Staff Security Engineer, API Security

PayPal

Bengaluru

Hybrid

INR 4,000,000 - 6,000,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Paid time off
Healthcare for you and family
Mental health resources

Job summary

PayPal is seeking a Staff Engineer for API Security to own and advance our security platform in Bengaluru. You will lead end-to-end security design, align with business priorities, and mentor engineers across teams. Strong hands-on skills in Python or Go, and deep API security expertise are required.

You will drive strategic initiatives for DAST/SAST, API gateway policies, and shadow-API detection while collaborating with stakeholders to raise security postures company-wide.

Qualifications

  • 5+ years of production software experience with platform ownership.
  • Strong background in API security architecture and threat modeling.
  • Experience with REST/GraphQL/AsyncAPI and policy-as-code enforcement.

Responsibilities

  • Build the end-state API security capability plane and integrate with existing enforcement architecture.
  • Lead the pre-release API security gate from draft to shipped control.
  • Own the DAST tooling strategy and production migration decisions.
  • Extend security capabilities to pipeline access, execution control, and artifact verification.

Skills

Python
Go
API Security
OAuth2
Envoy
GraphQL
AsyncAPI
DAST/SAST

Education

Bachelor’s degree or equivalent

Tools

Envoy

Job description

The Company

PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy. We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third‑party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers. We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards. Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end‑to‑end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross‑border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross‑border trade.


Our beliefs are the foundation for how we conduct business every day. We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.


Job Summary

This role sits at the core of Product and AI Security engineering. This job leverages security expertise to resolve complex security issues, partners with teams to drive security initiatives, applies analytical skills to solve security challenges, contributes to security improvements, and influences security processes.


Job Description

Essential Responsibilities


  • Leverage specialized security expertise to identify and resolve complex security issues, recommending best practices and determining new approaches that have an impact on broader security operations, while aligning security strategies with business priorities

  • Partner across teams and key stakeholders to drive security initiatives, leading and solutioning complex projects and programs to strengthen overall security posture.

  • Apply advanced analytical skills and sound judgment to solve security challenges, considering diverse perspectives and innovative solutions. Stay current with industry trends and emerging technologies, understanding their security implications to the company’s context.

  • Directly contribute to improvements within the security domain and occasionally beyond, ensuring decisions lead to meaningful enhancements in security practices.

  • Leverage relationships across teams, both within and outside of security, to influence initiatives and integrate feedback into security processes.


Minimum Qualifications


  • 5+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.


Additional Responsibilities & Preferred Qualifications

In your day-to-day role you will be responsible for


  • Build the end-state API security capability plane: Consolidate today's separate API security lint, gateway traffic visibility, shadow-API detection, and schema (GraphQL/AsyncAPI) security checks into a single, coherent capability that plugs into the org's shared policy-as-code enforcement architecture - the same engine already governing container, static-analysis, and software-composition findings. Design the end state first - this is not a request to bolt on another point tool.

  • Take the pre-release API security gate from draft architecture decision to a shipped control, working with the Staff Engineer who owns enforcement architecture to get the gateway-level hard-block policy enforced end to end. This person unblocks stalled decisions - they do not wait for consensus to form on its own.

  • Own the dynamic application security testing (DAST) tooling strategy end to end: complete the current tool evaluation into a production migration decision, and execute it.

  • Extend API security capability into two domains identified as organizational blind spots - pipeline access & execution control, and systemic artifact consumption verification - treating API security as one instance of the broader supply‑chain security problem, not a silo, and enabling them through the shared enforcement architecture rather than a parallel one.

  • Be a force multiplier: mentor engineers across the merged team, unblock stuck initiatives, and drive delivery and innovation without waiting to be told what's next. Standard staff‑engineer responsibilities and day‑to‑day routines apply in full - technical leadership, design review, on‑call/escalation, sustaining engineering, and maintenance are shared responsibilities like any other staff engineer, not exceptions carved out for this role.

  • Shape the Roadmap: Work with the engineering manager and tech leads to shape and prioritize the team's backlog, identify emerging business problems before they become fire drills, and think beyond the current scope of the role rather than just executing what's already been defined.


