Xsolla1mo ago
Senior Application Security Specialist
OtherSecurity SpecialistSkilled Trades & Field Services
6 views0 saves0 applied
Quick Summary
Overview
We are looking for junior application security specialists to join a growing security team atXsolla. This is a hands-on role where you will work closely with senior specialists to identify,assess, and help remediate security vulnerabilities across our products and infrastructure.You will be…
Technical Tools
awsazuregcpgojavascriptphppythonsqlci-cdcode-reviewrest-apis
We are looking for junior application security specialists to join a growing security team at
Xsolla. This is a hands-on role where you will work closely with senior specialists to identify,
assess, and help remediate security vulnerabilities across our products and infrastructure.
You will be involved in day-to-day AppSec work - code reviews, vulnerability triage, threat
modeling, and security testing. You are curious, detail-oriented, and eager to develop deep
expertise in application security. You do not need to have all the answers, but you ask the right
questions and follow through.
This is a strong learning environment. You will be exposed to real-world security challenges in a
payment platform operating at scale, and supported by experienced security specialists who will
help you grow.
Xsolla. This is a hands-on role where you will work closely with senior specialists to identify,
assess, and help remediate security vulnerabilities across our products and infrastructure.
You will be involved in day-to-day AppSec work - code reviews, vulnerability triage, threat
modeling, and security testing. You are curious, detail-oriented, and eager to develop deep
expertise in application security. You do not need to have all the answers, but you ask the right
questions and follow through.
This is a strong learning environment. You will be exposed to real-world security challenges in a
payment platform operating at scale, and supported by experienced security specialists who will
help you grow.
Evaluate validity, calculate real severity, and escalate appropriately with clear written
summaries.
applications and APIs. Help identify and document risks in new features and existing
systems.
remediation guidance in a way that engineering teams can act on.
trust boundaries, data flows, and attack surfaces in system designs.
Track findings, reduce noise, and support remediation workflows.
of senior specialists. Learn to identify security issues across PHP, Python, and Go
codebases.
vulnerability classes, CVEs, and attack techniques relevant to our stack.
OWASP Top 10, CSRF, XSS, IDOR, SQL injection, open redirect, authentication and
session management weaknesses. You understand root causes, not just names.
HTTP request/response cycle, client-server model, REST APIs, how browsers handle
same-origin policy, cookies and their attributes, and CORS. This is the foundation
everything else builds on.
application security testing tools. You have used them to intercept, modify, and replay
requests - not just run automated scans.
reproduction steps, proof of concept, and impact statement. Findings that engineering
teams cannot reproduce or understand do not get fixed.
concepts: input validation, output encoding, parameterized queries, and least privilege.
web security - PHP, Python, JavaScript, or Go. You don't need to be a developer, but you
need to follow logic and spot security-relevant patterns.
just what a vulnerability is but why it exists, how it is exploited, and what fixing it
actually requires.
reproducible, and useful to the engineers who need to act on them.
When something looks wrong, you investigate before concluding.
Xsolla operates across multiple time zones. Strong written communication is essential - you will need to document your work clearly so findings and context are not lost across handoffs. We value directness, intellectual honesty, and follow-through. If you do not know something, say so and find out. If you find something, explain it clearly and see it through to resolution.
Location & Eligibility
Where is the job
Baku, Azerbaijan
On-site at the office
Who can apply
AZ
Listed under
Worldwide
Listing Details
- Posted
- April 22, 2026
- First seen
- April 22, 2026
- Last seen
- June 10, 2026
Posting Health
- Days active
- 49
- Repost count
- 0
- Trust Level
- 31%
- Scored at
- June 10, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust

Xsolla
lever
Xsolla is a global video game commerce company that provides developers and publishers with tools and services for funding, marketing, launching, and monetizing games across multiple platforms.
View company profileExternal application · ~5 min on Xsolla's site
Please let Xsolla know you found this job on Jobera.
Similar Security Specialist jobs
View all →AI Security Specialist - Campinas/SP
I
IfoodcarreirasRemoteSenior Specialist AI Security Engineer
Remote
N
NeweratechCybersecurity Specialist
N
New Era Technology AUCybersecurity Specialist
ISE Space Component Security Specialist (Vandenberg)
USD 150000-170000
Personnel Security Specialist (PerSS) – SME
USD 83000–166000
Full Time On-Site
Browse Similar Jobs
Service Technician695Mechanic406Field Service Technician361Maintenance Supervisor210Electrician207Hvac Technician151Carpenter148Field Service Engineer147Welder128Plumber91Fabricator88Diesel Mechanic79Electrical Technician74Service Engineer68Painter67Mechanical Technician57Diesel Technician49Millwright45Automation Specialist42Heavy Equipment Mechanic41
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.