Senior Application Security Specialist
Xsolla is a global video game commerce company providing tools and services to launch, monetize, and scale games. Its offerings include payments, web shops, publishing, distribution, LiveOps, anti-fraud, subscriptions, SDKs, and creator solutions for developers, publishers, payment providers, creators, and other gaming businesses.
Maintainer signals as of 8/23/2026
Projects
About Xsolla (USA), Inc.
Xsolla operates as a global merchant of record and video game commerce platform serving developers, publishers, resellers, payment providers, creators, and retailers. It provides payment processing across more than 200 countries and regions, 1,000+ payment methods, and 130+ currencies, alongside tax management, compliance, fraud prevention, refunds, dispute management, and end-user support. Its product portfolio includes Web Shop, Publishing Suite, Payments, Xsolla Pay, Mobile Buy Button, SDKs, Subscriptions, game distribution, Partner Network, Offerwall, LiveOps, Anti-Fraud, Login, Site Builder, cloud gaming, and related gaming commerce tools.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Own security initiatives end-to-end by identifying, assessing, and driving remediation of vulnerabilities across products and infrastructure. Lead AppSec work, set security standards, balance risk against business velocity, mentor junior specialists, and document findings clearly.
Requirements
- 4+ years in application security or a related security engineering role.
- Expert knowledge of OWASP Top 10, SSRF, deserialization, request smuggling, OAuth/OIDC flaws, and business logic abuse.
- Extensive hands-on Burp Suite and manual testing experience.
- Ability to audit PHP, Python, Go, or JavaScript code.
- Experience embedding security requirements, design review, CI/CD gates, and developer enablement into workflows.
- Ability to assess severity and communicate risk to engineers and leadership.
- Strong analytical thinking, ownership, and follow-through.
- Nice-to-have experience with bug bounty programs, CTFs, Python or Go automation, GCP, Kubernetes security, advanced certifications, regulated environments, CVE credits, or security research.
Responsibilities
- Lead triage of bug bounty reports and scanner findings.
- Set severity standards, escalation policies, and remediation SLAs.
- Plan and conduct penetration tests of web applications, APIs, and services.
- Define assessment scope and methodology.
- Facilitate threat modeling sessions and identify trust boundaries, data flows, and attack surfaces.
- Select, operate, and tune SAST, DAST, SCA, and secrets-scanning tooling.
- Design noise-reduction and auto-triage workflows and integrate security gates into CI/CD.
- Lead secure code reviews across PHP, Python, and Go codebases.
- Define secure coding guidelines and review checklists.
- Coach junior security specialists, run internal training, and champion security awareness.
- Document findings, reproduction steps, and remediation guidance.
- Set the security documentation standard for the team.
