DevSecOps

RemoteSalary not specified
Warsaw, Poland · Kyiv, Ukraine · Lviv, Ukraine

Tech Stack

SDLC

Job Description, Responsibilities & Requirements

Description language:

About the Position

We are seeking a DevSecOps professional to join Boosta’s service team, focusing on vulnerability management, security integration, and cloud infrastructure security.

Remote | Full-time

Responsibilities

As a DevSecOps, you will:

  • Vulnerability Management - full lifecycle (core responsibility)
    • Detect vulnerabilities across all layers: code, dependencies, container images, IaC, configurations, and network.
    • Prioritize vulnerabilities based on real risk (exploitability + exposure), not only CVSS.
    • Perform hands-on remediation: dependency upgrades, patching, configuration hardening, and code changes through pull requests together with developers.
    • Verify remediation (re-scan / re-test), track SLA compliance, and prevent regressions.
  • Implement Security into CI/CD
    • Deploy and integrate SAST, DAST, SCA, and secret scanning into CI/CD pipelines.
    • Configure security gates to block deployments on critical findings and manage exceptions with assigned risk owners.
  • Network Security & Architecture
    • Implement segmentation, firewall policies, zero-trust access, VPN, egress filtering, and IMDS protection.
    • Work with edge/WAF (Cloudflare): tune rules, anti-bot protection, and rate limiting for payment and gaming APIs.
    • Review network architecture and perimeter security to identify dangerous exposures.
  • Cloud & Infrastructure Security
    • Assess and harden cloud and bare-metal infrastructure.
    • Perform IaC scanning (Terraform / Helm / Kubernetes) for insecure configurations.
    • Manage secrets and secret rotation (Vault / cloud secrets), eliminate hardcoded credentials.
    • Harden IAM / SSO (OIDC/SAML, Keycloak).
  • SIEM & Detection Engineering
    • Build and maintain logging and audit pipelines, detection-as-code, and correlation rules (ELK-like solutions).
    • Collaborate closely with the SOC team by providing detections for new findings instead of duplicating their work.
  • Containers & Orchestration
    • Scan container images (Trivy / Grype), implement RBAC and least privilege principles, configure network policies, runtime detection (Falco), and harden base images.
  • Secure SDLC & Security Culture
    • Conduct threat modeling during planning and participate in security design reviews.
    • Mentor developers on secure coding practices (OWASP Top 10 / ASVS).

Requirements

We value specialists who:

  • Have a deep understanding of network security and architecture: segmentation, firewalls, VPN, mTLS, TLS, DNS, zero-trust, and traffic analysis.
  • Have hands-on experience with SIEM solutions, including log collection, detection rule creation, and investigations (Wazuh / ELK / similar).
  • Have strong expertise in cloud and infrastructure security, including hardening, IAM, IaC scanning, and secrets management, with confident knowledge of at least one cloud platform (GCP / AWS / Azure) and experience with bare-metal environments.
  • Have practical experience in vulnerability management and remediation, including patching, upgrades, configuration, and code fixes.
  • Have implemented SAST, DAST, SCA, and secret scanning solutions from scratch and integrated them into CI/CD pipelines (SonarQube, Semgrep, Snyk, Trivy, OWASP ZAP, gitleaks/detect-secrets, or similar).
  • Are proficient in Python and Bash (Go will be a plus) for automation and remediation tasks.
  • Have experience working with GitLab CI, GitHub Actions, Jenkins, or TeamCity.
  • Have practical knowledge of Docker and Kubernetes.

We Offer

  • Support for your career growth: compensation for external courses and conferences, access to our corporate library.
  • Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
  • Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
  • 28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.
  • Care for your health: medical insurance and compensation for psychologist sessions.
  • Social initiatives: Ukrainian Victory Support program and other important projects.
  • Regular team-building activities, online or offline.

About the Company

Boosta’s service team provides design, development, content, and IT infrastructure creation & support services for the holding’s projects.

Your Journey with Us

  • Step 1. Pre-screen.
  • Step 2. Technical interview.
  • Step 3. Interview.
  • Step 4. Reference check.
  • Step 5. Job Offer!

Contact

For CV / career questions

[email protected]

For all other questions

[email protected]

Apply for a vacancy

Apply Here


Anna Polishchuk

Recruiter

Ask a question

Ask a Question

Send your CV

Send CV

Recommend a friend

Recommend a Friend

Job Details

Company name:
Boosta
Location:
Warsaw, Poland · Kyiv, Ukraine · Lviv, Ukraine
Employment Type:
Full-time
Work Mode:
Remote
Posted on TheJob:
Jul 29, 2026
Last checked:
Jul 29, 2026
Apply Now