Xsolla logo
XsollaPosted 1 month ago

Security Engineer

On-siteBaku, Baki, Azerbaijan

Full TimeLarge

Job Summary

Conduct code reviews, run SAST/DAST and dependency scanning tools, and work with engineering to resolve findings. Contribute to threat modeling sessions for new features and architecture changes, helping identify risks early in the design process. Harden GCP, Kubernetes, and IAM configurations to strengthen the security of cloud and container environments. Triage penetration test findings and coordinate with the security program manager to implement fixes. Review architectures, advise on secure implementation patterns, and document findings to track them through remediation. Investigate security events, contribute to root-cause analysis, and support containment efforts. Produce advisories, best-practice documentation, and practical guidance that helps engineering teams build securely across time zones. Partner with partners on the security posture of customer-facing services.

Required Qualifications

  • Strong written communication
  • Foundational AppSec Knowledge
  • Cloud Environment Exposure
  • Code Literacy
  • Security Tooling Familiarity
  • Collaborative Mindset
  • Self-Directed with Growth Mindset

Desired Qualifications

  • Threat modeling experience
  • Hands-on Kubernetes or container security experience
  • Infrastructure security background - Linux, networking, vSphere/ESX
  • Familiarity with NIST CSF, PCI, SOC 2, or ISO 27001 from a technical perspective
  • Detection engineering or incident response experience
  • Experience building security automation or internal tooling
  • Relevant certifications (OSCP, GWAPT, CKS, or similar hands-on certs)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce