You will be joining the Global Fraud Prevention organization to create and establish the Red Team capability - a groundbreaking function that operates at the intersection of offensive security and fraud research.
Technical Execution:
- Plan and execute red team engagements simulating real-world fraud attacks to expose gaps in fraud detection and prevention systems.
- Develop and deploy fraud attack simulations, including account takeover scenarios, synthetic identity fraud, payment manipulation, and automated bot attacks. You will collaborate closely with fraud operations, data science teams, and InfoSec to develop purple team strategies that continuously refine both offensive techniques and defensive capabilities.
- Conduct research on fraudsters' toolkits, malware, and automated fraud tools used against PayPal and its affiliates, analyzing network traffic patterns and behavioral indicators associated with fraud
Additional Responsibilities & Preferred Qualifications
What You Need to Bring
Required:
- 6+ years of experience in offensive security, cybercrime, cyber-fraud, or related areas
- Demonstrated experience building security capabilities or teams from inception
- Leadership experience coordinating technical activities and influencing cross-functional stakeholders
- Experience conducting red team engagements with fraud-related techniques (account manipulation, payment fraud simulation, data exfiltration)
- Proficiency in attack automation and tool development
- In-depth familiarity with the cybercrime and cyber-fraud environment
- Proficiency in multiple programming languages and both Linux and Windows environments
- Strategic thinking and entrepreneurial mindset
Preferred:
- Published security or fraud research (tools, papers, exploit analysis)
- Experience as a founding member or early hire in security teams
- Knowledge of network protocols, traffic analysis, and fraud detection technologies (SIEM, EDR, anti-fraud engines)
- Experience with big data platforms (Splunk, Hadoop) and machine learning approaches to fraud detection
- Knowledge of payment systems, digital wallets, and e-commerce fraud vectors
- Industry certifications (OSCP, OSCE, GPEN, GXPN)
- Track record of influencing security strategy at the organizational level
Our Benefits:
Any general requests for consideration of your skills, please