Staff Security Engineer, API Security

Posted Yesterday
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Fintech • Payments
The Role
Leads API security engineering across architecture, enforcement, DAST strategy, supply-chain security, and threat mitigation. The role consolidates API security capabilities into a shared policy-as-code platform, ships gateway-level security controls, evaluates and migrates DAST tooling, addresses pipeline and artifact risks, and shapes the roadmap. Responsibilities include technical leadership, coding, design reviews, mentoring, on-call support, and collaboration across engineering and security teams.
Summary Generated by Built In

The Company

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy. 

We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.

We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards.  Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade. 

Our beliefs are the foundation for how we conduct business every day.  We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.

Job Summary:

This role sits at the core of Product and AI Security engineering. This job leverages security expertise to resolve complex security issues, partners with teams to drive security initiatives, applies analytical skills to solve security challenges, contributes to security improvements, and influences security processes.

Job Description:

Essential Responsibilities:

  • Leverage specialized security expertise to identify and resolve complex security issues, recommending best practices and determining new approaches that have an impact on broader security operations, while aligning security strategies with business priorities
  • Partner across teams and key stakeholders to drive security initiatives, leading and solutioning complex projects and programs to strengthen overall security posture.
  • Apply advanced analytical skills and sound judgment to solve security challenges, considering diverse perspectives and innovative solutions. Stay current with industry trends and emerging technologies, understanding their security implications to the company’s context.
  • Directly contribute to improvements within the security domain and occasionally beyond, ensuring decisions lead to meaningful enhancements in security practices.
  • Leverage relationships across teams, both within and outside of security, to influence initiatives and integrate feedback into security processes.

Minimum Qualifications:

  • 5+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.

Additional Responsibilities & Preferred Qualifications:

In your day-to-day role you will be responsible for:
  • Build the end-state API security capability plane: Consolidate today's separate API security lint, gateway traffic visibility, shadow-API detection, and schema (GraphQL/AsyncAPI) security checks into a single, coherent capability that plugs into the org's shared policy-as-code enforcement architecture - the same engine already governing container, static-analysis, and software-composition findings. Design the end state first - this is not a request to bolt on another point tool.
  • Take the pre-release API security gate from draft architecture decision to a shipped control, working with the Staff Engineer who owns enforcement architecture to get the gateway-level hard-block policy enforced end to end. This person unblocks stalled decisions - they do not wait for consensus to form on its own.
  • Own the dynamic application security testing (DAST) tooling strategy end to end: complete the current tool evaluation into a production migration decision, and execute it.
  • Extend API security capability into two domains identified as organizational blind spots - pipeline access & execution control, and systemic artifact consumption verification - treating API security as one instance of the broader supply-chain security problem, not a silo, and enabling them through the shared enforcement architecture rather than a parallel one.
  • Be a force multiplier: mentor engineers across the merged team, unblock stuck initiatives, and drive delivery and innovation without waiting to be told what's next. Standard staff-engineer responsibilities and day-to-day routines apply in full - technical leadership, design review, on-call/escalation, sustaining engineering, and maintenance are shared responsibilities like any other staff engineer, not exceptions carved out for this role.
  • Shape the Roadmap: Work with the engineering manager and tech leads to shape and prioritize the team's backlog, identify emerging business problems before they become fire drills, and think beyond the current scope of the role rather than just executing what's already been defined.

What do you need to bring:

  • Software Engineering: 5+ years building production software with demonstrated staff-level ownership of a platform or system end-to-end, with hands-on coding experience in Python or Go - not just contributing features inside someone else's architecture.
  • API Security Engineering: Deep, hands-on expertise in API architecture (REST, GraphQL, AsyncAPI), authZ/authN (OAuth2 scopes, token/session models), and API gateway or service-mesh internals (Envoy-class systems or equivalent).
  • AI Knowledge: Working knowledge of how AI and agentic traffic is changing the API threat model - AI-driven API abuse patterns, agent-to-API authentication, and the security implications of agentic commerce - enough to reason about it directly, not just defer to the AI security team.
  • Working fluency in policy-as-code approaches to security enforcement and CI/CD security gating - you can write enforcement policy, not just consume someone else's.
  • Practical understanding of DAST/SAST tooling internals, deep enough to evaluate and replace an underperforming tool rather than just operate whatever is already in place.
  • Security fundamentals across product, cloud, and vulnerability management that go a bit deeper than most - you know why a control exists, not just that it exists.
  • Deep knowledge of the OWASP API Security Top 10 and common API abuse patterns (broken object-level authorization, excessive data exposure, resource/rate-limit abuse), and how to design controls that close them - not just cite the list.
  • Hands-on experience with API traffic-protection mechanisms - rate limiting, bot/abuse mitigation, WAF/API gateway policy, and mutual TLS for service-to-service authentication.
  • Working knowledge of API discovery and inventory practices, deep enough to stand up shadow-API detection rather than just consume a vendor's dashboard.

