Senior Cybersecurity Threat Analyst
Listed on 2026-03-13
-
IT/Tech
Cybersecurity
Company Overview
Pay Pal has been revolutionizing commerce globally for more than 25 years. Creating innovative experiences that make moving money, selling, and shopping simple, personalized, and secure, Pay Pal empowers consumers and businesses in approximately 200 markets to join and thrive in the global economy. We operate a global, two-sided network at scale that connects hundreds of millions of merchants and consumers.
We help merchants and consumers connect, transact, and complete payments, whether they are online or in person. Pay Pal is more than a connection to third‑party payment networks. We provide proprietary payment solutions accepted by merchants that enable the completion of payments on our platform on behalf of our customers. We offer our customers the flexibility to use their accounts to purchase and receive payments for goods and services, as well as the ability to transfer and withdraw funds.
We enable consumers to exchange funds more safely with merchants using a variety of funding sources, which may include a bank account, a Pay Pal or Venmo account balance, Pay Pal and Venmo branded credit products, a credit card, a debit card, certain cryptocurrencies, or other stored value products such as gift cards, and eligible credit card rewards. Our Pay Pal, Venmo, and Xoom products also make it safer and simpler for friends and family to transfer funds to each other.
We offer merchants an end‑to‑end payments solution that provides authorization and settlement capabilities, as well as instant access to funds and payouts. We also help merchants connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross‑border shopping and merchants to extend their global reach while reducing the complexity and friction involved in enabling cross‑border trade.
We’re looking for a forward‑thinking Detection Engineer to join our Threat Detection team within Security Operations. This role is focused on building high‑fidelity, scalable detections that reduce risk and improve response effectiveness across enterprise, cloud, and product environments. You will partner closely with Incident Response, Threat Intelligence, Product Security, and Platform teams to design resilient detection strategies, close visibility gaps, and continuously improve our defensive posture.
This role goes beyond writing alerts. It requires strategic thinking, ownership of detection lifecycle maturity, and a strong bias toward measurable impact.
- Independently apply security best practices to enhance and optimize cyber threat management.
- Partner with peers and internal teams to drive security initiatives, contribute to cross‑functional projects, and at times co‑lead efforts to strengthen security posture and cyber threat management.
- Analyze and resolve security challenges by adapting standard cyber threat management processes and exploring alternative approaches to address complex threats.
- Influence the quality, efficiency, and effectiveness of the team through informed decision‑making, with a potential impact on other teams.
- Collaborate with key partners to gather and incorporate feedback, driving continuous improvements in cyber threat management.
- 3+ years of relevant experience and a Bachelor’s degree OR any equivalent combination of education and experience.
Preferred Qualifications What You’ll Do
- Design, implement, and continuously tune high‑fidelity detections across SIEM, EDR, and cloud‑native security platforms.
- Correlate telemetry across diverse data sources to identify complex or multi‑stage attack patterns.
- Own the end‑to‑end detection lifecycle from hypothesis and use case development through deployment, tuning, validation, and documentation.
- Build and enhance SOAR playbooks and automation workflows to reduce manual effort and improve response consistency.
- Conduct proactive threat hunting to identify anomalous behaviors, misconfigurations, and emerging attack techniques.
- Partner with engineering and infrastructure teams to improve logging quality, telemetry coverage,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).