Sr Cybersecurity Engineer

PayPal PayPal · Fintech · Austin, TX +1 · Cybersecurity Engineering

This role focuses on cybersecurity engineering within the fintech domain, specifically addressing application security vulnerabilities and managing vulnerability platforms. It involves analyzing security challenges, determining the impact of vulnerabilities, and collaborating with engineering teams to improve security posture. The role requires experience with various programming languages and vulnerability scanning tools, as well as knowledge of financial services security standards.

What you'd actually do

  1. Analyze and resolve security challenges by adapting standard processes and exploring alternative approaches to address complex threats.
  2. Establish operational workflow around application security vulnerabilities.
  3. Determine the impact of vulnerabilities in the environment and communicate them to stakeholders across the company.
  4. Implement and configure vulnerability management platforms/application security posture management platforms.
  5. Locate patterns in the data that point to root causes that unlock mitigation opportunities.

Skills

Required

  • Ruby, Java, Python, JavaScript, or Swift
  • Actioning results of vulnerability scanning tools, such as: SAST, API security scanners, and software composition analysis, including driving vulnerability management lifecycle for these scan results including communication with software developers, remediation engineering and reporting to leadership.
  • Experience working in a large enterprise environment
  • Experience in identifying and remediating common application security vulnerabilities such as OWASP Top 10 and deep understanding of web application and mobile app vulnerabilities
  • Financial services regulations and security standards, such as PCI-DSS and ISO27001

What the JD emphasized

  • Actioning results of vulnerability scanning tools, such as: SAST, API security scanners, and software composition analysis, including driving vulnerability management lifecycle for these scan results including communication with software developers, remediation engineering and reporting to leadership.
  • Experience in identifying and remediating common application security vulnerabilities such as OWASP Top 10 and deep understanding of web application and mobile app vulnerabilities
  • Financial services regulations and security standards, such as PCI-DSS and ISO27001