Offensive Security Specialist

2 Months ago • 3 Years + • Cyber Security

Job Summary

Job Description

As an Offensive Security Specialist at Xsolla, you'll strengthen the company's security posture by conducting penetration testing in Blackbox and Greybox environments. You'll collaborate with developer teams, secure payment systems and core services, and contribute to security code reviews and SDLC automation. Responsibilities include identifying and investigating vulnerabilities, conducting security assessments, participating in bug bounty programs, and developing security training. Proficiency in Linux, PHP/JavaScript, OWASP, BurpSuite, and penetration testing is essential. The role requires strong collaboration skills and a proactive approach to addressing security challenges.
Must have:
  • Penetration testing (Blackbox/Greybox)
  • Linux, PHP/JavaScript, OWASP
  • BurpSuite/OWASP ZAP
  • Web application security expertise
  • Collaboration with developers
  • Vulnerability identification & mitigation

Job Details

ABOUT YOU

Join Xsolla as an Offensive Security Specialist, where you’ll dive deep into our infrastructure, architecture, services, and tools to strengthen our security posture. This role offers an exciting opportunity to conduct rigorous penetration testing across Blackbox and Greybox environments. You’ll work closely with developer teams, contribute to the security of our payment systems, and help secure our core services. If you're passionate about Linux, PHP/JavaScript, OWASP, and BurpSuite, and have the drive to innovate security processes, we want to meet you!

ABOUT US

At Xsolla, we believe that great games begin as ideas, driven by the curiosity, dedication, and grit of creators around the world. Our mission is to empower these visionaries by providing the support and resources they need to bring their games to life. We are committed to leveling the playing field, ensuring that every creator has the opportunity to share their passion with the world. 

Headquartered in Los Angeles, with offices in Berlin, Seoul, and beyond, we partner with industry leaders like Valve, Twitch, and Ubisoft to clear the paths for innovation in gaming. Our global reach spans over 200 geographies, offering more than 700 payment methods in 130+ currencies.

Longevity Opportunity Vision Enjoy the game!

RESPONSIBILITIES

    • Familiarize yourself with and master our current infrastructure, services, and tools.
    • Conduct thorough penetration testing of core services in Blackbox and Greybox environments.
    • Identify and investigate vulnerabilities in the company’s products, ensuring they are resolved according to SLAs.
    • Collaborate effectively with product development, IT, and management teams to ensure vulnerabilities are addressed.
    • Conduct security assessments of the company’s service architecture and offer improvement suggestions.
    • Engage in the study of payment systems’ technologies and operations.
    • Assist in the implementation of the security code review process and SDLC automation.
    • Actively participate in the Bug Bounty program and other information security incident investigations.
    • Regularly utilize tools like BurpSuite and various scanners for vulnerability testing and reporting.
    • Develop and conduct training sessions to educate developers on secure coding practices and vulnerability mitigation.
    • Take part in the selection and implementation of new information security systems and processes.

REQUIREMENTS

    • Proficiency in Linux, penetration testing (Blackbox/Greybox), PHP/JavaScript, OWASP, BurpSuite/OWASP ZAP.
    • At least 3 years of relevant experience in application security or a similar role.
    • Strong understanding of web application attacks, how to exploit them, and appropriate defense techniques.
    • Familiarity with manual and automated security analysis tools and experience with SDLC practices.
    • Experience in testing payment systems and an eagerness to learn about their operation and associated technologies.
    • Solid understanding of networking principles and how modern web applications work.
    • Demonstrated ability to work collaboratively with developer teams to mitigate vulnerabilities.
    • Initiative and innovative mindset to create and improve security processes.
    • Strong communication skills and a proactive approach to addressing security challenges.
    • Comfortable with verbal and written communication in English.
By submitting the following job application form, you consent to Xsolla processing your data for career-related inquiries and potential employment opportunities. We process your data in accordance with this Xsolla Privacy Notice for Job Applicants. Please direct any inquiries regarding your data privacy to careers@xsolla.com.

Longevity Opportunity Vision Enjoy the game!

Similar Jobs

SPH Media - The Straits Times Specialist Internship – Interactive Graphics (4 to 6 months)

SPH Media

Singapore, Singapore (On-Site)
9 Months ago
Interactive Brokers - Senior Systems Engineer- Microsoft M365/Active Directory

Interactive Brokers

Greenwich, Connecticut, United States (Hybrid)
7 Months ago
Easygo - Software Development Engineer, Engagement

Easygo

Melbourne, Victoria, Australia (On-Site)
1 Month ago
Nagarro - Engineer

Nagarro

Mexico (Remote)
7 Months ago
Hedra - Full-Stack Engineer

Hedra

New York, New York, United States (On-Site)
2 Months ago
ION - SOC Manager

ION

Noida, Uttar Pradesh, India (On-Site)
7 Months ago
Normalyze - Customer Success Engineer - Data Security - Implementation - DSPM - Bangalore

