Security Engineer
Xsolla · Baku
—
Jul 6, 2026
Baku
Jul 21, 2026
What this job asks for AI summary
A generalist security engineering role on a team in early build-out, covering both application and infrastructure security. Day-to-day work spans code reviews, SAST/DAST tooling, cloud and container hardening on GCP and Kubernetes, threat modeling, penetration test remediation, and incident response support. The role suits someone comfortable moving across security domains, writing clear async documentation, and working directly alongside engineering teams on secure design and remediation.
Mid level · Los Angeles-Long Beach-Anaheim, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 75 people in the Los Angeles-Long Beach-Anaheim, CA area plausibly meet what this posting asks for (information security analysts). range 30–110
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,481 (middle half $96,915–$170,448).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
No overall years-of-experience requirement is stated anywhere in the posting; seniority is assessed as Mid based on the generalist, early-team-hire framing and the 'foundational' language used for required skills.
The title carries no level word, so advertised seniority is Unspecified.
Code literacy in Go, Python, or PHP is listed as a single requirement with explicit alternatives ('one or more of'); Go is used as the primary name with Python and PHP in alternatives.
GCP is listed as the primary cloud requirement but the posting explicitly accepts 'a similar cloud provider,' so AWS and Azure are captured as alternatives.
Kubernetes appears in both the required section (cloud/container hardening) and the Nice to Have section (hands-on container security experience); the required mention gates on general container concepts, while the Nice to Have refers to deeper hands-on expertise — the skill is marked required at the foundational level.
Threat modeling appears in the responsibilities but is listed under 'Nice to Have' as experience, so it is marked preferred.
No compensation range is disclosed in the posting.
The role is headquartered in Los Angeles; no explicit remote option is stated, so remote is set to false.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.