Security Engineer

Xsolla
Baku
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Written communication","Collaboration","Growth mindset","Self-directed","Directness"]

Join a new security team during a critical build-out phase, working across application security and infrastructure security. You’ll perform application security reviews using SAST/DAST and dependency scanning, participate in threat modeling, harden cloud and container environments on GCP/Kubernetes/IAM, and help triage and remediate penetration test findings. You’ll support incident response, track security findings, and partner directly with engineering on secure design and remediation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Xsolla
Xsolla
2 months ago

Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 27 minutes agoStatus: Live

Job Summary

Join a new security team during a critical build-out phase, working across application security and infrastructure security. You’ll perform application security reviews using SAST/DAST and dependency scanning, participate in threat modeling, harden cloud and container environments on GCP/Kubernetes/IAM, and help triage and remediate penetration test findings. You’ll support incident response, track security findings, and partner directly with engineering on secure design and remediation.
Location: Baku
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Conduct application security reviews, including code review and running SAST/DAST and dependency scanning tools, then help engineering resolve findings.
  • •Contribute to threat modeling sessions for new features and architecture changes to identify risks early.
  • •Harden cloud and container infrastructure by working on GCP, Kubernetes, and IAM configurations.
  • •Triage penetration test findings and coordinate with engineering teams to implement fixes with the security program manager.
  • •Support incident response by investigating and documenting security events, contributing to root-cause analysis, and assisting with containment.

Key Requirements

  • •Understand common vulnerability classes and secure coding patterns, and be able to conduct meaningful code reviews.
  • •Have exposure to GCP (or a similar cloud) with comfort around IAM, networking, and container concepts.
  • •Read and review code in one or more of Go, Python, or PHP, able to spot issues and follow logic.
  • •Use or be familiar with SAST, DAST, and dependency scanning tools within a development workflow.
  • •Write clear, concise async documentation and communicate findings and guidance effectively across time zones.
Experience:Application securityInfrastructure securityCloud securityContainer securityIncident response
Skills:Written communicationCollaborationGrowth mindsetSelf-directedDirectness
Certifications:OSCPGWAPTCKS
Tech Stack:GCPVSphere/ESXKubernetesContainersIAMSASTDASTDependency scanningMariaDBCockroachDBGoPHPPythonLinuxNetworkingESXPenetration testing

Company Brief

Xsolla
Provides payment, billing, distribution and commerce solutions for video game developers and publishers, enabling in-game purchases, store infrastructure, fraud protection, and global payment processing to monetize games across platforms and regions.
Industry: Payments
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Sherman Oaks, Los Angeles, United States
Founded: 2005
WebsiteLinkedIn