Normalyze

Bengaluru, Karnataka, India (Remote)
7 Months ago
Dream Games - Workplace Security Manager

Dream Games

İstanbul, Türkiye (On-Site)
3 Months ago
PwC - IN-Manager_AWS Engineer_Advisory Corporate_Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
8 Months ago
NVIDIA - Offensive Hardware Security Researcher

NVIDIA

Canada (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Reality Games - Data Analyst - Monopoly World

Reality Games

Kraków, Lesser Poland Voivodeship, Poland (On-Site)
2 Months ago
The Walt Disney Company - Lead Software Engineer

The Walt Disney Company

Seattle, Washington, United States (On-Site)
2 Months ago
Relax Gaming  - Front-End Technical Lead

Relax Gaming

Harju County, Estonia (Hybrid)
3 Months ago
Meta - Software Engineer, Intern/Co-op

Meta

New York, New York, United States (On-Site)
6 Months ago
Velotio Technologies - Senior DevOps Engineer (AWS)

Velotio Technologies

Maharashtra, India (Remote)
2 Months ago
Google - Student Researcher, BS/MS, Winter/Summer 2025

Google

Ann Arbor, Michigan, United States (On-Site)
6 Months ago
Push Gaming - Game Developer

Push Gaming

Poland (Hybrid)
2 Months ago
CloudHire - Salesforce Developer L5/6 (Vlocity)

CloudHire

Telangana, India (Remote)
2 Months ago
Netflix - Senior Software Engineer — Testing Tools & Infrastructure

Netflix

Warsaw, Masovian Voivodeship, Poland (On-Site)
3 Months ago
Epic Games - Lead Automation Engineer

Epic Games

Cary, North Carolina, United States (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Baku, Azerbaijan

Xsolla - Tech Lead - Metasites

Xsolla

Baku, Azerbaijan (Hybrid)
4 Months ago
Xsolla - Senior QA Engineer (Anti-fraud)

Xsolla

Baku, Azerbaijan (On-Site)
2 Months ago
Xsolla - Senior Backend Developer

Xsolla

Baku, Azerbaijan (On-Site)
1 Month ago
Xsolla - Customer Support Representative

Xsolla

Baku, Azerbaijan (On-Site)
3 Months ago
Xsolla - Tech Lead - Data Services

Xsolla

Baku, Azerbaijan (Hybrid)
1 Month ago
Xsolla - Application Security Specialist

Xsolla

Baku, Azerbaijan (On-Site)
6 Months ago
Xsolla - Middle+/Senior IT Recruiter

Xsolla

Baku, Azerbaijan (Remote)
2 Months ago
Xsolla - Middle / Senior Backend Developer for Xsolla Account

Xsolla

Baku, Azerbaijan (On-Site)
7 Months ago
Xsolla - Legal Counsel

Xsolla

Baku, Azerbaijan (Hybrid)
2 Months ago
Xsolla - Tech Lead for Xsolla ID

Xsolla

Baku, Azerbaijan (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - IN-Senior Associate – D365 POS Technical-Ms Dynamics–Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
7 Months ago
CD PROJEKT RED - Cybersecurity Specialist

CD PROJEKT RED

Warsaw, Masovian Voivodeship, Poland (On-Site)
3 Months ago
Playtika - Product Security Team Leader

Playtika

Israel (On-Site)
5 Months ago
The Walt Disney Company - Senior Security Specialist, Compliance

The Walt Disney Company

Burbank, California, United States (On-Site)
2 Months ago
ION - Senior Security Architect

ION

Milan, Lombardy, Italy (On-Site)
7 Months ago
Krafton  - Senior Security Engineer

Krafton

Seoul, South Korea (On-Site)
2 Months ago
Axinous - Senior Professional Services Consultant - AMS

Axinous

United States (Remote)
2 Months ago
ByteDance - Software Engineer, Security Operation Center

ByteDance

San Jose, California, United States (On-Site)
2 Months ago
NVIDIA - Senior Hardware Security Architect, GPU Security Verification

NVIDIA

Redmond, Washington, United States (On-Site)
3 Months ago
The Walt Disney Company - Senior Security Specialist, Third-Party Risk Management

The Walt Disney Company

Burbank, California, United States (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Baku, Azerbaijan (Hybrid)

Baku, Azerbaijan (Hybrid)

Tokyo, Japan (On-Site)

Beijing, China (On-Site)

Berlin, Berlin, Germany (Hybrid)

Berlin, Berlin, Germany (On-Site)

Baku, Azerbaijan (Hybrid)

Los Angeles, California, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by Xsolla

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug