Sr Analyst, Cybersecurity Threat (Chennai)

Sr Analyst, Cybersecurity Threat (Chennai)

27 Sep
|
Xoom
|
Chennai

27 Sep

Xoom

Chennai

Job Summary

The Offensive Security team helps protect PayPal and its brands by testing products, applications, infrastructure, and emerging technologies. We work closely with engineering teams to identify security issues, explain the risk, and support effective remediation. This role combines hands-on penetration testing with vulnerability validation. You will review findings from AI assisted code reviews and other automated security tools, reproduce potential vulnerabilities, and assess their exploitability and business impact.

Meet our team The Offensive Security team works with groups across PayPal to assess the security of products and technologies throughout the product development life cycle. The team performs authorized testing across web, mobile, API, thick client, cloud, infrastructure, and other technology environments.

Essential Responsibilities

- Independently apply security best practices to enhance and optimize cyber threat management, ensuring robust protection and efficiency, while beginning to understand and align security measures with business objectives.
- Partner with peers and internal teams to drive security initiatives, contribute to cross-functional projects, and at times co-lead efforts to strengthen security posture and cyber threat management.
- Analyze and resolve security challenges by adapting standard cyber threat management processes and exploring alternative approaches to address complex threats.
- Influence the quality, efficiency, and effectiveness of the team through informed decision-making, with a potential impact on other teams.
- Collaborate with key partners to gather and incorporate feedback, driving continuous improvements in cyber threat management.

Minimum Qualifications

- 3+ years relevant experience and a Bachelor s degree OR Any equivalent combination of education and experience.

Your Way to Impact





Performs hands-on penetration testing and vulnerability validation across web, mobile, API, and cloud environments. Reviews and reproduces findings from AI-assisted code reviews and automated security tools to assess exploitability, business impact, and remediation priority. Conducts secure code reviews to identify complex, business logic vulnerabilities, and partners with engineering teams to communicate risk and drive remediation to closure. Individual-contributor role requiring end-to-end ownership of assessments, from scoping through reporting and remediation support.

In your day-to-day role you will be responsible for

- Scope and perform penetration tests from planning through reporting and remediation support.
- Perform hands-on testing of web applications, mobile applications, APIs, thick client applications, and internal infrastructure.
- Review and validate potential vulnerabilities identified through AI assisted code reviews and other automated security tools.
- Reproduce findings and assess exploitability, business impact, severity, remediation priority, and whether a finding is a false positive.
- Perform secure source code reviews and identify complex vulnerabilities, including business logic flaws.
- Test authentication, authorization, session management, OAuth, OIDC, JWT, CSP, cryptography, and other application security controls.
- Understand cloud environments, APIs, identity flows, and common attacker techniques.
- Evaluate AI and ML systems and use automation to improve the efficiency and depth of testing.




- Communicate findings with explicit context, reproduction steps, attack scenarios, and practical remediation guidance.
- Support engineering teams through remediation and closure of security findings.
- Assess systems against requirements such as PCI DSS and provide actionable remediation guidance.
- Conduct security research and contribute to other Offensive Security initiatives as needed.

What do you need to bring

- Bachelors degree or higher in Information Security, Computer Science, or a related technical discipline.
- At least five years of hands-on penetration testing experience, including the ability to manage assessments from scoping through reporting and remediation support.
- Strong experience in web application penetration testing, with hands-on experience testing mobile applications, APIs, and thick client applications.
- Experience with secure source code review and identifying complex vulnerabilities, including business logic flaws.
- Knowledge of application security, cloud environments, identity flows, and the MITRE ATT&CK; framework.
- Experience with testing approaches such as PTES and OWASP.
- Proficiency in at least one scripting language, such as Python, PowerShell, or Perl.
- Software development experience in a language such as Java or Node.js is preferred.
- Strong writing, communication, attention to detail, and critical thinking skills.
- Security certifications such as OSWE, OSCP, GPEN, GWAPT, or CEH are a plus.
- We value diverse perspectives and encourage

Subsidiary

Subsidiary: PayPal

Travel Percent

Travel Percent: 0 Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Sr Analyst, Cybersecurity Threat (Chennai)
🏢 Xoom
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sr analyst, cybersecurity threat (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: sr analyst, cybersecurity threat (chennai) / chennai