Junior Application Security Specialist

Xsolla is a global video game commerce company providing tools and services to launch, monetize, and scale games. Its offerings include payments, web shops, publishing, distribution, LiveOps, anti-fraud, subscriptions, SDKs, and creator solutions for developers, publishers, payment providers, creators, and other gaming businesses.

Maintainer signals as of 8/23/2026

Distributed
About Xsolla (USA), Inc.

Xsolla operates as a global merchant of record and video game commerce platform serving developers, publishers, resellers, payment providers, creators, and retailers. It provides payment processing across more than 200 countries and regions, 1,000+ payment methods, and 130+ currencies, alongside tax management, compliance, fraud prevention, refunds, dispute management, and end-user support. Its product portfolio includes Web Shop, Publishing Suite, Payments, Xsolla Pay, Mobile Buy Button, SDKs, Subscriptions, game distribution, Partner Network, Offerwall, LiveOps, Anti-Fraud, Login, Site Builder, cloud gaming, and related gaming commerce tools.

View jobs by Xsolla (USA), Inc.

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Join Xsolla's growing security team to identify, assess, document, and help remediate vulnerabilities across products and infrastructure while developing application security expertise under the guidance of senior specialists.

Requirements

  • Understanding of OWASP Top 10, CSRF, XSS, IDOR, SQL injection, open redirects, authentication, and session management weaknesses.
  • Understanding of HTTP, client-server architecture, REST APIs, same-origin policy, cookies, and CORS.
  • Hands-on experience with Burp Suite or similar web application security testing tools.
  • Ability to reproduce vulnerabilities and write clear reports with reproduction steps, proof of concept, and impact statements.
  • Familiarity with secure coding concepts including input validation, output encoding, parameterized queries, and least privilege.
  • Ability to read code in PHP, Python, JavaScript, or Go.
  • Analytical thinking, clear written communication, curiosity, and initiative.

Responsibilities

  • Assess bug bounty reports and scanner findings, evaluate validity and severity, and escalate issues with clear summaries.
  • Participate in web application and API security assessments.
  • Identify and document risks in new and existing features.
  • Document findings, reproduction steps, proof of concept, and remediation guidance.
  • Participate in threat modeling and identify trust boundaries, data flows, and attack surfaces.
  • Help operate SAST, DAST, and dependency scanning tools and support remediation workflows.
  • Review code for common vulnerability classes under senior guidance.
  • Stay current with vulnerability classes, CVEs, and security techniques.