Application Security Specialist
Baku
Xsolla
Find out how you can launch, monetize and scale your video games worldwide, with no upfront costs, using Xsolla's comprehensive suite of tools and services.
Join Xsolla as an Application Security Specialist, where you’ll dive deep into our infrastructure, architecture, services, and tools to strengthen our security posture. This role offers an exciting opportunity to conduct rigorous penetration testing across Blackbox and Greybox environments. You’ll work closely with developer teams, contribute to the security of our payment systems, and help secure our core services. If you're passionate about Linux, PHP/JavaScript, OWASP, and BurpSuite, and have the drive to innovate security processes, we want to meet you!
Convenient work toolsLatest Mac workplaces + additional hardware to make you more effective at workGoogle Chat, Gmail, Google Drive, Confluence, Jira, GitLab
Professional growthFree trainings and participation in specialized conferencesRich knowledge exchange within the company
More perksFlexible hours: organize your day according to your needs and sprint & teamwork demandsNo dress codeComfortable and new office environment
ABOUT XSOLLA
Xsolla is a global video game commerce company with a robust and powerful set of tools and services designed specifically for the video game industry. Since its founding in 2005, Xsolla has helped thousands of game developers and publishers of all sizes fund, market, launch and monetize their games globally and across multiple platforms. As an innovative leader in in-game commerce, Xsolla’s mission is to solve the inherent complexities of global distribution, marketing, and monetization to help our partners reach more geographies, generate more revenue and create relationships with gamers worldwide. Xsolla is headquartered and incorporated in Los Angeles, California, with offices in Berlin, Seoul, and cities worldwide. Xsolla supports major gaming titles like Valve, Twitch, Roblox, Ubisoft, Epic Games, Take-Two, KRAFTON, Nexters, NetEase, Playstudios, Playrix, miHoYo, and more.
For additional information and to learn more, please visit xsolla.com
PHYSICAL DEMANDS
The physical demands for this position are sits, stands, bends, lifts, and moves intermittently during working hours. These physical requirements may be accomplished with or without reasonable accommodations.
The duties of this position may change from time to time so the individual and organization can achieve their results. This job description is intended to describe the general level of work being performed. It is not intended to be all-inclusive.
Longevity Opportunity Vision Enjoy the game.
For more vacancies: https://xsolla.com/careers/vacancies
RESPONSIBILITIES
- Familiarize yourself with and master our current infrastructure, services, and tools.
- Conduct thorough penetration testing of core services in Blackbox and Greybox environments.
- Identify and investigate vulnerabilities in the company’s products, ensuring they are resolved according to SLAs.
- Collaborate effectively with product development, IT, and management teams to ensure vulnerabilities are addressed.
- Conduct security assessments of the company’s service architecture and offer improvement suggestions.
- Engage in the study of payment systems’ technologies and operations.
- Assist in the implementation of the security code review process and SDLC automation.
- Actively participate in the Bug Bounty program and other information security incident investigations.
- Regularly utilize tools like BurpSuite and various scanners for vulnerability testing and reporting.
- Develop and conduct training sessions to educate developers on secure coding practices and vulnerability mitigation.
- Take part in the selection and implementation of new information security systems and processes.
REQUIREMENTS
- Proficiency in Linux, penetration testing (Blackbox/Greybox), PHP/JavaScript, OWASP, BurpSuite/OWASP ZAP.
- At least 3 years of relevant experience in application security or a similar role.
- Strong understanding of web application attacks, how to exploit them, and appropriate defense techniques.
- Familiarity with manual and automated security analysis tools and experience with SDLC practices.
- Experience in testing payment systems and an eagerness to learn about their operation and associated technologies.
- Solid understanding of networking principles and how modern web applications work.
- Demonstrated ability to work collaboratively with developer teams to mitigate vulnerabilities.
- Initiative and innovative mindset to create and improve security processes.
- Strong communication skills and a proactive approach to addressing security challenges.
- Comfortable with verbal and written communication in English.
Convenient work toolsLatest Mac workplaces + additional hardware to make you more effective at workGoogle Chat, Gmail, Google Drive, Confluence, Jira, GitLab
Professional growthFree trainings and participation in specialized conferencesRich knowledge exchange within the company
More perksFlexible hours: organize your day according to your needs and sprint & teamwork demandsNo dress codeComfortable and new office environment
ABOUT XSOLLA
Xsolla is a global video game commerce company with a robust and powerful set of tools and services designed specifically for the video game industry. Since its founding in 2005, Xsolla has helped thousands of game developers and publishers of all sizes fund, market, launch and monetize their games globally and across multiple platforms. As an innovative leader in in-game commerce, Xsolla’s mission is to solve the inherent complexities of global distribution, marketing, and monetization to help our partners reach more geographies, generate more revenue and create relationships with gamers worldwide. Xsolla is headquartered and incorporated in Los Angeles, California, with offices in Berlin, Seoul, and cities worldwide. Xsolla supports major gaming titles like Valve, Twitch, Roblox, Ubisoft, Epic Games, Take-Two, KRAFTON, Nexters, NetEase, Playstudios, Playrix, miHoYo, and more.
For additional information and to learn more, please visit xsolla.com
PHYSICAL DEMANDS
The physical demands for this position are sits, stands, bends, lifts, and moves intermittently during working hours. These physical requirements may be accomplished with or without reasonable accommodations.
The duties of this position may change from time to time so the individual and organization can achieve their results. This job description is intended to describe the general level of work being performed. It is not intended to be all-inclusive.
Longevity Opportunity Vision Enjoy the game.
For more vacancies: https://xsolla.com/careers/vacancies
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
2
0
0
Category:
AppSec Jobs
Tags: Application security Automation Burp Suite Confluence Exploit GitLab JavaScript Jira Linux OWASP Pentesting PHP SDLC Security analysis Security assessment SLAs Vulnerabilities
Region:
Asia/Pacific
Country:
Azerbaijan
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Security Analyst jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsSenior Network Security Engineer jobsInformation Security Specialist jobsSenior Cybersecurity Engineer jobsSecurity Consultant jobsSenior Penetration Tester jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Cyber Security Engineer jobsCyber Security Specialist jobsChief Information Security Officer jobsStaff Security Engineer jobsIT Security Analyst jobsInformation System Security Officer (ISSO) jobsPrincipal Security Engineer jobsCloud Security Architect jobsCyber Security Architect jobsSystems Engineer jobsSecurity Operations Analyst jobsSenior Product Security Engineer jobsSenior Information Security Engineer jobs
CI/CD jobsSaaS jobsMalware jobsForensics jobsEncryption jobsEDR jobsIDS jobsSplunk jobsTop Secret jobsIPS jobsRMF jobsSDLC jobsSQL jobsIntrusion detection jobsBash jobsCompTIA jobsThreat detection jobsDoDD 8570 jobsOWASP jobsITIL jobsFinance jobsDocker jobsActive Directory jobsTCP/IP jobsCRISC jobs
IT infrastructure jobsGIAC jobsVPN jobsHIPAA jobsUNIX jobsBanking jobsTerraform jobsClearance Required jobsSANS jobsJavaScript jobsDNS jobsPolygraph jobsSOX jobsCISO jobsOSCP jobsAnsible jobsCCSP jobsMITRE ATT&CK jobsSOC 2 jobsJira jobsGCIH jobsData Analytics jobsCryptography jobsCyber defense jobsSOAR jobs