15 Sep
|
Xoom
|
Bengaluru
Job Summary
As a Staff Product Security Engineer, AI Security at PayPal, you ll help protect 439M active accounts and 8T in annual total payment volume by providing technical leadership across three areas: securing AI-assisted software development, protecting AI-enabled products and agentic systems, and applying AI to improve vulnerability detection and remediation. You ll partner with Security Architecture, engineering, product, and platform teams to translate AI security requirements into scalable controls, testing, and enforcement across PayPal s products and business units. Through hands-on technical leadership and mentorship, you ll turn emerging risks into durable capabilities and measurable risk reduction.
Essential Responsibilities
- Leverage specialized security expertise to identify and resolve complex security issues, recommending best practices and determining new approaches that have an impact on broader security operations, while aligning security strategies with business priorities
- Partner across teams and key stakeholders to drive security initiatives, leading and solutioning complex projects and programs to strengthen overall security posture.
- Apply advanced analytical skills and sound judgment to solve security challenges, considering diverse perspectives and innovative solutions. Stay current with industry trends and emerging technologies, understanding their security implications to the company s context.
- Directly contribute to improvements within the security domain and occasionally beyond, ensuring decisions lead to meaningful enhancements in security practices.
- Leverage relationships across teams, both within and outside of security, to influence initiatives and integrate feedback into security processes.
Minimum Qualifications
- 5+ years relevant experience and a Bachelor s degree OR Any equivalent combination of education and experience.
Roles and Responsibilities
- Lead the development and execution of Product Security s technical roadmap for AI security controls and assurance, partnering with Security Architecture to translate requirements into scalable engineering capabilities.
- Design, implement, and operate controls for AI-assisted software development, including security review of AI-generated code, security context and constraints for coding agents, automated testing, and risk-based enforcement.
- Conduct and lead security reviews of AI-enabled applications and their models, agents, retrieval systems, data flows, and external tool integrations.
- Create controls for agent identity, least privilege, tool access, execution isolation, human approval, and interruption of unsafe behavior.
- Design and help implement security controls for AI models, agents, toolsets, datasets, and pipelines.
- Develop runtime monitoring, auditability, detection, containment, and incident-response requirements for AI systems, including visibility into agent actions, tool calls, and sensitive-data access.
- Build and scale AI-driven capabilities for vulnerability discovery, validation, prioritization, and remediation across teams and engineering workflows.
- Partner with AI platform and cloud engineering teams to integrate security across AI infrastructure, platforms, and workloads.
- Help establish security criteria for evaluating, onboarding, integrating, and periodically reassessing third-party models, AI services, APIs, and developer tools.
- Develop methods and metrics for evaluating AI security risk, control effectiveness, remediation performance, and adoption across teams.
- Serve as a technical escalation point for complex AI security issues and lead architectural reviews following significant incidents or control failures.
- Mentor security and engineering professionals, deliver targeted technical guidance, and help teams apply AI security controls across diverse technology stacks.
Minimum Qualifications
- 5+ years of experience in software engineering, application security, product security, or cybersecurity, including leadership of complex security initiatives spanning multiple teams or technology platforms.
- Deep knowledge of application security vulnerabilities, secure software development practices, and technical controls used to identify, prevent, and remediate software risk.
- Hands-on experience securing AI systems.
- Strong software-engineering experience building and operating production security tooling, automation, platform services, or developer-facing capabilities.
- Track record of partnering with developers to implement robust security controls.
- Strong written and verbal communication skills, with the ability to influence technical and senior stakeholder audiences.
- Experience designing and operating security controls across cloud environments, CI/CD systems, and diverse application and infrastructure stacks.
- Experience mentoring and developing engineers.
Preferred Qualifications
- Hands-on familiarity with application security tools (SAST, DAST, SCA, WAF, Burp Suite).
- Solid programming experience in at least one language such as Ruby, Java, Python, JavaScript, or Swift.
- Knowledge of Kubernetes, Terraform, and version control systems such as Git.
- Hands-on experience with at least one major cloud vendor (AWS, Azure, GCP).
- Strong understanding of authentication and authorization protocols (OAuth 2.0, SAML).
What you need to know about the role
This is a hands-on individual contributor role with cross-organizational scope. You will help set technical direction, lead delivery, and mentor engineers while remaining directly involved in architecture reviews, control design, implementation, and technical problem-solving.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Staff Security Engineer, AI Security (Bengaluru)
🏢 Xoom
📍 Bengaluru