Subsidiary:

PayPal

Travel Percent:

0

PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes.  Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal email domains. If you suspect fraudulent activity, please report it immediately.  To learn more about how to identify and avoid recruitment fraud please visit https://careers.pypl.com/contact-us

For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in-person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.

Our Benefits:

At PayPal, we’re committed to building an equitable and inclusive global economy. And we can’t do this without our most important asset-you. That’s why we offer comprehensive, choice-based programs, to support all aspects of personal wellbeing—physical, emotional, and financial—delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.

Who We Are:

Click Here to learn more about our culture and community.

Commitment to Diversity and Inclusion 

PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law.  In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities.  If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at [email protected].  

Belonging at PayPal: 

Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued. We are proud to have a diverse workforce reflective of the merchants, consumers, and communities that we serve, and we continue to take tangible actions to cultivate inclusivity and belonging at PayPal.

Any general requests for consideration of your skills, please Join our Talent Community.

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates. Please don’t hesitate to apply.

Skills Required

  • 5+ years of relevant experience and a bachelor's degree, or an equivalent combination of education and experience
  • 5+ years building production software with staff-level ownership of a platform or system end to end
  • Hands-on coding experience in Python or Go
  • Deep hands-on expertise in REST, GraphQL, and AsyncAPI architecture
  • Experience with OAuth2 scopes, authentication and authorization, token and session models
  • Experience with API gateways or service-mesh internals, including Envoy-class systems or equivalent
  • Working knowledge of AI-driven API abuse, agent-to-API authentication, and agentic commerce security implications
  • Fluency in policy-as-code security enforcement and CI/CD security gating
  • Practical understanding of DAST and SAST tooling internals
  • Security fundamentals across product, cloud, and vulnerability management
  • Deep knowledge of the OWASP API Security Top 10 and common API abuse patterns
  • Hands-on experience with rate limiting, bot and abuse mitigation, WAF or API gateway policies, and mutual TLS
  • Working knowledge of API discovery, inventory, and shadow-API detection

PayPal Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about PayPal and has not been reviewed or approved by PayPal.

  • Healthcare Strength Health coverage starts on the date of hire with medical, dental, vision, wellness resources, and health-navigation support. Eligibility includes spouses/domestic partners and dependents up to age 26, indicating broad and robust coverage.
  • Leave & Time Off Breadth Flexible time-off frameworks and a market-leading sabbatical after five years provide substantial time-away options. Paid leaves span bonding/parental, disability, and localized programs, offering broad coverage across situations.
  • Retirement Support A 401(k) with company match and a year-end true-up strengthens long-term savings. Financial-wellbeing tools and related programs further support retirement planning.

PayPal Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
34,450 Employees
Year Founded: 1998

What We Do

HELP US REIMAGINE MONEY. At PayPal, we believe that now is the time to democratize financial services so that moving and managing money is a right for all citizens, not just the affluent. We are driven by this purpose, and we uphold our cultural values of collaboration, innovation, wellness and inclusion as our guide for making decisions and conducting business every day. It is our duty and privilege to be customer champions and put those we serve at the center of everything we do. We are one team that respects and values diversity of thought for everyone, everywhere, and we actively seek to create an energizing workplace that brings out the best in all of us. If you’re ready to shape the future of money, join the team at PayPal. We're proud to work here. You will be too. PayPal is headquartered in San Jose, California and its international headquarters is located in Singapore.

Similar Jobs

TransUnion Logo TransUnion

Manager - Escalations

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
World Trade Center, Yeshwanthpur, Bengaluru Urban, Karnataka, IND
13000 Employees

The Aerospace Corporation Logo The Aerospace Corporation

Principal Systems Engr

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4600 Employees

Expedia Group Logo Expedia Group

Senior Manager, Software Development Engineering

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
16000 Employees

Expedia Group Logo Expedia Group

Data Science III - Pricing Analytics

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Bangalore, Bengaluru Urban, Karnataka, IND
16000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account