Source description
About the role
Web Security Fundamentals - Solid understanding of common vulnerability classes: OWASP Top 10, CSRF , XSS , IDOR , SQL injection, open redirect, authentication and session management weaknesses. You understand root causes, not just names.
Web and Browser Fundamentals - Solid understanding of how web applications work: HTTP request/response cycle, client-server model, REST APIs, how browsers handle same-origin policy, cookies and their attributes, and CORS . This is the foundation everything else builds on.
Security Testing Tools - Hands-on experience with Burp Suite or similar web application security testing tools. You have used them to intercept, modify, and replay requests — not just run automated scans.
Vulnerability Documentation - Able to reproduce a vulnerability and write it up clearly: reproduction steps, proof of concept, and impact statement. Findings that engineering teams cannot reproduce or understand do not get fixed.
Secure Development Awareness - Familiarity with foundational secure coding concepts: input validation, output encoding, parameterized queries, and least privilege.
Code Readability - Ability to read and follow code in at least one language relevant to web security - PHP, Python, JavaScript, or Go. You don't need to be a developer, but you need to follow logic and spot security-relevant patterns.
Analytical Thinking - You reason through problems methodically. You can explain not just what a vulnerability is but why it exists, how it is exploited, and what fixing it actually requires.
Clear Written Communication - You write findings and summaries that are precise, reproducible, and useful to the engineers who need to act on them.
Curiosity and Initiative - You dig into problems rather than stopping at the surface. When something looks wrong, you investigate before concluding
More at Xsolla
