Xsolla logo
XsollaPosted 1 month ago

Junior Application Security Specialist

On-siteBaku, Baki, Azerbaijan

Full TimeEntry LevelLarge

Job Summary

Triage security findings by assessing bug bounty reports and scanner outputs, evaluating validity, and calculating real severity. Assist with vulnerability assessments for web applications and APIs, while supporting threat modeling sessions to identify trust boundaries and attack surfaces. Write clear security documentation detailing findings, reproduction steps, and remediation guidance for engineering teams. Monitor SAST, DAST, and dependency scanning tools to track findings and support remediation workflows. Review code for common vulnerability classes in PHP, Python, and Go under senior guidance. Stay current on the security community by tracking new CVEs and attack techniques relevant to our stack.

Required Qualifications

  • Strong written communication
  • Solid understanding of common vulnerability classes: OWASP Top 10, CSRF, XSS, IDOR, SQL injection, open redirect, authentication and session management weaknesses
  • Solid understanding of how web applications work: HTTP request/response cycle, client-server model, REST APIs, how browsers handle same-origin policy, cookies and their attributes, and CORS
  • Hands-on experience with Burp Suite or similar web application security testing tools
  • Able to reproduce a vulnerability and write it up clearly: reproduction steps, proof of concept, and impact statement
  • Familiarity with foundational secure coding concepts: input validation, output encoding, parameterized queries, and least privilege
  • Ability to read and follow code in at least one language relevant to web security - PHP, Python, JavaScript, or Go
  • You reason through problems methodically
  • You write findings and summaries that are precise, reproducible, and useful to the engineers who need to act on them
  • You dig into problems rather than stopping at the surface
  • When something looks wrong, you investigate before concluding

Desired Qualifications

  • Participation in bug bounty programs or CTF competitions
  • Basic scripting ability for automation - Python or Bash
  • Familiarity with CI/CD pipelines and where security tooling fits
  • Exposure to cloud environments - GCP, AWS, or Azure
  • Relevant coursework or certifications - eWPT, CEH, PortSwigger Web Security Academy progress, or similar entry-level credentials

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce