2,818 Open roles
102 Companies
95 Posted today
Jobs / Boosta / DevSecOps | WebTech
Posted 2026-07-27

DevSecOps | WebTech

Description

Boosta is looking for a DevSecOps professional to join its service team. This team provides design, development, content, and IT infrastructure creation and support services for the holding's various projects.

Responsibilities
  • Manage the full lifecycle of vulnerability management, including detection across code, dependencies, container images, IaC, configurations, and network.
  • Prioritise vulnerabilities based on real risk and perform hands-on remediation through dependency upgrades, patching, configuration hardening, and code changes.
  • Verify remediation, track SLA compliance, and prevent regressions.
  • Implement and integrate security tools such as SAST, DAST, SCA, and secret scanning into CI/CD pipelines.
  • Configure security gates to block deployments on critical findings and manage exceptions.
  • Implement network security measures including segmentation, firewall policies, zero-trust access, VPN, egress filtering, and IMDS protection.
  • Tune edge and WAF rules, anti-bot protection, and rate limiting for payment and gaming APIs.
  • Review network architecture and perimeter security to identify exposures.
  • Assess and harden cloud and bare-metal infrastructure.
  • Perform IaC scanning for insecure configurations and manage secrets and rotation.
  • Harden IAM and SSO configurations.
  • Build and maintain logging and audit pipelines, detection-as-code, and correlation rules.
  • Collaborate with the SOC team to provide detections for new findings.
  • Scan container images, implement RBAC and least privilege principles, and configure runtime detection.
  • Conduct threat modelling and participate in security design reviews.
  • Mentor developers on secure coding practices.
Requirements
  • Deep understanding of network security and architecture including segmentation, firewalls, VPN, mTLS, TLS, DNS, zero-trust, and traffic analysis (required).
  • Hands-on experience with SIEM solutions, including log collection, detection rule creation, and investigations (required).
  • Strong expertise in cloud and infrastructure security, including hardening, IAM, IaC scanning, and secrets management (required).
  • Confident knowledge of at least one cloud platform such as GCP, AWS, or Azure (required).
  • Experience with bare-metal environments (required).
  • Practical experience in vulnerability management and remediation (required).
  • Experience implementing SAST, DAST, SCA, and secret scanning solutions from scratch and integrating them into CI/CD pipelines (required).
  • Proficiency in Python and Bash (required).
  • Experience with Go (nice-to-have).
  • Experience working with GitLab CI, GitHub Actions, Jenkins, or TeamCity (required).
  • Practical knowledge of Docker and Kubernetes (required).
Benefits
  • Compensation for external courses and conferences.
  • Access to a corporate library.
  • Flexible working schedule with start times between 8:00 and 11:00 Kyiv time.
  • Choice of work location including Kyiv office, coworking in Lviv or Warsaw, or fully remote.
  • 28 working days of paid vacation per year.
  • Up to 30 days of sick leave with medical confirmation.
  • Medical insurance and compensation for psychologist sessions.
  • Participation in social initiatives and the Ukrainian Victory Support program.
  • Regular team-building activities.
About Boosta

Boosta is an international IT company that develops and promotes SEO tools, digital products and educational products, primarily for Western markets. Founded in 2014 and headquartered in Kyiv, Ukraine, it has released more than 10 products used by tens of thousands of people across Europe, Asia, the Americas and Australia. The company employs a team of over 400 specialists and runs an R&D department that backs startups and develops new products. Boosta operates across several verticals, including the iGaming affiliate space.

Read more about Boosta →

Apply on Boosta →