal and its brands by testing products, applications, infrastructure, and emerging technologies, working with engineering teams to identify security issues, explain the risk, and support effective remediation. The team performs authorized testing across web, mobile, API, thick client, cloud, and infrastructure environments throughout the product development life cycle. This role combines hands-on penetration testing with vulnerability validation, reviewing findings from AI assisted code reviews and other automated security tools, reproducing potential vulnerabilities, and assessing their exploitability and business impact.

What you will do

  • Independently apply security best practices to enhance and optimize cyber threat management, ensuring robust protection and efficiency, while beginning to understand and align security measures with business objectives.
  • Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture and cyber threat management.
  • Analyze and resolve security challenges by adapting standard cyber threat management processes and exploring alternative approaches to address complex threats.
  • Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
  • Collaborate with key partners to gather and incorporate feedback, driving continuous improvements in cyber threat management.
  • Scope and perform penetration tests from planning through reporting and remediation support.
  • Perform hands-on testing of web applications, mobile applications, APIs, thick client applications, and internal infrastructure.
  • Review and validate potential vulnerabilities identified through AI assisted code reviews and other automated security tools.
  • Reproduce findings and assess exploitability, business impact, severity, remediation priority, and whether a finding is a false positive.
  • Perform secure source code reviews and identify complex vulnerabilities, including business logic flaws.
  • Test authentication, authorization, session management, OAuth, OIDC, JWT, CSP, cryptography, and other application security controls.
  • Understand cloud environments, APIs, identity flows, and common attacker techniques.
  • Evaluate AI and ML systems and use automation to improve the efficiency and depth of testing.
  • Communicate findings with clear context, reproduction steps, attack scenarios, and practical remediation guidance.
  • Support engineering teams through remediation and closure of security findings.
  • Assess systems against requirements such as PCI DSS and provide actionable remediation guidance.
  • Conduct security research and contribute to other Offensive Security initiatives as needed.

Skills used in this role

Penetration TestingVulnerability ValidationSecure Source Code ReviewWeb Application SecurityMobile Application TestingAPI SecurityThick Client TestingCloud SecurityIdentity FlowsPythonPowerShellPerlJavaNode.jsOAuthOIDCJWTCSPCryptographyMITRE ATT&CKOWASPPTESPCI DSSAIML

What the employer is looking for

  • 3+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.
  • Bachelor's degree or higher in Information Security, Computer Science, or a related technical discipline.
  • At least five years of hands-on penetration testing experience, including the ability to manage assessments from scoping through reporting and remediation support.
  • Strong experience in web application penetration testing, with hands-on experience testing mobile applications, APIs, and thick client applications.
  • Experience with secure source code review and identifying complex vulnerabilities, including business logic flaws.
  • Knowledge of application security, cloud environments, identity flows, and the MITRE ATT&CK framework.
  • Experience with testing approaches such as PTES and OWASP.
  • Proficiency in at least one scripting language, such as Python, PowerShell, or Perl.
  • Software development experience in a language such as Java or Node.js is preferred.
  • Strong writing, communication, attention to detail, and critical thinking skills.
  • Security certifications such as OSWE, OSCP, GPEN, GWAPT, or CEH are a plus.
  • We value diverse perspectives and encourage

Benefits and support

  • Generous paid time off
  • Healthcare coverage for you and your family
  • Resources to create financial security and support your mental health
  • Balanced hybrid work model offering 3 days in the office and 2 days at your choice of either the PayPal office or your home workspace

About PayPal

PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system that supports online money transfers globally. It serves as an electronic alternative to traditional paper methods, providing merchant processing, digital wallets, and peer-to-peer payment services through major brands like Venmo, Braintree, and Xoom.

Industry
Financial Technology
Company size
23800 employees
Founded
1998
Location
San Jose, California, USA
Funding stage
Public Company

Funding

Public Company · $216M raised

BlueRun VenturesINGMDP
  • 2022-07-26Post IPO

Leadership

EL
Enrique Lores

President & Chief Executive Officer

JM

Jamie Miller

Chief Financial & Operating Officer

SV

Srini Venkatesan

Chief Technology Officer