The role
From PayPal's own posting.
The Company
PayPal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, PayPal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy.
We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers. We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. PayPal is more than a connection to third-party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers.
We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds. We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a PayPal or Venmo account balance, PayPal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards. Our PayPal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other. We offer merchants an end-to-end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross-border trade.
Our beliefs are the foundation for how we conduct business every day. We live each day guided by our core values of Inclusion, Innovation, Collaboration, and Wellness. Together, our values ensure that we work together as one global team with our customers at the center of everything we do – and they push us to ensure we take care of ourselves, each other, and our communities.
Job Summary:
As a Senior Staff Product Security Engineer, AI Security at PayPal, you'll help protect 439M active accounts and $1.8T in annual payment volume by leading Product Security engineering across three areas: securing AI-assisted software development, protecting AI-enabled products and agentic systems, and applying AI to improve vulnerability detection and remediation. You'll partner with Security Architecture, engineering, product, and platform teams to translate AI security requirements into scalable controls, testing, and enforcement across PayPal's products and business units. Through hands-on technical leadership and mentorship, you'll turn emerging risks into durable capabilities and measurable risk reduction — reducing the likelihood that AI-assisted development introduces exploitable vulnerabilities or that AI-enabled systems misuse sensitive data, tools, or business actions, while improving PayPal's ability to detect, validate, and remediate vulnerabilities at scale.
Job Description:
Essential Responsibilities:
Recognized as a security expert, independently resolving the most complex security challenges and providing strategic direction on problem resolution across the security domain.
Define methods and procedures for new or special assignments, collaborating with cross-functional teams to drive security initiatives that align with business needs and objectives.
Lead complex, high-impact security projects of diverse scope, applying an in-depth understanding of business trends and security challenges to develop innovative solutions.
Possess a keen awareness of the broader impact of decisions, with initiatives often leading to enterprise-wide improvements that enhance security practices and operational efficiency.
Minimum Qualifications:
8+ years relevant experience and a Bachelor’s degree OR Any equivalent combination of education and experience.
Additional Responsibilities & Preferred Qualifications :
Hands-on familiarity with application security tools (SAST, DAST, SCA, WAF, Burp Suite)
Strong programming experience in at least one language (Ruby, Java, Python, JavaScript, or Swift)
Knowledge of Kubernetes, Terraform, and version control systems such as Git
Hands-on experience with at least one major cloud vendor (AWS, Azure, GCP)
Strong understanding of authentication and authorization protocols (OAuth 2.0, SAML)
Deep knowledge of application security vulnerabilities, secure software development practices, and technical controls to identify, prevent, and remediate software risk
Hands-on experience securing AI systems
Strong software-engineering experience building and operating production security tooling, automation, platform services, or developer-facing capabilities
Track record of partnering with developers to implement robust security controls
Strong written and verbal communication skills, with the ability to influence technical and executive audiences
Experience designing and operating security controls across cloud environments, CI/CD systems, and diverse application and infrastructure stacks
Experience mentoring and developing engineers
Additional Responsibilities
Define Product Security's technical strategy and roadmap for AI security controls and assurance, partnering with Security Architecture to translate requirements into scalable engineering capabilities
Design, implement, and operate controls for AI-assisted software development, including security review of AI-generated code, security context and constraints for coding agents, automated testing, and risk-based enforcement
Lead security reviews of AI-enabled applications and their models, agents, retrieval systems, data flows, and external tool integrations
Create controls for agent identity, least privilege, tool access, execution isolation, human approval, and interruption of unsafe behavior
Establish security controls for AI models, agents, toolsets, datasets, and pipelines
Define runtime monitoring, auditability, detection, containment, and incident-response requirements for AI systems, including visibility into agent actions, tool calls, and sensitive-data access
Build and scale AI-driven capabilities for vulnerability discovery, validation, prioritization, and remediation
Partner with AI platform and cloud engineering teams to integrate security across AI infrastructure, platforms, and workloads
Establish security criteria for evaluating, onboarding, integrating, and periodically reassessing third-party models, AI services, APIs, and developer tools
Define methods and metrics for evaluating AI security risk, control effectiveness, remediation performance, and program adoption across PayPal
Serve as a senior technical escalation point for complex AI security issues and lead architectural reviews following significant incidents or control failures
Your Day-to-Day
Reviewing an AI architecture, threat model, or agent workflow and identifying material security risks.
Designing, prototyping, or integrating an AI security control into a product, shared platform, or engineering workflow.
Evaluating results from AI security scanners, adversarial tests, and runtime monitoring to determine required engineering action.
Partnering with developers and platform teams to resolve complex design or implementation issues.
Analyzing control coverage, effectiveness, adoption, and incident findings to determine program priorities.
Mentoring engineers and leading technical decisions that span multiple teams or business units.
Subsidiary:
PayPal
Travel Percent:
0
-
The base pay for this role will depend on where you work and the relevant experience and expertise you bring. The expected range of pay for this role by location is:

Primary Location | Pay Range:
Chicago, Illinois: ($178,500.00 - $265,100.00 Annu