Sr Analyst, Cybersecurity Threat

Senior
CompanyPayPal
LocationChennai, Tamil Nadu, India
Category-
SenioritySenior
Workplace-
Posted2026-09-23
Viaworkday

Description

The Company

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy.

We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.

We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards.  Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade.

Our beliefs are the foundation for how we conduct business every day.  We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.

Job Summary

What you need to know about the role

The Offensive Security team helps protect PayPal and its brands by testing products, applications, infrastructure, and emerging technologies. We work closely with engineering teams to identify security issues, explain the risk, and support effective remediation.
This role combines hands-on penetration testing with vulnerability validation. You will review findings from AI assisted code reviews and other automated security tools, reproduce potential vulnerabilities, and assess their exploitability and business impact.

Meet our team

The Offensive Security team works with groups across PayPal to assess the security of products and technologies throughout the product development life cycle. The team performs authorized testing across web, mobile, API, thick client, cloud, infrastructure, and other technology environments

Job Description

Essential Responsibilities

  • Independently apply security best practices to enhance and optimize cyber threat management, ensuring robust protection and efficiency, while beginning to understand and align security measures with business objectives.
  • Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture and cyber threat management.
  • Analyze and resolve security challenges by adapting standard cyber threat management processes and exploring alternative approaches to address complex threats.
  • Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
  • Collaborate with key partners to gather and incorporate feedback, driving continuous improvements in cyber threat management.

Minimum Qualifications

  • 3+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.

Additional Responsibilities & Preferred Qualifications

Your way to impact

Performs hands-on penetration testing and vulnerability validation across web, mobile, API, and cloud environments. Reviews and reproduces findings from AI-assisted code reviews and automated security tools to assess exploitability, business impact, and remediation priority. Conducts secure code reviews to identify complex, business logic vulnerabilities, and partners with engineering teams to communicate risk and drive remediation to closure. Individual-contributor role requiring end-to-end ownership of assessments, from scoping through reporting and remediation support.

In your day-to-day role you will be responsible for

  • Scope and perform penetration tests from planning through reporting and remediation support.
  • Perform hands-on testing of web applications, mobile applications, APIs, thick client applications, and internal infrastructure.
  • Review and validate potential vulnerabilities identified through AI assisted code reviews and other automated security tools.
  • Reproduce findings and assess exploitability, business impact, severity, remediation priority, and whether a finding is a false positive.
  • Perform secure source code reviews and identify complex vulnerabilities, including business logic flaws.
  • Test authentication, authorization, session management, OAuth, OIDC, JWT, CSP, cryptography, and other application security controls.
  • Understand cloud environments, APIs, identity flows, and common attacker techniques.
  • Evaluate AI and ML systems and use automation to improve the efficiency and depth of testing.
  • Communicate findings with clear context, reproduction steps, attack scenarios, and practical remediation guidance.
  • Support engineering teams through remediation and closure of security findings.
  • Assess systems against requirements such as PCI DSS and provide actionable remediation guidance.
  • Conduct security research and contribute to other Offensive Security initiatives as needed.

What do you need to bring

  • Bachelor's degree or higher in Information Security, Computer Science, or a related technical discipline.
  • At least five years of hands-on penetration testing experience, including the ability to manage assessments from scoping through reporting and remediation support.
  • Strong experience in web application penetration testing, with hands-on experience testing mobile applications, APIs, and thick client applications.
  • Experience with secure source code review and identifying complex vulnerabilities, including business logic flaws.
  • Knowledge of application security, cloud environments, identity flows, and the MITRE ATT&CK framework.
  • Experience with testing approaches such as PTES and OWASP.
  • Proficiency in at least one scripting language, such as Python, PowerShell, or Perl.
  • Software development experience in a language such as Java or Node.js is preferred.
  • Strong writing, communication, attention to detail, and critical thinking skills.
  • Security certifications such as OSWE, OSCP, GPEN, GWAPT, or CEH are a plus.
  • We value diverse perspectives and encourage

Subsidiary

PayPal

Travel Percent

0

PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes.  Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal email domains. If you suspect fraudulent activity, please report it immediately.  To learn more about how to identify and avoid recruitment fraud please visit https://careers.pypl.com/contact-us .

For the majority of empl