Middle+/Senior DevSecOps Engineer | WebTech
We are looking for a Middle+/Senior DevSecOps Engineer to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects.
Remote Full-time | DevOps
Apply
job description
As a Middle+/Senior DevSecOps Engineer, you will:
- Vulnerability Management — full lifecycle:
- Launch, monitor, and analyze scanning results across code, dependencies, containers, and IaC.
- Triage findings and prioritize them based on real risk, not only CVSS.
- Perform hands-on remediation: update dependencies, apply patches, harden Docker/K8s/IaC configurations, and create pull requests in repositories without involving developers.
- Coordinate complex fixes with development teams, monitor SLA compliance, and verify remediation through re-scans.
- Security in CI/CD:
- Administer and maintain already integrated SAST, DAST, SCA, and Secret Scanning tools.
- Process security alerts and investigate false positives.
- Monitoring and Operational Security:
- Review logs, work with existing SIEM/Wazuh rules, and escalate incidents to the SOC when needed.
- Tune existing WAF/Cloudflare rules according to established instructions and procedures.
We value specialists who:
- Have hands-on experience with vulnerability management, including working with scanners such as Trivy, Snyk, SonarQube, Semgrep, OWASP ZAP, Gitleaks, and similar tools, and understand how they work.
- Have practical remediation skills: can independently update a package, modify a Dockerfile, make changes to Terraform/Helm, or create a basic code PR in Python, JavaScript, or another language.
- Are confident with Bash and Python for automating routine tasks and interacting with scanner APIs.
- Have practical experience with Docker and Kubernetes and understand CI/CD pipelines, such as GitLab CI, GitHub Actions, or Jenkins.
- Have a basic understanding of infrastructure and networking: Cloud (AWS/GCP/Azure), IAM, TLS, DNS, network segmentation, and firewall principles.
- Have strong communication skills and can clearly assign tasks to developers, explain the criticality of a finding, and justify the need for remediation.
- Will be a plus:
- Experience with an existing secrets management infrastructure such as Vault will be a plus.
- Have a basic understanding of SIEM, including log collection and reading existing detection rules.
- Experience with Cloudflare (WAF/rate limiting) at the level of maintaining existing configurations will be a plus.
- Understand OWASP Top 10 and can explain the nature of vulnerabilities to developers.
Do you want to know some details about this position?
Dina will help!more details
Your journey with us:
- Step 1. Pre-screen.
- Step 2. Technical interview.
- Step 3. Interview.
- Step 4. Reference check.
- Step 5. Job Offer!
What you’ll get from working with us:
- Support for your career growth: compensation for external courses and conferences, access to our corporate library.
- Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
- Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
- 28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.
- Care for your health: medical insurance and compensation for psychologist sessions.
- Social initiatives: Ukrainian Victory Support program and other important projects.
- Regular team-building activities, online or offline.
What you’ll get from working with us:
Recommend a friend
apply
Haven’t found
a vacancy that
suits you?
Maybe we will find something to offer you
Send resume