DevSecOps | WebTech
We are looking for a DevSecOps to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects.
Remote Full-time | DevOps
Apply
job description
As a DevSecOps, you will:
- Vulnerability Management — full lifecycle (core responsibility)
- Detect vulnerabilities across all layers: code, dependencies, container images, IaC, configurations, and network.
- Prioritize vulnerabilities based on real risk (exploitability + exposure), not only CVSS.
- Perform hands-on remediation: dependency upgrades, patching, configuration hardening, and code changes through pull requests together with developers.
- Verify remediation (re-scan / re-test), track SLA compliance, and prevent regressions.
- Implement Security into CI/CD
- Deploy and integrate SAST, DAST, SCA, and secret scanning into CI/CD pipelines.
- Configure security gates to block deployments on critical findings and manage exceptions with assigned risk owners.
- Network Security & Architecture
- Implement segmentation, firewall policies, zero-trust access, VPN, egress filtering, and IMDS protection.
- Work with edge/WAF (Cloudflare): tune rules, anti-bot protection, and rate limiting for payment and gaming APIs.
- Review network architecture and perimeter security to identify dangerous exposures.
- Cloud & Infrastructure Security
- Assess and harden cloud and bare-metal infrastructure.
- Perform IaC scanning (Terraform / Helm / Kubernetes) for insecure configurations.
- Manage secrets and secret rotation (Vault / cloud secrets), eliminate hardcoded credentials.
- Harden IAM / SSO (OIDC/SAML, Keycloak).
- SIEM & Detection Engineering
- Build and maintain logging and audit pipelines, detection-as-code, and correlation rules (ELK-like solutions).
- Collaborate closely with the SOC team by providing detections for new findings instead of duplicating their work.
- Containers & Orchestration
- Scan container images (Trivy / Grype), implement RBAC and least privilege principles, configure network policies, runtime detection (Falco), and harden base images.
- Secure SDLC & Security Culture
- Conduct threat modeling during planning and participate in security design reviews.
- Mentor developers on secure coding practices (OWASP Top 10 / ASVS).
We value specialists who:
- Have a deep understanding of network security and architecture: segmentation, firewalls, VPN, mTLS, TLS, DNS, zero-trust, and traffic analysis.
- Have hands-on experience with SIEM solutions, including log collection, detection rule creation, and investigations (Wazuh / ELK / similar).
- Have strong expertise in cloud and infrastructure security, including hardening, IAM, IaC scanning, and secrets management, with confident knowledge of at least one cloud platform (GCP / AWS / Azure) and experience with bare-metal environments.
- Have practical experience in vulnerability management and remediation, including patching, upgrades, configuration, and code fixes.
- Have implemented SAST, DAST, SCA, and secret scanning solutions from scratch and integrated them into CI/CD pipelines (SonarQube, Semgrep, Snyk, Trivy, OWASP ZAP, gitleaks/detect-secrets, or similar).
- Are proficient in Python and Bash (Go will be a plus) for automation and remediation tasks.
- Have experience working with GitLab CI, GitHub Actions, Jenkins, or TeamCity.
- Have practical knowledge of Docker and Kubernetes.
Do you want to know some details about this position?
Anna will help!more details
YOUR JOURNEY WITH US:
- Step 1. Pre-screen.
- Step 2. Technical interview.
- Step 3. Interview.
- Step 4. Reference check.
- Step 5. Job Offer!
What you’ll get from working with us:
- Support for your career growth: compensation for external courses and conferences, access to our corporate library.
- Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
- Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
- 28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.
- Care for your health: medical insurance and compensation for psychologist sessions.
- Social initiatives: Ukrainian Victory Support program and other important projects.
- Regular team-building activities, online or offline.
What you’ll get from working with us:
Recommend a friend
apply
Haven’t found
a vacancy that
suits you?
Maybe we will find something to offer you
Send resume