Sr Application Security Engineer
PayPal Holdings, Inc.ShanghaiUpdate time: April 8,2020
Job Description

Fueled by a fundamental belief that having access to financial services creates opportunity, PayPal (NASDAQ: PYPL) is committed to democratizing financial services and empowering people and businesses to join and thrive in the global economy. Our open digital payments platform gives PayPal’s 305 million active account holders the confidence to connect and transact in new and powerful ways, whether they are online, on a mobile device, in an app, or in person. Through a combination of technological innovation and strategic partnerships, PayPal creates better ways to manage and move money, and offers choice and flexibility when sending payments, paying or getting paid. Available in more than 200 markets around the world, the PayPal platform, including Braintree, Venmo and Xoom enables consumers and merchants to receive money in more than 100 currencies, withdraw funds in 56 currencies and hold balances in their PayPal accounts in 25 currencies.

Specific Responsibilities

  • Recommend, evaluate and enforce security vulnerability scanning application findings including static, binary and related security frameworks etc.

  • Research, investigate and perform risk analysis of new findings surfaced by various application security tools and services.

  • Supports and implements Web Application Firewall (WAF) rulesets.

  • Perform code reviews and perform analysis using application security toolsets.

  • Educates developers on application security best practices.

  • Support software developers in triaging and remediating security issues.

  • Code optimization, tuning and filtering to remove false positives and increase visibility.

  • Evangelize security tooling throughout the organization.

  • Be an influencer of change while maintaining a strong relationship with the development organization.

Required Skills

  • Ability to proficiently code in Java, Python and NodeJS.

  • Ability to understand various application code base regardless of the programming language.

  • Ability to describe security best practices to software development teams.

  • Ability understand complex software architectures and their deployment models.

  • Ability to understand security issues identified by security scans regardless of application programing language.

Ability to research, analyze, and understand known and new CVEs

Experience Requirements

  • 5+ years of experience as a Security Engineer with active design & development experience in languages such as Java, Python and NodeJS and in performing software-based risk assessments.

  • Experience with enterprise rollout of Static Analysis Security Testing (SAST) tools such as Fortify or other similar tools is an added advantage.

  • Experience working in collaboration with software engineering organizations to improve security posture.

  • Experience with Web Application Firewall technologies such as Imperva or F5.

  • Experience in financial services and security technology industries.

  • BS in Computer Science or Equivalent.

We're a purpose-driven company whose beliefs are the foundation for how we conduct business every day. We hold ourselves to our One Team Behaviors which demand that we hold the highest ethical standards, to empower an open and diverse workplace, and strive to treat everyone who is touched by our business with dignity and respect. Our employees challenge the status quo, ask questions, and find solutions. We want to break down barriers to financial empowerment. Join us as we change the way the world defines financial freedom.PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities. If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at paypalglobaltalentacquisition@paypal.com.

Get email alerts for the latest"Sr Application Security Engineer jobs in Shanghai"