
DevSecOps | WebTech
DevSecOps | WebTech We are looking for a DevSecOps to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects. Remote Full-time | DevOps Apply job description As a DevSecOps, you will: Vulnerability Management — full lifecycle (core responsibility) Detect vulnerabilities across all layers: code, dependencies, container images, IaC, configurations, and network. Prioritize vulnerabilities based on real risk (exploitability + exposure), not only CVSS. Perform hands-on remediation: dependency upgrades, patching, configuration hardening, and code changes through pull requests together with developers. Verify remediation (re-scan / re-test), track SLA compliance, and prevent regressions. Implement Security into CI/CD Deploy and integrate SAST, DAST, SCA, and secret scanning into CI/CD pipelines. Configure security gates to block deployments on critical findings and manage exceptions with assigned risk owners. Network Security & Architecture Implement segmentation, firewall policies, zero-trust access, VPN, egress filtering, and IMDS protection. Work with edge/WAF (Cloudflare): tune rules, anti-bot protection, and rate limiting for payment and gaming APIs. Review network architecture and perimeter security to identify dangerous exposures. Cloud & Infrastructure Security Assess and harden cloud and bare-metal infrastructure. Perform IaC scanning (Terraform / Helm / Kubernetes) for insecure configurations. Manage secrets and secret rotation (Vault / cloud secrets), eliminate hardcoded credentials. Harden IAM / SSO (OIDC/SAML, Keycloak). SIEM & Detection Engineering Build and maintain logging and audit pipelines, detection-as-code, and correlation rules (ELK-like solutions). Collaborate closely with the SOC team by providing detections for new findings instead of duplicating their work. Containers & Orchestration Scan container images (Trivy / Grype), implement RBAC and least privilege principles, configure network policies, runtime detection (Falco), and harden base images. Secure SDLC & Security Culture Conduct threat modeling during planning and participate in security design reviews. Mentor developers on secure coding practices (OWASP Top 10 / ASVS).
