Job Summary:As a Senior Product Security Engineer at PayPal, you'll help secure 439M accounts and $1.8T in annual payment volume by designing, building, and operating automated security scanners and developer guardrails across the software development lifecycle. Partnering with engineering, platform, and security teams, you'll identify and reduce risk across source code, open source dependencies, secrets, software supply chains, AI/LLM tools, and other developer workflows.
Our team's mission is to make secure development the easiest path for engineers, building scanners and guardrails that catch risk before software reaches production - spanning source code, dependencies, supply chains, AI/LLM tools, edge/CDN environments, and developer workflows. You'll turn security requirements into reliable automation that meets engineers where they build and deploy, improving detection quality and remediation ease while supporting delivery speed, with impact reaching adjacent teams.
Job Description:Essential Responsibilities: - Independently apply security best practices to enhance and optimize systems, ensuring robust protection and efficiency, while beginning to understand and align security solutions with business objectives.
- Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture.
- Analyze and resolve security challenges by adapting standard processes and exploring alternative approaches to address complex threats.
- Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
- Collaborate with other engineers to gather and incorporate feedback, driving continuous improvements in security processes.
Minimum Qualifications:- 3+ years relevant experience and a Bachelor's degree OR Any equivalent combination of education and experience.
Additional Responsibilities & Preferred Qualifications:- Experience with SLSA, software bills of materials (SBOMs), provenance, artifact signing or verification, package repositories, or dependency governance.
- Experience creating or tuning rules for static analysis, secrets detection, or policy-as-code systems.
- Familiarity with security considerations for AI/LLM development tools, AI-assisted coding, or model and tool supply chains.
- Experience with GCP, complemented by hands-on expertise with Kubernetes, Terraform, and other cloud-native technologies.
- Familiarity in other programming and scripting languages, such as Java and Javascript, with the ability to troubleshoot code
- Experience using telemetry and metrics to improve security tooling at scale, including coverage, quality, performance, adoption, or remediation outcomes.
- 3-5 minimum years of relevant experience in software engineering, application or product security, DevSecOps, or cybersecurity, and a Bachelor's degree or an equivalent combination of education and experience.
- Experience developing, integrating, or operating security automation in CI/CD or developer workflows, including one or more of SAST, SCA, secrets detection, or software supply chain security.
- Programming or scripting experience in multiple languages such as Python, Go, and Bash, with the ability to write, review, and troubleshoot code.
- Working knowledge of secure software development, common application vulnerabilities, dependency and package ecosystem risks, and practical remediation approaches.
- Ability to work independently and collaborate with software, platform, and security teams, with clear written and verbal communication of technical findings and tradeoffs.
Additional Responsibilities
- Build and operate scanning and guardrail capabilities across source control, CI/CD, package ecosystems, and developer platforms.
- Tune SAST, SCA, and supply chain controls; investigate gaps and false positives and improve remediation guidance.
- Write and review code, APIs, detection rules, and automation that process findings and enforce security policy.
- Partner with developers, platform engineers, and security teams to troubleshoot integrations and deliver practical improvements.
- Evaluate new technical surfaces, including AI/LLM tools, and help define appropriate security controls.
- Use metrics and feedback to improve reliability, coverage, performance, adoption, and remediation outcomes.
Subsidiary:PayPal
Travel Percent:0
The base pay for this role will depend on where you work and the relevant experience and expertise you bring. The expected range of pay for this role by location is:
Primary Location | Pay Range:Austin, Texas: ($130,500.00 - $193,600.00 Annually)
Additional Location(s) | Pay Range:Chicago, Illinois: ($130,500.00 - $193,600.00 Annually)
Additional compensation for this role may include an annual performance bonus, equity, or other incentive compensation, as applicable.
For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in-person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.
Our Benefits:At PayPal, we're committed to building an equitable and inclusive global economy. And we can't do this without our most important asset-you. That's why we offer comprehensive, choice-based programs, to support all aspects of personal wellbeing-physical, emotional, and financial-delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.