Hello !!
I recommend you the book Professional Java Security (Programmer to Programmer) (Paperback)
by Jess Garms, Daniel Somerfield (Wrox). It is excelent and will allow you to cover all "techs" topic related to security.
But, more important than this, remember to consider many issues related to security, special if you starting a project like 'PayPal': check it out this first http://www.ranum.com/security/computer_security/editorials/dumb/.
Https doesn't mean 'secure' just for it. I thought you have many tools related and you will need to check where and how are you going to use them all around your project.
I hope i helped you.
Faturita