368,530open jobs
9,432companies
50,439added this week
Browse all
Location
In office (Baku)
Seniority
Junior
Employment
Full-Time
Overview
Company
Impact
Profile match
Xsolla is a global video game commerce company that provides specialized financial and operational tools tailored for the gaming industry. The firm helps game developers and publishers fund, launch, market, and monetize their titles across PC, mobile, web, and cloud platforms. By operating as a merchant of record with support for over 1,000 local payment methods, it enables direct-to-consumer sales and seamless cross-border transactions for gaming studios worldwide.

ABOUT YOU

We are looking for a junior application security specialist to join a growing security team at Xsolla. This is a hands-on role where you will work closely with senior specialists to identify, assess, and help remediate security vulnerabilities across our products and infrastructure.

You will be involved in day-to-day AppSec work - code reviews, vulnerability triage, threat modeling, and security testing. You are curious, detail-oriented, and eager to develop deep expertise in application security. You do not need to have all the answers, but you ask the right questions and follow through.

This is a strong learning environment. You will be exposed to real-world security challenges in a payment platform operating at scale, and supported by experienced security specialists who will help you grow.

ABOUT US

Xsolla is a global commerce company with robust tools and services to help developers solve the inherent challenges of the video game industry. From indie to AAA, companies partner with Xsolla to help them fund, distribute, market, and monetize their games. Grounded in the belief in the future of video games, Xsolla is resolute in the mission to bring opportunities together, and continually make new resources available to creators. Headquartered and incorporated in Los Angeles, California, Xsolla operates as the merchant of record and has helped over 1,500+ game developers to reach more players and grow their businesses around the world. With more paths to profits and ways to win, developers have all the things needed to enjoy the game.

For more information, visit xsolla.com.

Responsibilities

    • Triage Security Findings - Assess incoming bug bounty reports and scanner findings. Evaluate validity, calculate real severity, and escalate appropriately with clear written summaries.

    • Assist with Vulnerability Assessments - Participate in security assessments of web applications and APIs. Help identify and document risks in new features and existing systems.

    • Write Clear Security Documentation - Document findings, reproduction steps, and remediation guidance in a way that engineering teams can act on.

    • Support Threat Modeling - Participate in threat modeling sessions. Learn to identify trust boundaries, data flows, and attack surfaces in system designs.

    • Monitor Security Tools - Help operate SAST, DAST, and dependency scanning tooling. Track findings, reduce noise, and support remediation workflows.

    • Support Code Reviews - Review code for common vulnerability classes under guidance of senior specialists. Learn to identify security issues across PHP, Python, and Go codebases.

    • Stay Current - Follow developments in the security community. Bring awareness of new vulnerability classes, CVEs, and attack techniques relevant to our stack.

What You Bring

    • Web Security Fundamentals - Solid understanding of common vulnerability classes: OWASPTop 10, CSRF, XSS, IDOR, SQL injection, open redirect, authentication and session management weaknesses. You understand root causes, not just names.

    • Web and Browser Fundamentals - Solid understanding of how web applications work: HTTP request/response cycle, client-server model, REST APIs, how browsers handle same-origin policy, cookies and their attributes, and CORS. This is the foundation everything else builds on.

    • Security Testing Tools - Hands-on experience with Burp Suite or similar web application security testing tools. You have used them to intercept, modify, and replay requests - not just run automated scans.

    • Vulnerability Documentation - Able to reproduce a vulnerability and write it up clearly: reproduction steps, proof of concept, and impact statement. Findings that engineering teams cannot reproduce or understand do not get fixed.

    • Secure Development Awareness - Familiarity with foundational secure coding concepts: input validation, output encoding, parameterized queries, and least privilege.

    • Code Readability - Ability to read and follow code in at least one language relevant to web security - PHP, Python, JavaScript, or Go. You don't need to be a developer, but you need to follow logic and spot security-relevant patterns.

    • Analytical Thinking - You reason through problems methodically. You can explain not just what a vulnerability is but why it exists, how it is exploited, and what fixing it actually requires.

