15 Sep
|
Xoom
|
Bengaluru
Job Summary
This role sits at the core of Product and AI Security engineering. This job leverages security expertise to resolve complex security issues, partners with teams to drive security initiatives, applies analytical skills to solve security challenges, contributes to security improvements, and influences security processes.
Essential Responsibilities
- Leverage specialized security expertise to identify and resolve complex security issues, recommending best practices and determining new approaches that have an impact on broader security operations, while aligning security strategies with business priorities
- Partner across teams and key stakeholders to drive security initiatives, leading and solutioning complex projects and programs to strengthen overall security posture.
- Apply advanced analytical skills and sound judgment to solve security challenges, considering diverse perspectives and innovative solutions. Stay current with industry trends and emerging technologies, understanding their security implications to the company s context.
- Directly contribute to improvements within the security domain and occasionally beyond, ensuring decisions lead to meaningful enhancements in security practices.
- Leverage relationships across teams, both within and outside of security, to influence initiatives and integrate feedback into security processes.
Minimum Qualifications
- 5+ years relevant experience and a Bachelor s degree OR Any equivalent combination of education and experience.
In your day-to-day role you will be responsible for:
- Build the end-state API security capability plane: Consolidate todays separate API security lint, gateway traffic visibility, shadow-API detection, and schema (GraphQL/AsyncAPI) security checks into a single, coherent capability that plugs into the orgs shared policy-as-code enforcement architecture - the same engine already governing container, static-analysis, and software-composition findings. Design the end state first - this is not a request to bolt on another point tool.
- Take the pre-release API security gate from draft architecture decision to a shipped control,
working with the Staff Engineer who owns enforcement architecture to get the gateway-level hard-block policy enforced end to end. This person unblocks stalled decisions - they do not wait for consensus to form on its own.
- Own the energetic application security testing (DAST) tooling strategy end to end: complete the current tool evaluation into a production migration decision, and execute it.
- Extend API security capability into two domains identified as organizational blind spots - pipeline access execution control, and systemic artifact consumption verification - treating API security as one instance of the broader supply-chain security problem, not a silo, and enabling them through the shared enforcement architecture rather than a parallel one.
- Be a force multiplier: mentor engineers across the merged team, unblock stuck initiatives, and drive delivery and innovation without waiting to be told whats next. Standard staff-engineer responsibilities and day-to-day routines apply in full - technical leadership, design review, on-call/escalation, sustaining engineering, and maintenance are shared responsibilities like any other staff engineer, not exceptions carved out for this role.
- Shape the Roadmap: Work with the engineering manager and tech leads to shape and prioritize the teams backlog, identify emerging business problems before they become fire drills, and think beyond the current scope of the role rather than just executing whats already been defined.
What do you need to bring:
- Software Engineering: 5+ years building production software with demonstrated staff-level ownership of a platform or system end-to-end, with hands-on coding experience in Python or Go - not just contributing features inside someone elses architecture.
- API Security Engineering: Deep, hands-on expertise in API architecture (REST, GraphQL, AsyncAPI), authZ/authN (OAuth2 scopes,
token/session models), and API gateway or service-mesh internals (Envoy-class systems or equivalent).
- AI Knowledge: Working knowledge of how AI and agentic traffic is changing the API threat model - AI-driven API abuse patterns, agent-to-API authentication, and the security implications of agentic commerce - enough to reason about it directly, not just defer to the AI security team.
- Working fluency in policy-as-code approaches to security enforcement and CI/CD security gating - you can write enforcement policy, not just consume someone elses.
- Practical understanding of DAST/SAST tooling internals, deep enough to evaluate and replace an underperforming tool rather than just operate whatever is already in place.
- Security fundamentals across product, cloud, and vulnerability management that go a bit deeper than most - you know why a control exists, not just that it exists.
- Deep knowledge of the OWASP API Security Top 10 and common API abuse patterns (broken object-level authorization, excessive data exposure, resource/rate-limit abuse), and how to design controls that close them - not just cite the list.
- Hands-on experience with API traffic-protection mechanisms - rate limiting, bot/abuse mitigation, WAF/API gateway policy, and mutual TLS for service-to-service authentication.
- Working knowledge of API discovery and inventory practices, deep enough to stand up shadow-API detection rather than just consume a vendors dashboard.
Subsidiary:
PayPal
Travel Percent:
0 PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes. Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Staff Security Engineer, API Security (Bengaluru)
🏢 Xoom
📍 Bengaluru