Junior Application Security Specialist

Join Xsolla's growing security team to identify, assess, document, and help remediate vulnerabilities across products and infrastructure while developing application security expertise under the guidance of senior specialists.

Responsibilities

  • Assess bug bounty reports and scanner findings, evaluate validity and severity, and escalate issues with clear summaries.
  • Participate in web application and API security assessments.
  • Identify and document risks in new and existing features.
  • Document findings, reproduction steps, proof of concept, and remediation guidance.
  • Participate in threat modeling and identify trust boundaries, data flows, and attack surfaces.
  • Help operate SAST, DAST, and dependency scanning tools and support remediation workflows.
  • Review code for common vulnerability classes under senior guidance.
  • Stay current with vulnerability classes, CVEs, and security techniques.

Requirements

  • Understanding of OWASP Top 10, CSRF, XSS, IDOR, SQL injection, open redirects, authentication, and session management weaknesses.
  • Understanding of HTTP, client-server architecture, REST APIs, same-origin policy, cookies, and CORS.
  • Hands-on experience with Burp Suite or similar web application security testing tools.
  • Ability to reproduce vulnerabilities and write clear reports with reproduction steps, proof of concept, and impact statements.
  • Familiarity with secure coding concepts including input validation, output encoding, parameterized queries, and least privilege.
  • Ability to read code in PHP, Python, JavaScript, or Go.
  • Analytical thinking, clear written communication, curiosity, and initiative.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available