Hiring.Camp

Sr Analyst, Cybersecurity Threat

PayPal

·

Today

Location
IND - Tamil Nadu - Chennai - Corp - Old Mahabalipuram Rd, India
Type
Full-time
Department
IT
Education
Bachelor
Source
Workday

Description

The Company

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy. 

We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.

We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards.  Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade. 

Our beliefs are the foundation for how we conduct business every day.  We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.

Job Summary:

What you need to know about the role

The Offensive Security team helps protect PayPal and its brands by testing products, applications, infrastructure, and emerging technologies. We work closely with engineering teams to identify security issues, explain the risk, and support effective remediation.
This role combines hands-on penetration testing with vulnerability validation. You will review findings from AI assisted code reviews and other automated security tools, reproduce potential vulnerabilities, and assess their exploitability and business impact.

Meet our team

The Offensive Security team works with groups across PayPal to assess the security of products and technologies throughout the product development life cycle. The team performs authorized testing across web, mobile, API, thick client, cloud, infrastructure, and other technology environments

Job Description:

Essential Responsibilities:

  • Independently apply security best practices to enhance and optimize cyber threat management, ensuring robust protection and efficiency, while beginning to understand and align security measures with business objectives.
  • Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture and cyber threat management.
  • Analyze and resolve security challenges by adapting standard cyber threat management processes and exploring alternative approaches to address complex threats.
  • Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
  • Collaborate with key partners to gather and incorporate feedback, driving continuous improvements in cyber threat management.

Minimum Qualifications:

  • 3+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.

Additional Responsibilities & Preferred Qualifications:

Your way to impact:


Performs hands-on penetration testing and vulnerability validation across web, mobile, API, and cloud environments. Reviews and reproduces findings from AI-assisted code reviews and automated security tools to assess exploitability, business impact, and remediation priority. Conducts secure code reviews to identify complex, business logic vulnerabilities, and partners with engineering teams to communicate risk and drive remediation to closure. Individual-contributor role requiring end-to-end ownership of assessments, from scoping through reporting and remediation support.


In your day-to-day role you will be responsible for


  • Scope and perform penetration tests from planning through reporting and remediation support.
  • Perform hands-on testing of web applications, mobile applications, APIs, thick client applications, and internal infrastructure.
  • Review and validate potential vulnerabilities identified through AI assisted code reviews and other automated security tools.
  • Reproduce findings and assess exploitability, business impact, severity, remediation priority, and whether a finding is a false positive.
  • Perform secure source code reviews and identify complex vulnerabilities, including business logic flaws.
  • Test authentication, authorization, session management, OAuth, OIDC, JWT, CSP, cryptography, and other application security controls.
  • Understand cloud environments, APIs, identity flows, and common attacker techniques.
  • Evaluate AI and ML systems and use automation to improve the efficiency and depth of testing.
  • Communicate findings with clear context, reproduction steps, attack scenarios, and practical remediation guidance.
  • Support engineering teams through remediation and closure of security findings.
  • Assess systems against requirements such as PCI DSS and provide actionable remediation guidance.
  • Conduct security research and contribute to other Offensive Security initiatives as needed.

What do you need to bring


  • Bachelor's degree or higher in Information Security, Computer Science, or a related technical discipline.
  • At least five years of hands-on penetration testing experience, including the ability to manage assessments from scoping through reporting and remediation support.
  • Strong experience in web application penetration testing, with hands-on experience testing mobile applications, APIs, and thick client applications.
  • Experience with secure source code review and identifying complex vulnerabilities, including business logic flaws.
  • Knowledge of application security, cloud environments, identity flows, and the MITRE ATT&CK framework.
  • Experience with testing approaches such as PTES and OWASP.
  • Proficiency in at least one scripting language, such as Python, PowerShell, or Perl.
  • Software development experience in a language such as Java or Node.js is preferred.
  • Strong writing, communication, attention to detail, and critical thinking skills.
  • Security certifications such as OSWE, OSCP, GPEN, GWAPT, or CEH are a plus.
  • We value diverse perspectives and encourage

Subsidiary:

PayPal

Travel Percent:

0

PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes.  Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal email domains. If you suspect fraudulent activity, please report it immediately.  To learn more about how to identify and avoid recruitment fraud please visit https://careers.pypl.com/contact-us

For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in-person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.

