InfrastructurePlatformPythonAIRustSQLSecurityHTTPOSSREST API
📋 Job Overview
We are looking for a junior application security specialist to join a growing security team at Xsolla. This is a hands-on role where you will work closely with senior specialists to identify, assess, and help remediate security vulnerabilities across our products and infrastructure.
🏢 About Xsolla
Xsolla is a global commerce company with robust tools and services to help developers solve the inherent challenges of the video game industry. From indie to AAA, companies partner with Xsolla to help them fund, distribute, market, and monetize their games. Grounded in the belief in the future of video games, Xsolla is resolute in the mission to bring opportunities together, and continually make new resources available to creators. Headquartered and incorporated in Los Angeles, California, Xsolla operates as the merchant of record and has helped over 1,500+ game developers to reach more players and grow their businesses around the world. With more paths to profits and ways to win, developers have all the things needed to enjoy the game.
🎯 The Role
This is a strong learning environment. You will be exposed to real-world security challenges in a payment platform operating at scale, and supported by experienced security specialists who will help you grow.
✅ Key Responsibilities
Triage Security Findings - Assess incoming bug bounty reports and scanner findings. Evaluate validity, calculate real severity, and escalate appropriately with clear written summaries.
Assist with Vulnerability Assessments - Participate in security assessments of web applications and APIs. Help identify and document risks in new features and existing systems.
Write Clear Security Documentation - Document findings, reproduction steps, and remediation guidance in a way that engineering teams can act on.
Support Threat Modeling - Participate in threat modeling sessions. Learn to identify trust boundaries, data flows, and attack surfaces in system designs.
Monitor Security Tools - Help operate SAST, DAST, and dependency scanning tooling. Track findings, reduce noise, and support remediation workflows.
Support Code Reviews - Review code for common vulnerability classes under guidance of senior specialists. Learn to identify security issues across PHP, Python, and Go codebases.
Stay Current - Follow developments in the security community. Bring awareness of new vulnerability classes, CVEs, and attack techniques relevant to our stack.
📌 Required Qualifications
Web Security Fundamentals - Solid understanding of common vulnerability classes: OWASP Top 10, CSRF, XSS, IDOR, SQL injection, open redirect, authentication and session management weaknesses. You understand root causes, not just names.
Web and Browser Fundamentals - Solid understanding of how web applications work: HTTP request/response cycle, client-server model, REST APIs, how browsers handle same-origin policy, cookies and their attributes, and CORS. This is the foundation everything else builds on.