Junior Application Security Specialist

Xsolla
Baku
Workplace: OnsiteFull timeFunction: Solutions Engineering & Sales EngineeringSkills: ["Analytical thinking","Clear written communication","Curiosity","Initiative"]

Join a growing security team to help identify, assess, and remediate application security vulnerabilities across Xsolla’s products and infrastructure. You’ll perform day-to-day AppSec work including vulnerability triage, code reviews, threat modeling, and security testing. You’ll also help operate SAST/DAST and dependency scanning tools, document findings with clear reproduction steps, and escalate issues with accurate severity analysis while learning from senior specialists.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Xsolla
Xsolla
2 months ago

Junior Application Security Specialist

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live

Job Summary

Join a growing security team to help identify, assess, and remediate application security vulnerabilities across Xsolla’s products and infrastructure. You’ll perform day-to-day AppSec work including vulnerability triage, code reviews, threat modeling, and security testing. You’ll also help operate SAST/DAST and dependency scanning tools, document findings with clear reproduction steps, and escalate issues with accurate severity analysis while learning from senior specialists.
Location: Baku
Workplace: Onsite
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Entry level

Key Responsibilities

  • •Triage security findings by assessing bug bounty and scanner reports, determining validity and real severity, and escalating with clear summaries.
  • •Assist with vulnerability assessments for web applications and APIs by identifying and documenting risks in new and existing systems.
  • •Document security findings with reproduction steps and remediation guidance that engineering teams can act on.
  • •Participate in threat modeling to identify trust boundaries, data flows, and attack surfaces in system designs.
  • •Help monitor and operate SAST, DAST, and dependency scanning tools, reducing noise and supporting remediation workflows.

Key Requirements

  • •Solid understanding of web security vulnerabilities (OWASP Top 10, CSRF, XSS, IDOR, SQL injection, open redirect, auth/session weaknesses) including root causes.
  • •Strong grasp of web fundamentals (HTTP request/response, REST APIs, same-origin policy, cookies, CORS).
  • •Hands-on experience with Burp Suite or similar web app security testing tools, including intercepting/modifying/replaying requests.
  • •Ability to reproduce vulnerabilities and write clear documentation (reproduction steps, proof of concept, impact).
  • •Familiarity with secure coding concepts such as input validation, output encoding, parameterized queries, and least privilege.
Experience:Payment platformApplication securityAppSecBug bounty
Skills:Analytical thinkingClear written communicationCuriosityInitiative
Tech Stack:OWASP Top 10CSRFXSSIDORSQL injectionOpen redirectHTTPREST APIsSame-origin policyCookiesCORSBurp SuiteSASTDASTDependency scanningPHPPythonJavaScriptGo

Company Brief

Xsolla
Provides payment, billing, distribution and commerce solutions for video game developers and publishers, enabling in-game purchases, store infrastructure, fraud protection, and global payment processing to monetize games across platforms and regions.
Industry: Payments
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Sherman Oaks, Los Angeles, United States
Founded: 2005
WebsiteLinkedIn