Our Benefits:

At PayPal, we’re committed to building an equitable and inclusive global economy. And we can’t do this without our most important asset-you. That’s why we offer comprehensive, choice-based programs, to support all aspects of personal wellbeing—physical, emotional, and financial—delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.

Who We Are:

Click Here to learn more about our culture and community.

Commitment to Diversity and Inclusion 

PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law.  In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities.  If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at [email protected].  

Belonging at PayPal: 

Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued. We are proud to have a diverse workforce reflective of the merchants, consumers, and communities that we serve, and we continue to take tangible actions to cultivate inclusivity and belonging at PayPal.

Any general requests for consideration of your skills, please Join our Talent Community.

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates. Please don’t hesitate to apply.

Skills

PythonJavaPerlNode.jsPenetration TestingOAuth

Similar Jobs

30

Senior Cybersecurity Analyst

Triumf·TRIUMF, Canada

Today

Senior Cybersecurity Analyst

relay·Raleigh, NC +1

1w ago

Sr. Analyst, Cybersecurity

Nexgen Sports Group Inc·Orlando, FL

1w ago

Senior Cybersecurity Analyst

Leidos·2019 DISA HQ Fort George G. Meade MD, US

1w ago

Senior Cybersecurity Analyst

ISO New England Inc.·ISO New England Inc., One Sullivan Road

1w ago

Senior Analyst, Cybersecurity

Ensemble Health Partners·Blue Ash CBO, US +1·Remote

2w ago

Senior Analyst - Cybersecurity

Freshworks CRM·Chennai, India

1mo ago

Cybersecurity Analyst Senior

Basecamp·Minnesota - Minneapolis, US·Hybrid

1mo ago

CyberSecurity Senior Analyst

Nelnet as the nation·Centennial, CO

1mo ago

Sr Cybersecurity Analyst

Dexcom·Bengaluru, KA

2mo ago

Sr Cybersecurity Analyst

Dexcom·Bengaluru, India

2mo ago

Cybersecurity Analyst, Senior

Cook Children's·Rosedale Office Building, US

3mo ago

Sr. Cybersecurity Analyst

Johnson & Quin·Niles, IL

4mo ago

Senior Cybersecurity Analyst

Cyberphore·New Westminster, British Columbia

10mo ago

Sr Analyst-Cybersecurity

Ascension1 Ascension·Remote, US·Remote

1y+ ago

Sr Analyst, Vendor Risk & Cybersecurity Policy Management

PVH as one of the·Office India

Today

Sr. Principal Classified Cybersecurity Analyst - Polygraph

Northrop Grumman·Aurora, CO·Onsite

1d ago

Sr. Principal Classified Cybersecurity Analyst - Polygraph

Northrop Grumman·COAU01, US·Onsite

1d ago

Cybersecurity Incident Senior Analyst

Babelgroup·MADRID, Spain +4·Remote

2d ago

[PUB-IDTD] Sr/Cybersecurity Analyst, Governance, Compliance and Audit

Sggovterp·PUB - WATERHUB OFFICE BLK #04-01, Singapore

1w ago

Cybersecurity Blue Team Analyst – Senior

Sentinel Group·Chantilly, VA

1w ago

Cybersecurity Blue Team Analyst – Senior

Sentinel Group·Chantilly, VA

1w ago

Sr Global Cybersecurity Analyst

AgReliant Genetics·Westfield, IN

1w ago

Sr Principal Classified Cybersecurity Analyst - Secret

Northrop Grumman·COCO01, US·Onsite

1w ago

Sr Principal Classified Cybersecurity Analyst - Secret

Northrop Grumman·Colorado Springs, CO·Onsite

1w ago

Cybersecurity GRC Sr. Analyst

Pepsi Co·Warszawa, PL

1w ago

Acquisition Cybersecurity Operations (ACO) - Senior SOC Analyst

JPMorgan Chase·LONDON, GB

2w ago

Acquisition Cybersecurity Operations (ACO) - Senior SOC Analyst

JP Morgan Chase·LONDON, GB

2w ago

Senior Cybersecurity Analyst, OT Compliance

Marathon Petroleum Corporation (MPC)·Findlay OH Main Bldg, US +2

2w ago

Senior Business Analyst – Cybersecurity & DevSecOps

Thermofisher·India - Bangalore - 5th floor, Building No. 3·Hybrid

2w ago