Join Xsolla as anApplication Security Specialist, where you'll dive deep into our infrastructure, architecture, services, and tools to strengthen our security posture. This role offers an exciting opportunity to conduct rigorous penetration testing across Blackbox and Greybox environments. You'll work closely with developer teams, contribute to the security of our payment systems, and help secure our core services. If you're passionate about Linux, PHP/JavaScript, OWASP, and BurpSuite, and have the drive to innovate security processes, we want to meet you!
RESPONSIBILITIES
- Familiarize yourself with and master our current infrastructure, services, and tools.
- Conduct thorough penetration testing of core services in Blackbox and Greybox environments.
- Identify and investigate vulnerabilities in the company's products, ensuring they are resolved according to SLAs.
- Collaborate effectively with product development, IT, and management teams to ensure vulnerabilities are addressed.
- Conduct security assessments of the company's service architecture and offer improvement suggestions.
- Engage in the study of payment systems technologies and operations.
- Assist in the implementation of the security code review process and SDLC automation.
- Actively participate in the Bug Bounty program and other information security incident investigations.
- Regularly utilize tools like BurpSuite and various scanners for vulnerability testing and reporting.
- Develop and conduct training sessions to educate developers on secure coding practices and vulnerability mitigation.
- Take part in the selection and implementation of new information security systems and processes.
REQUIREMENTS
- Proficiency in Linux, penetration testing (Blackbox/Greybox), PHP/JavaScript, OWASP, BurpSuite/OWASP ZAP.
- At least 3 years of relevant experience in application security or a similar role.
- Strong understanding of web application attacks, how to exploit them, and appropriate defense techniques.
- Familiarity with manual and automated security analysis tools and experience with SDLC practices.
- Experience in testing payment systems and an eagerness to learn about their operation and associated technologies.
- Solid understanding of networking principles and how modern web applications work.
- Demonstrated ability to work collaboratively with developer teams to mitigate vulnerabilities.
- Initiative and innovative mindset to create and improve security processes.
- Strong communication skills and a proactive approach to addressing security challenges.
- Comfortable with verbal and written communication in English.