Junior Application Security Specialist
Core
Junior Application Security Specialist working with senior specialists to identify, assess, and remediate security vulnerabilities across Xsolla's payment platform products and infrastructure.
Role type
Junior IC application security specialist
Builds
Secure web applications and APIs for a global video game commerce platform
Domain
Cybersecurity / Application Security / Payments
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Web security fundamentals (OWASP Top 10, CSRF, XSS, IDOR, SQL injection), Web and browser fundamentals (HTTP, REST, CORS), Security testing tools (Burp Suite), Vulnerability documentation, Secure development awareness, Code readability (PHP, Python, JavaScript, Go), Analytical thinking
Preferred skills
Bug bounty participation, CTF competitions, Basic scripting (Python, Bash), CI/CD pipeline familiarity, Cloud environments (GCP, AWS, Azure), Relevant coursework or certifications
Technologies
Burp Suite, SAST, DAST, Dependency scanning tools, PHP, Python, Go, JavaScript
Responsibilities
Triage security findings from bug bounty reports and scanners; Assist with vulnerability assessments of web applications and APIs; Write clear security documentation for engineering teams; Support threat modeling sessions; Monitor and operate security tools (SAST, DAST, dependency scanning); Support code reviews for common vulnerability classes; Stay current on security community developments
Seniority
Junior, hands-on IC