iGBA

DevSecOps | WebTech

27 JUL 2026

DevSecOps | WebTech We are looking for a DevSecOps to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects. Remote Full-time | DevOps Apply job description As a DevSecOps, you will: Vulnerability Management — full lifecycle (core responsibility) Detect vulnerabilities across all layers: code, dependencies, container images, IaC, configurations, and network. Prioritize vulnerabilities based on real risk (exploitability + exposure), not only CVSS. Perform hands-on remediation: dependency upgrades, patching, configuration hardening, and code changes through pull requests together with developers. Verify remediation (re-scan / re-test), track SLA compliance, and prevent regressions. Implement Security into CI/CD Deploy and integrate SAST, DAST, SCA, and secret scanning into CI/CD pipelines. Configure security gates to block deployments on critical findings and manage exceptions with assigned risk owners. Network Security & Architecture Implement segmentation, firewall policies, zero-trust access, VPN, egress filtering, and IMDS protection. Work with edge/WAF (Cloudflare): tune rules, anti-bot protection, and rate limiting for payment and gaming APIs. Review network architecture and perimeter security to identify dangerous exposures. Cloud & Infrastructure Security Assess and harden cloud and bare-metal infrastructure. Perform IaC scanning (Terraform / Helm / Kubernetes) for insecure configurations. Manage secrets and secret rotation (Vault / cloud secrets), eliminate hardcoded credentials. Harden IAM / SSO (OIDC/SAML, Keycloak). SIEM & Detection Engineering Build and maintain logging and audit pipelines, detection-as-code, and correlation rules (ELK-like solutions). Collaborate closely with the SOC team by providing detections for new findings instead of duplicating their work. Containers & Orchestration Scan container images (Trivy / Grype), implement RBAC and least privilege principles, configure network policies, runtime detection (Falco), and harden base images. Secure SDLC & Security Culture Conduct threat modeling during planning and participate in security design reviews. Mentor developers on secure coding practices (OWASP Top 10 / ASVS).

We value specialists who:
Have a deep understanding of network security and architecture: segmentation, firewalls, VPN, mTLS, TLS, DNS, zero-trust, and traffic analysis.
Have hands-on experience with SIEM solutions, including log collection, detection rule creation, and investigations (Wazuh / ELK / similar).
Have strong expertise in cloud and infrastructure security, including hardening, IAM, IaC scanning, and secrets management, with confident knowledge of at least one cloud platform (GCP / AWS / Azure) and experience with bare-metal environments.
Have practical experience in vulnerability management and remediation, including patching, upgrades, configuration, and code fixes.
Have implemented SAST, DAST, SCA, and secret scanning solutions from scratch and integrated them into CI/CD pipelines (SonarQube, Semgrep, Snyk, Trivy, OWASP ZAP, gitleaks/detect-secrets, or similar).
Are proficient in Python and Bash (Go will be a plus) for automation and remediation tasks.
Have experience working with GitLab CI, GitHub Actions, Jenkins, or TeamCity.
Have practical knowledge of Docker and Kubernetes.
Do you want to know some details about this position?
Anna will help!
more details
work
YOUR JOURNEY WITH US:
Step 1. Pre-screen.
Step 2. Technical interview.
Step 3. Interview.
Step 4. Reference check.
Step 5. Job Offer!
Support for your career growth: compensation for external courses and conferences, access to our corporate library.
Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.
Care for your health: medical insurance and compensation for psychologist sessions.
Social initiatives: Ukrainian Victory Support program and other important projects.
Regular team-building activities, online or offline.
What you’ll get from working with us:
Recommend a friend
apply
Haven’t found
a vacancy that
suits you?
Maybe we will find something to offer you
Send resume
For CV / career questions
cv@boosta.co
For all other questions
pr@boosta.co