368,634open jobs
9,437companies
50,578added this week
Browse all
Location
In office (Baku)
Seniority
Senior · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Xsolla is a global video game commerce company that provides specialized financial and operational tools tailored for the gaming industry. The firm helps game developers and publishers fund, launch, market, and monetize their titles across PC, mobile, web, and cloud platforms. By operating as a merchant of record with support for over 1,000 local payment methods, it enables direct-to-consumer sales and seamless cross-border transactions for gaming studios worldwide.

ABOUT YOU

We are looking for a senior application security specialist to join a growing security team at Xsolla. This is a hands-on role where you will own security initiatives end-to-end - identifying, assessing, and driving remediation of security vulnerabilities across our products and infrastructure.

You will lead day-to-day AppSec work - deep code reviews, vulnerability triage, threat modeling, and security testing - and set the standards for how this work is done. You are rigorous, pragmatic, and able to balance security risk against business velocity in a payment platform operating at scale.

You will also mentor junior specialists and help raise the security bar across engineering teams.

ABOUT US

Xsolla is a global commerce company with robust tools and services to help developers solve the inherent challenges of the video game industry. From indie to AAA, companies partner with Xsolla to help them fund, distribute, market, and monetize their games. Grounded in the belief in the future of video games, Xsolla is resolute in the mission to bring opportunities together, and continually make new resources available to creators. Headquartered and incorporated in Los Angeles, California, Xsolla operates as the merchant of record and has helped over 1,500+ game developers to reach more players and grow their businesses around the world. With more paths to profits and ways to win, developers have all the things needed to enjoy the game.

For more information, visit xsolla.com.

Responsibilities

  • Own Vulnerability Management - Lead triage of bug bounty reports and scanner findings. Set severity standards, drive escalation policy, and ensure remediation SLAs are met across teams.

  • Lead Security Assessments - Plan and conduct in-depth security assessments and penetration tests of web applications, APIs, and services. Define assessment scope and methodology.

  • Drive Threat Modeling - Facilitate threat modeling sessions with engineering teams. Identify trust boundaries, data flows, and attack surfaces early in the design phase, and embed the practice into the SDLC.

  • Own AppSec Tooling Strategy - Select, operate, and tune SAST, DAST, SCA, and secrets-scanning tooling. Design noise-reduction and auto-triage workflows; integrate security gates into CI/CD.

  • Lead Secure Code Reviews - Perform security-focused code reviews across PHP, Python, and Go codebases. Define secure coding guidelines and review checklists for engineering teams.

  • Mentor and Educate - Coach junior security specialists, run internal security training, and champion security awareness among developers.

  • Write Clear Security Documentation - Document findings, reproduction steps, and remediation guidance in a way engineering teams can act on. Set the documentation standard for the team.

What You Bring

    • 4+ years in application security or a closely related security engineering role, with demonstrable ownership of AppSec programs or major initiatives.

    • Deep Web Security Expertise - Expert-level understanding of vulnerability classes (OWASPTop 10 and well beyond: SSRF, deserialization, request smuggling, OAuth/OIDCflaws, business logic abuse). You understand root causes, exploitation chains, and realistic impact in production systems.

    • Offensive Testing Proficiency - Extensive hands-on experience with Burp Suite and manual testing methodology. You can find vulnerabilities that scanners miss and chain low-severity issues into meaningful impact.

    • Code Fluency - Comfortable reading and auditing code in at least one of: PHP, Python, Go, JavaScript. Able to trace data flows across services and spot vulnerable patterns without runtime access.

    • Secure SDLCExperience - Practical experience embedding security into development workflows: security requirements, design review, CI/CD security gates, and developer enablement.

    • Risk Communication - You can calculate and defend real severity, push back on inflated findings, and explain risk to both engineers and leadership in their own language.

    • Analytical Thinking - You reason through problems methodically and can explain not just what a vulnerability is, but why it exists, how it is exploited, and what fixing it actually requires.

    • Ownership and Follow-Through - You drive findings to resolution across team boundaries without being asked.

