Cybersecurity Engineer

Location
IND - Karnataka - Bangalore - Corp - Sarjapur Main Rd
Workplace
Hybrid

About this role

The Company

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy.

We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.

We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards. Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade.

Our beliefs are the foundation for how we conduct business every day. We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.

Job Summary:

<p>Join PayPal’s Offensive Security team to help protect our products, applications, infrastructure, and emerging technologies. You’ll conduct hands-on penetration testing and secure code reviews across web, mobile, APIs, cloud, infrastructure, and other environments. You’ll also validate findings from AI-assisted code reviews and automated security tools, assessing exploitability and business impact while identifying complex vulnerabilities and business logic flaws. Working closely with engineering teams, you’ll translate findings into realistic attack scenarios and practical remediation guidance.</p>

Job Description:

Essential Responsibilities:

  • Independently apply security best practices to enhance and optimize systems, ensuring robust protection and efficiency, while beginning to understand and align security solutions with business objectives.
  • Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture.
  • Analyze and resolve security challenges by adapting standard processes and exploring alternative approaches to address complex threats.
  • Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
  • Collaborate with other engineers to gather and incorporate feedback, driving continuous improvements in security processes.

Minimum Qualifications:

  • 3+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.

Additional Responsibilities & Preferred Qualifications:

  • 5+ years of hands-on penetration testing experience preferred, including experience managing security assessments from scoping and execution through reporting and remediation support.
  • Experience conducting secure source-code reviews and identifying complex vulnerabilities and business logic flaws.
  • Knowledge of application security, cloud environments, identity flows, common attacker techniques, and the MITRE ATT&CK framework.
  • Familiarity with penetration-testing methodologies and guidance such as PTES and OWASP.
  • Proficiency in a scripting language such as Python, PowerShell, or Perl.
  • Software development experience with languages or platforms such as Java or Node.js is preferred.
  • Experience assessing AI/ML systems or using AI-assisted security analysis and automation is a plus.
  • Security certifications such as OSWE, OSCP, GPEN, GWAPT, or CEH are a plus.
  • Strong technical writing, communication, critical-thinking, and attention-to-detail skills.

Additional Responsibilities

  • Scope and execute authorized penetration tests across web, mobile, APIs, thick-client applications, cloud environments, and internal infrastructure.
  • Review and validate potential vulnerabilities identified through AI-assisted code reviews and automated security tooling.
  • Reproduce security findings and evaluate exploitability, business impact, severity, remediation priority, and potential false positives.
  • Perform secure source-code reviews to identify complex vulnerabilities, including business logic weaknesses.
  • Test authentication, authorization, session management, OAuth, OIDC, JWT, CSP, cryptography, and related application security controls.
  • Evaluate AI/ML systems and apply automation to improve the efficiency and depth of security testing.
  • Document vulnerabilities with clear reproduction steps, realistic attack scenarios, technical context, and actionable remediation guidance.
  • Support engineering teams through remediation and closure of identified security findings.
  • Assess systems against applicable security requirements, including PCI DSS.
  • Conduct security research and contribute to broader Offensive Security initiatives.

Subsidiary:

PayPal

Travel Percent:

0

PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes. Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal email domains. If you suspect fraudulent activity, please report it immediately. To learn more about how to identify and avoid recruitment fraud please visit https://careers.pypl.com/contact-us.

For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in-person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.

Our Benefits:

At PayPal, we’re committed to building an equitable and inclusive global economy. And we can’t do this without our most important asset-you. That’s why we offer comprehensive, choice-based programs, to support all aspects of personal wellbeing—physical, emotional, and financial—delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.

Who We Are:

Click Here to learn more about our culture and community.

Commitment to Diversity and Inclusion

PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities. If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at paypalglobaltalentacquisition@paypal.com.

Belonging at PayPal:

Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued. We are proud to have a diverse workforce reflective of the merchants, consumers, and communities that we serve, and we continue to take tangible actions to cultivate inclusivity and belonging at PayPal.

Any general requests for consideration of your skills, please Join our Talent Community.

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates. Please don’t hesitate to apply.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?

Top Benefits

  • Paid time off
  • Healthcare coverage
  • Financial security resources
  • Mental health support