DevSecOps | WebTech

We are looking for a DevSecOps to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects.

Remote Full-time | DevOps
Apply

job description

As a DevSecOps, you will:

  • Vulnerability Management — full lifecycle (core responsibility)
  • Detect vulnerabilities across all layers: code, dependencies, container images, IaC, configurations, and network.
  • Prioritize vulnerabilities based on real risk (exploitability + exposure), not only CVSS.
  • Perform hands-on remediation: dependency upgrades, patching, configuration hardening, and code changes through pull requests together with developers.
  • Verify remediation (re-scan / re-test), track SLA compliance, and prevent regressions.
  • Implement Security into CI/CD
  • Deploy and integrate SAST, DAST, SCA, and secret scanning into CI/CD pipelines.
  • Configure security gates to block deployments on critical findings and manage exceptions with assigned risk owners.
  • Network Security & Architecture
  • Implement segmentation, firewall policies, zero-trust access, VPN, egress filtering, and IMDS protection.
  • Work with edge/WAF (Cloudflare): tune rules, anti-bot protection, and rate limiting for payment and gaming APIs.
  • Review network architecture and perimeter security to identify dangerous exposures.
  • Cloud & Infrastructure Security
  • Assess and harden cloud and bare-metal infrastructure.
  • Perform IaC scanning (Terraform / Helm / Kubernetes) for insecure configurations.
  • Manage secrets and secret rotation (Vault / cloud secrets), eliminate hardcoded credentials.
  • Harden IAM / SSO (OIDC/SAML, Keycloak).
  • SIEM & Detection Engineering
  • Build and maintain logging and audit pipelines, detection-as-code, and correlation rules (ELK-like solutions).
  • Collaborate closely with the SOC team by providing detections for new findings instead of duplicating their work.
  • Containers & Orchestration
  • Scan container images (Trivy / Grype), implement RBAC and least privilege principles, configure network policies, runtime detection (Falco), and harden base images.
  • Secure SDLC & Security Culture
  • Conduct threat modeling during planning and participate in security design reviews.
  • Mentor developers on secure coding practices (OWASP Top 10 / ASVS).

We value specialists who:

  • Have a deep understanding of network security and architecture: segmentation, firewalls, VPN, mTLS, TLS, DNS, zero-trust, and traffic analysis.
  • Have hands-on experience with SIEM solutions, including log collection, detection rule creation, and investigations (Wazuh / ELK / similar).
  • Have strong expertise in cloud and infrastructure security, including hardening, IAM, IaC scanning, and secrets management, with confident knowledge of at least one cloud platform (GCP / AWS / Azure) and experience with bare-metal environments.
  • Have practical experience in vulnerability management and remediation, including patching, upgrades, configuration, and code fixes.
  • Have implemented SAST, DAST, SCA, and secret scanning solutions from scratch and integrated them into CI/CD pipelines (SonarQube, Semgrep, Snyk, Trivy, OWASP ZAP, gitleaks/detect-secrets, or similar).
  • Are proficient in Python and Bash (Go will be a plus) for automation and remediation tasks.
  • Have experience working with GitLab CI, GitHub Actions, Jenkins, or TeamCity.
  • Have practical knowledge of Docker and Kubernetes.

Do you want to know some details about this position?

Anna will help!
more details
work

YOUR JOURNEY WITH US:

  • Step 1. Pre-screen.
  • Step 2. Technical interview.
  • Step 3. Interview.
  • Step 4. Reference check.
  • Step 5. Job Offer!
What you’ll get from working with us:
  • Support for your career growth: compensation for external courses and conferences, access to our corporate library.
  • Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
  • Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
  • 28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.
  • Care for your health: medical insurance and compensation for psychologist sessions.
  • Social initiatives: Ukrainian Victory Support program and other important projects.
  • Regular team-building activities, online or offline.

What you’ll get from working with us:

Recommend a friend
apply

Haven’t found
a vacancy that
suits you?

Maybe we will find something to offer you
Send resume
close
Contact
us
Thank you.
we’ll be in touch soon.
close
close
Apply for
a vacancie
or
We will consider your
application within 2 weeks.

Or maybe faster!
close
Recruiter

Anna
Polishchuk

Recruiter
close
ask a
question

Anna
Polishchuk

Recruiter
Thank you.
we’ll be in touch soon.
close
close
SEND YOUR CV
We will consider your
application within 2 weeks.

Or maybe faster!
close
close
SEND YOUR CV
We will consider your
application within 2 weeks.

Or maybe faster!
close
close
Recommend
a friend
or
We will consider your
application within 2 weeks.

Or maybe faster!
close