What do you need to bring


  • Software Engineering: 5+ years building production software with demonstrated staff-level ownership of a platform or system end-to-end, with hands‑on coding experience in Python or Go - not just contributing features inside someone else’s architecture.

  • API Security Engineering: Deep, hands‑on expertise in API architecture (REST, GraphQL, AsyncAPI), authZ/authN (OAuth2 scopes, token/session models), and API gateway or service‑mesh internals (Envoy‑class systems or equivalent).

  • AI Knowledge: Working knowledge of how AI and agentic traffic is changing the API threat model - AI-driven API abuse patterns, agent-to-API authentication, and the security implications of agentic commerce - enough to reason about it directly, not just defer to the AI security team.

  • Working fluency in policy-as-code approaches to security enforcement and CI/CD security gating - you can write enforcement policy, not just consume someone else’s.

  • Practical understanding of DAST/SAST tooling internals, deep enough to evaluate and replace an underperforming tool rather than just operate whatever is already in place.

  • Security fundamentals across product, cloud, and vulnerability management that go a bit deeper than most - you know why a control exists, not just that it exists.

  • Deep knowledge of the OWASP API Security Top 10 and common API abuse patterns (broken object-level authorization, excessive data exposure, resource/rate-limit abuse), and how to design controls that close them - not just cite the list.

  • Hands‑on experience with API traffic‑protection mechanisms - rate limiting, bot/abuse mitigation, WAF/API gateway policy, and mutual TLS for service-to-service authentication.

  • Working knowledge of API discovery and inventory practices, deep enough to stand up shadow‑API detection rather than just consume a vendor's dashboard.


Subsidiary

PayPal


Travel Percent

0


For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in‑person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.


Our Benefits


  • generous paid time off

  • healthcare coverage for you and your family

  • resources to create financial security and support your mental health


Commitment to Diversity and Inclusion

PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities. If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at paypalglobaltalentacquisition@paypal.com.


Belonging at PayPal

Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued. We are proud to have a diverse workforce reflective of the merchants, consumers, and communities that we serve, and we continue to take tangible actions to cultivate inclusivity and belonging at PayPal.


Click Here to learn more about our culture and community.


Any general requests for consideration of your skills, please Join our Talent Community.


We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer, AI Security
Staff Security Engineer, AI Security

PayPal • Bengaluru

On-site
INR 3,000,000 - 5,400,000
Hybrid work model
Flexible work arrangements
Senior Full Stack Software Engineer
Senior Full Stack Software Engineer

Paypal India Pvt Ltd • Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Sr Site Reliability Engineer
Sr Site Reliability Engineer

PayPal • Chennai District

Hybrid
INR 3,000,000 - 6,000,000
Hybrid work model
Healthcare coverage
Accountant Accounts Payable
Accountant Accounts Payable

PayPal • Bengaluru

Hybrid
INR 1,200,000 - 2,000,000
Hybrid work model
Healthcare coverage
Paid time off
Senior Software Engineer - Python
Senior Software Engineer - Python

SupportFinity™ • Bengaluru

Hybrid
INR 4,000,000 - 6,000,000
Flexible work environment
Employee stock options
Health and life insurance
Sr Accountant - Intercompany And Daily Close
Sr Accountant - Intercompany And Daily Close

PayPal • Bengaluru

Hybrid
INR 800,000 - 1,400,000
Hybrid work model
Healthcare coverage for you and your a
Accounts Payable Analyst
Accounts Payable Analyst

Paypal India Pvt Ltd • Bengaluru

Hybrid
INR 1,800,000 - 2,800,000
Healthcare coverage for you and your >
Paid time off
Hybrid work model
CIP investigator
CIP investigator

PayPal • Mumbai

Hybrid
INR 900,000 - 1,600,000
Software Engineer Jobs at PayPal | Hybrid Work - Stifons
Software Engineer Jobs at PayPal | Hybrid Work - Stifons

Stifons Limited • Chennai District

Hybrid
INR 1,500,000 - 3,000,000
Payroll Accountant
Payroll Accountant

PayPal • Bengaluru

On-site
INR 2,500,000 - 4,000,000