Security Engineer

Xsolla is a global video game commerce company providing tools and services to launch, monetize, and scale games. Its offerings include payments, web shops, publishing, distribution, LiveOps, anti-fraud, subscriptions, SDKs, and creator solutions for developers, publishers, payment providers, creators, and other gaming businesses.

Maintainer signals as of 8/23/2026

Distributed
About Xsolla (USA), Inc.

Xsolla operates as a global merchant of record and video game commerce platform serving developers, publishers, resellers, payment providers, creators, and retailers. It provides payment processing across more than 200 countries and regions, 1,000+ payment methods, and 130+ currencies, alongside tax management, compliance, fraud prevention, refunds, dispute management, and end-user support. Its product portfolio includes Web Shop, Publishing Suite, Payments, Xsolla Pay, Mobile Buy Button, SDKs, Subscriptions, game distribution, Partner Network, Offerwall, LiveOps, Anti-Fraud, Login, Site Builder, cloud gaming, and related gaming commerce tools.

View jobs by Xsolla (USA), Inc.

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Join a new security team during a critical build-out phase, working across application and infrastructure security. The role is a generalist position involving code reviews, cloud hardening, incident response, secure design, security findings, remediation, and documentation while collaborating closely with engineering teams.

Requirements

  • Understanding of common vulnerability classes, secure coding patterns, and meaningful code review.
  • Experience with GCP or a similar cloud provider, including IAM, networking, and container concepts.
  • Ability to read and review Go, Python, or PHP code.
  • Familiarity with SAST, DAST, or dependency scanning tools.
  • Strong written communication and clear async documentation skills.
  • Ability to partner effectively with engineering teams.
  • Eagerness to learn and comfort with ambiguity.

Responsibilities

  • Perform application security reviews through code reviews, SAST/DAST, and dependency scanning.
  • Participate in threat modeling for new features and architecture changes.
  • Harden cloud and container infrastructure using GCP, Kubernetes, and IAM configurations.
  • Triage penetration test findings and coordinate remediation with engineering teams.
  • Review architectures and advise on secure implementation patterns.
  • Identify, assess, document, and track security findings through remediation.
  • Investigate and document security events and contribute to root-cause analysis.
  • Write async security advisories, best-practice documentation, and practical guidance.
  • Support product security reviews for customer-facing services.
Security Engineer at Xsolla (USA), Inc. | JobStash