    • Clear Written Communication - You write findings and summaries that are precise, reproducible, and useful to the engineers who need to act on them.

    • Curiosity and Initiative - You dig into problems rather than stopping at the surface. When something looks wrong, you investigate before concluding

Nice to Have

    • Participation in bug bounty programs or CTFcompetitions;

    • Basic scripting ability for automation - Python or Bash;

    • Familiarity with CI/CD pipelines and where security tooling fits;

    • Exposure to cloud environments - GCP, AWS, or Azure;

    • Relevant coursework or certifications - eWPT, CEH, PortSwigger Web Security Academy progress, or similar entry-level credentials.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Baku
$110k – $130k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
JavaScript
Python
SQL
AI/ML
AI Agents
Human-in-the-Loop
Cybersecurity
HIPAA
Apply
$134k – $241k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
JavaScript
Python
TypeScript
Node JS
Node JS
Axios
Databases
ElasticSearch
Frontend
Vue.js
DevOps
Terraform
Apply
$217k – $304k per year • Equity • Remote • Full-Time • 8+ years exp
Go
Databases
Apache Kafka
ClickHouse
Google BigQuery
AI/ML
Flink
Recommender Systems
DevOps
Incident Management
Kubernetes
Apply
$83k – $187k per year (Estimated) • Equity • Remote • Full-Time
C++
Go
Java
Python
Rust
Scala
Apply
$48k – $136k per year (Estimated) • Equity • Remote • Full-Time
C++
Go
Java
Python
Rust
Scala
Apply
$14k – $26k per year (Estimated) • In office • Contractor • 4+ years exp • Bachelor's Degree • Vladivostok
Node JS
TypeScript
JavaScript
Frontend
esbuild
GraphQL
React.js
styled-components
Webpack
Zod
DevOps
CI/CD
GitLab CI
GitLab
QA
Cypress
Jest
Playwright
Vitest
Apply
$15k – $37k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Perm
Bash
Python
SQL
Databases
MySQL
PostgreSQL
DevOps
AWS
Datadog
GCP
Grafana
Prometheus
Puppet
Terraform
Zabbix
Apply
$14k – $35k per year (Estimated) • In office • Perm
Go
PHP
SQL
DevOps
CI/CD
Apply
$12k – $27k per year (Estimated) • In office • 3+ years exp • Perm
Go
PHP
Python
DevOps
CI/CD
Datadog
GCP
GitHub Actions
GitLab CI
Google GKE
Grafana
Helm
Kubernetes
OpenTelemetry
Prometheus
SLI/SLO/SLA
Terraform
Terragrunt
GitHub
GitLab
IAM
Apply
IT Support Engineer 4 days ago
$31k – $67k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Berlin
Cybersecurity
Okta
Management
Google Workspace
Apply
Remote • 2+ years exp • Baku
Go
SQL
TypeScript
JavaScript
Frontend
React.js
Apply
$24k – $36k per year (gross) • Remote • Full-Time • Baku
TypeScript
Databases
PostgreSQL
Supabase
Apply
Remote • 7+ years exp • Baku
DevOps
AWS
AWS Fargate
CI/CD
CircleCI
CloudFormation
Datadog
GitHub Actions
Grafana
Kubernetes
New Relic
OpenTelemetry
Platform Engineering
Terraform
Amazon ECS
GitHub
IAM
Cybersecurity
Snyk
SonarQube
Apply
Remote • Internship • Bachelor's Degree • Baku
PHP
Python
SQL
Databases
Apache Kafka
RabbitMQ
DevOps
CI/CD
Git
Helm
Jenkins
Kubernetes
Terraform
WebSockets
Web3
DeFi
Smart Contracts
Apply
Tech Lead 5 days ago
In office • Full-Time • 5+ years exp • Baku
Go
JavaScript
PHP
Frontend
Next.js
React.js
DevOps
CI/CD
Git
Incident Management
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.