Nice to Have

    • Track record in bug bounty programs (accepted reports on major platforms) or notable CTFresults;

    • Strong automation skills - Python or Go for building internal security tooling;

    • Experience securing cloud-native environments - GCP preferred; Kubernetes security a plus;

    • Advanced certifications - OSWE, OSCP, BSCP, or GWAPT;

    • Experience in payments, fintech, or other regulated environments (PCIDSSfamiliarity);

    • CVEcredits, public security research, or conference talks.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Baku
$20k – $50k per year (Estimated) • In office • Full-Time • Tomsk
C++
Go
Java
Kotlin
Databases
Apache Kafka
ClickHouse
ElasticSearch
DevOps
Jaeger
Kubernetes
Prometheus
SLI/SLO/SLA
Apply
$20k – $50k per year (Estimated) • In office • Full-Time • Perm
C++
Go
Java
Kotlin
Databases
Apache Kafka
ClickHouse
ElasticSearch
DevOps
Jaeger
Kubernetes
Prometheus
SLI/SLO/SLA
Apply
$11k – $25k per year (Estimated) • In office • Full-Time • 2+ years exp • Perm
Go
Java
Kotlin
SQL
Databases
Apache Kafka
PostgreSQL
DevOps
GitLab
QA
Postman
Swagger
Apply
$11k – $25k per year (Estimated) • In office • Full-Time • 2+ years exp • Tomsk
Go
Java
Kotlin
SQL
Databases
Apache Kafka
PostgreSQL
DevOps
GitLab
QA
Postman
Swagger
Apply
$19k – $47k per year (Estimated) • Remote • Full-Time • Perm
C#
C#
ASP.NET Core
Dapper
Entity Framework Core
Databases
Apache Kafka
ClickHouse
ElasticSearch
PostgreSQL
RabbitMQ
Redis
DevOps
CI/CD
Docker
Docker Compose
GitHub Actions
Kubernetes
TeamCity
GitHub
GitLab
Apply
$14k – $26k per year (Estimated) • In office • Contractor • 4+ years exp • Bachelor's Degree • Vladivostok
Node JS
TypeScript
JavaScript
Frontend
esbuild
GraphQL
React.js
styled-components
Webpack
Zod
DevOps
CI/CD
GitLab CI
GitLab
QA
Cypress
Jest
Playwright
Vitest
Apply
$15k – $37k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Perm
Bash
Python
SQL
Databases
MySQL
PostgreSQL
DevOps
AWS
Datadog
GCP
Grafana
Prometheus
Puppet
Terraform
Zabbix
Apply
$14k – $35k per year (Estimated) • In office • Perm
Go
PHP
SQL
DevOps
CI/CD
Apply
$12k – $27k per year (Estimated) • In office • 3+ years exp • Perm
Go
PHP
Python
DevOps
CI/CD
Datadog
GCP
GitHub Actions
GitLab CI
Google GKE
Grafana
Helm
Kubernetes
OpenTelemetry
Prometheus
SLI/SLO/SLA
Terraform
Terragrunt
GitHub
GitLab
IAM
Apply
IT Support Engineer 4 days ago
$31k – $67k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Berlin
Cybersecurity
Okta
Management
Google Workspace
Apply
Remote • 2+ years exp • Baku
Go
SQL
TypeScript
JavaScript
Frontend
React.js
Apply
$24k – $36k per year (gross) • Remote • Full-Time • Baku
TypeScript
Databases
PostgreSQL
Supabase
Apply
Remote • 7+ years exp • Baku
DevOps
AWS
AWS Fargate
CI/CD
CircleCI
CloudFormation
Datadog
GitHub Actions
Grafana
Kubernetes
New Relic
OpenTelemetry
Platform Engineering
Terraform
Amazon ECS
GitHub
IAM
Cybersecurity
Snyk
SonarQube
Apply
Remote • Internship • Bachelor's Degree • Baku
PHP
Python
SQL
Databases
Apache Kafka
RabbitMQ
DevOps
CI/CD
Git
Helm
Jenkins
Kubernetes
Terraform
WebSockets
Web3
DeFi
Smart Contracts
Apply
Tech Lead 5 days ago
In office • Full-Time • 5+ years exp • Baku
Go
JavaScript
PHP
Frontend
Next.js
React.js
DevOps
CI/CD
Git
Incident Management
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.