Base Career helps you apply smarter for this job.
Key skills for this role
Build the end-state API security capability plane: Consolidate today's separate API security lint, gateway traffic visibility, shadow-API detection, and schema (GraphQL/AsyncAPI) security checks into a single, coherent capability that plugs into the org's shared policy-as-code enforcement architecture - the same engine already governing container, static-analysis, and software-composition findings. Design the end state first - this is not a request to bolt on another point tool.
Take the pre-release API security gate from draft architecture decision to a shipped control, working with the Staff Engineer who owns enforcement architecture to get the gateway-level hard-block policy enforced end to end. This person unblocks stalled decisions - they do not wait for consensus to form on its own.
Own the dynamic application security testing (DAST) tooling strategy end to end: complete the current tool evaluation into a production migration decision, and execute it.
Extend API security capability into two domains identified as organizational blind spots - pipeline access & execution control, and systemic artifact consumption verification - treating API security as one instance of the broader supply-chain security problem, not a silo, and enabling them through the shared enforcement architecture rather than a parallel one.
Be a force multiplier: mentor engineers across the merged team, unblock stuck initiatives, and drive delivery and innovation without waiting to be told what's next. Standard staff-engineer responsibilities and day-to-day routines apply in full - technical leadership, design review, on-call/escalation, sustaining engineering, and maintenance are shared responsibilities like any other staff engineer, not exceptions carved out for this role.
Shape the Roadmap: Work with the engineering manager and tech leads to shape and prioritize the team's backlog, identify emerging business problems before they become fire drills, and think beyond the current scope of the role rather than just executing what's already been defined.
What do you need to bring:
Software Engineering: 5+ years building production software with demonstrated staff-level ownership of a platform or system end-to-end, with hands-on coding experience in Python or Go - not just contributing features inside someone else's architecture.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Toronto, CAN
The Company PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consum
Toronto, CAN
The Company PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consum
Bengaluru, IND
Toronto, CAN
Toronto, CAN
Austin, USA
New York City, USA
San Jose, USA
San Jose, USA
Austin, USA
API Security Engineering: Deep, hands-on expertise in API architecture (REST, GraphQL, AsyncAPI), authZ/authN (OAuth2 scopes, token/session models), and API gateway or service-mesh internals (Envoy-class systems or equivalent).
AI Knowledge: Working knowledge of how AI and agentic traffic is changing the API threat model - AI-driven API abuse patterns, agent-to-API authentication, and the security implications of agentic commerce - enough to reason about it directly, not just defer to the AI security team.
Working fluency in policy-as-code approaches to security enforcement and CI/CD security gating - you can write enforcement policy, not just consume someone else's.
Practical understanding of DAST/SAST tooling internals, deep enough to evaluate and replace an underperforming tool rather than just operate whatever is already in place.
Security fundamentals across product, cloud, and vulnerability management that go a bit deeper than most - you know why a control exists, not just that it exists.
Deep knowledge of the OWASP API Security Top 10 and common API abuse patterns (broken object-level authorization, excessive data exposure, resource/rate-limit abuse), and how to design controls that close them - not just cite the list.
Hands-on experience with API traffic-protection mechanisms - rate limiting, bot/abuse mitigation, WAF/API gateway policy, and mutual TLS for service-to-service authentication.
Working knowledge of API discovery and inventory practices, deep enough to stand up shadow-API detection rather than just consume a vendor's dashboard.
Subsidiary:
Travel Percent:
PayPal does not charge candidates any fees for courses, applications, resume reviews, interviews, background checks, or onboarding. When making an application directly, we will never ask you to share passwords, one-time passcodes (OTP), or verification codes. Any such request is a red flag and likely part of a scam. All communication regarding your application will come from official PayPal email domains. If you suspect fraudulent activity, please report it immediately. To learn more about how to identify and avoid recruitment fraud please visit https://careers.pypl.com/contact-us.
For the majority of employees, PayPal's balanced hybrid work model offers 3 days in the office for effective in-person collaboration and 2 days at your choice of either the PayPal office or your home workspace, ensuring that you equally have the benefits and conveniences of both locations.
Our Benefits:
At PayPal, we’re committed to building an equitable and inclusive global economy. And we can’t do this without our most important asset-you. That’s why we offer comprehensive, choice-based programs, to support all aspects of personal wellbeing—physical, emotional, and financial—delivering meaningful value where it matters most. We strive to create a flexible, balanced work culture with a holistic approach to benefits, including generous paid time off, healthcare coverage for you and your family, and resources to create financial security and support your mental health.
Who We Are:
Click Here to learn more about our culture and community.
Commitment to Diversity and Inclusion
PayPal provides equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, pregnancy, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state, or local law. In addition, PayPal will provide reasonable accommodations for qualified individuals with disabilities. If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at paypalglobaltalentacquisition@paypal.com.
Belonging at PayPal:
Our employees are central to advancing our mission, and we strive to create an environment where everyone can do their best work with a sense of purpose and belonging. Belonging at PayPal means creating a workplace with a sense of acceptance and security where all employees feel included and valued. We are proud to have a diverse workforce reflective of the merchants, consumers, and communities that we serve, and we continue to take tangible actions to cultivate inclusivity and belonging at PayPal.
Any general requests for consideration of your skills, please Join our Talent Community.
We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates. Please don’t hesitate to apply.
PayPal is a global digital payments platform that enables individuals and businesses to send and receive money online, manage transactions, and access financial services.
Visit company websiteJobs and hiring trendsFull-time
Senior · 5+ years experience
Apply faster on company sites with our extension.