PayPal

Senior Cybersecurity Threat Analyst

PayPal

Singapore · Full Time

Be the first to apply

Experience
3+ yrs
Salary
—
Openings
1
Posted
2 weeks ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About PayPal

For over 25 years, PayPal has been at the forefront of global commerce innovation by providing secure, personalized, and simple ways for consumers and businesses to transact in nearly 200 markets worldwide. Operating a large-scale, dual-sided network, PayPal connects millions of merchants and consumers enabling seamless online and in-person payments. Beyond facilitating third-party payment networks, PayPal offers proprietary payment solutions that allow merchants to complete transactions on our platform safely.

We provide users with the ability to purchase, receive payments, transfer, and withdraw funds using various funding sources such as bank accounts, PayPal or Venmo balances, branded credit products, cards, cryptocurrencies, stored value products, and credit card rewards. Our products like PayPal, Venmo, and Xoom simplify peer-to-peer fund transfers and enable merchants to manage authorizations, settlements, payouts, exchanges, returns, and risk. Our platform supports cross-border commerce, helping merchants scale globally while reducing transaction friction.

Our core values of Inclusion, Innovation, Collaboration, and Wellness guide us in working as a global team with customers at the center, ensuring care for ourselves, each other, and our communities.

Job Summary

We seek an innovative Detection Engineer to join our Threat Detection team within Security Operations. This role involves creating scalable and precise threat detections to reduce risks and improve incident response across enterprise, cloud, and product environments. You will collaborate extensively with Incident Response, Threat Intelligence, Product Security, and Platform groups to devise detection strategies, close visibility gaps, and enhance our security defenses. The role demands strategic oversight of detection lifecycles and a focus on measurable security impacts.

Key Responsibilities

  • Design and continuously optimize high-fidelity detections across SIEM, EDR, and cloud-native security platforms.
  • Correlate security telemetry from multiple sources to detect complex or multi-phase attack patterns.
  • Manage the complete detection lifecycle including hypothesis formation, use case development, deployment, tuning, validation, and documentation.
  • Develop and improve SOAR playbooks and automation to reduce manual response and enhance consistency.
  • Conduct proactive hunts to uncover anomalous activities, misconfigurations, and emerging threats.
  • Collaborate with engineering teams to enhance logging, telemetry quality, and data normalization.
  • Identify detection gaps and drive improvements in visibility across systems and products.
  • Participate in red and purple team exercises for validating detection capabilities and resilience.
  • Create and track metrics measuring detection coverage, false positive rates, and operational impact.
  • Communicate complex technical findings clearly and effectively to leadership and stakeholders.
  • Translate adversary tactics, techniques, and procedures (TTPs) into scalable detections aligned with MITRE ATT&CK framework.
  • Balance detection noise and coverage to maintain signal effectiveness and minimize false positives.
  • Continuously assess detection success and recommend enhancements.
  • Work with Incident Response to refine detections based on real-world incident investigations.
  • Drive strategic projects such as SIEM and SOAR migrations, detection standardization, and automation expansion.
  • Contribute to building detection frameworks, documentation standards, and repeatable procedures to mature the program.

Requirements

  • At least 5 years of professional cybersecurity experience focusing on detection engineering, threat hunting, or security automation.
  • Proficient hands-on experience with SIEM platforms like Splunk, Microsoft Sentinel, or Google SecOps, and EDR tools such as CrowdStrike or SentinelOne.
  • Strong familiarity with SIEM query languages, including SPL and KQL.
  • Deep understanding of adversary behavior, attack lifecycles, and detection engineering concepts.
  • Hands-on experience scripting automation with languages such as Python or PowerShell.
  • Demonstrated strategic thinking about detection coverage, data quality, and operational efficiency.
  • Excellent collaboration and influencing skills across cross-functional teams.
  • Minimum 3 years of relevant professional experience with a Bachelor's degree, or equivalent education and experience.

Additional Information

PayPal employs a hybrid work model offering three days in-office and two flexible days either at a PayPal office or home, fostering collaboration and flexibility. There is no business travel requirement for this role.

PayPal is committed to diversity, inclusion, and equal employment opportunity. We provide accommodations for qualified individuals as needed and maintain vigilance against recruitment fraud, communicating only through official PayPal domains. Our benefits include competitive paid time off, healthcare coverage, financial security programs, and mental health support.

Important Notices

PayPal does not charge any fees for applications, interviews, or onboarding, nor does it request passwords or verification codes. Candidates should report any suspicious activity immediately.

Minimum education

Bachelor's Degree

How they work

Teamwork & Collaboration Problem Solving Initiative Strategic Thinking Accountability
🤖
Online · instant AI help
Broxer