Middle+/Senior DevSecOps Engineer
Boosta is looking for a Middle+/Senior DevSecOps Engineer to join its service team, which provides design, development, content, and IT infrastructure creation and support services for the holding’s projects.
The role involves managing the full lifecycle of vulnerabilities, integrating security into CI/CD pipelines, and maintaining operational security. The engineer will be responsible for launching, monitoring, and analysing scanning results across code, dependencies, containers, and IaC. They will triage findings, prioritise them based on real risk, and perform hands-on remediation by updating dependencies, applying patches, hardening configurations, and creating pull requests. The role also includes coordinating complex fixes with development teams, monitoring SLA compliance, and verifying remediation through re-scans. Additionally, the engineer will administer and maintain integrated SAST, DAST, SCA, and Secret Scanning tools, process security alerts, and investigate false positives. They will also review logs, work with existing SIEM/Wazuh rules, escalate incidents to the SOC, and tune existing WAF/Cloudflare rules.
- Launch, monitor, and analyse scanning results across code, dependencies, containers, and IaC.
- Triage findings and prioritise them based on real risk, not only CVSS.
- Perform hands-on remediation: update dependencies, apply patches, harden Docker/K8s/IaC configurations, and create pull requests in repositories without involving developers.
- Coordinate complex fixes with development teams, monitor SLA compliance, and verify remediation through re-scans.
- Administer and maintain already integrated SAST, DAST, SCA, and Secret Scanning tools.
- Process security alerts and investigate false positives.
- Review logs, work with existing SIEM/Wazuh rules, and escalate incidents to the SOC when needed.
- Tune existing WAF/Cloudflare rules according to established instructions and procedures.
- Hands-on experience with vulnerability management, including working with scanners such as Trivy, Snyk, SonarQube, Semgrep, OWASP ZAP, Gitleaks, and similar tools, and understand how they work (required).
- Practical remediation skills: can independently update a package, modify a Dockerfile, make changes to Terraform/Helm, or create a basic code PR in Python, JavaScript, or another language (required).
- Confidence with Bash and Python for automating routine tasks and interacting with scanner APIs (required).
- Practical experience with Docker and Kubernetes and understand CI/CD pipelines, such as GitLab CI, GitHub Actions, or Jenkins (required).
- Basic understanding of infrastructure and networking: Cloud (AWS/GCP/Azure), IAM, TLS, DNS, network segmentation, and firewall principles (required).
- Strong communication skills and can clearly assign tasks to developers, explain the criticality of a finding, and justify the need for remediation (required).
- Experience with an existing secrets management infrastructure such as Vault (nice-to-have).
- Basic understanding of SIEM, including log collection and reading existing detection rules (nice-to-have).
- Experience with Cloudflare (WAF/rate limiting) at the level of maintaining existing configurations (nice-to-have).
- Understand OWASP Top 10 and can explain the nature of vulnerabilities to developers (nice-to-have).
- Compensation for external courses and conferences.
- Access to our corporate library.
- Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
- Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
- 28 working days of paid vacation per year.
- Up to 30 days of sick leave with medical confirmation.
- All state holidays.
- Medical insurance.
- Compensation for psychologist sessions.
- Social initiatives: Ukrainian Victory Support program and other important projects.
- Regular team-building activities, online or offline.
Boosta is an international IT company that develops and promotes SEO tools, digital products and educational products, primarily for Western markets. Founded in 2014 and headquartered in Kyiv, Ukraine, it has released more than 10 products used by tens of thousands of people across Europe, Asia, the Americas and Australia. The company employs a team of over 400 specialists and runs an R&D department that backs startups and develops new products. Boosta operates across several verticals, including the iGaming affiliate space.