Skip to content

Open nowPosted 2 hours agoWe saw it 21 min after it went up

Middle+/Senior DevSecOps Engineer | WebTech

Boosta54 open roles

Where
Remote, Ukraine
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowMiddle+/Senior DevSecOps Engineer | WebTechBoosta · Remote, Ukraine
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Boosta's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Boosta postings stay open a median of 8 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 2 hours ago

Boosta median: 8 days open

The posting

Hi!

We are Boosta, a holding tech company that creates, develops, and invests in digital businesses with global potential. Today, we collaborate with over 800 specialists from different parts of the world, and millions of users use our products and services.

We are looking for a Middle+/Senior DevSecOps Engineer to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects.

As a Middle+/Senior DevSecOps Engineer, you will:

Vulnerability Management — full lifecycle:

  • Launch, monitor, and analyze scanning results across code, dependencies, containers, and IaC.
  • Triage findings and prioritize them based on real risk, not only CVSS.
  • Perform hands-on remediation: update dependencies, apply patches, harden Docker/K8s/IaC configurations, and create pull requests in repositories without involving developers.
  • Coordinate complex fixes with development teams, monitor SLA compliance, and verify remediation through re-scans.

Security in CI/CD:

  • Administer and maintain already integrated SAST, DAST, SCA, and Secret Scanning tools.
  • Process security alerts and investigate false positives.

Monitoring and Operational Security:

  • Review logs, work with existing SIEM/Wazuh rules, and escalate incidents to the SOC when needed.
  • Tune existing WAF/Cloudflare rules according to established instructions and procedures.

We value specialists who:

  • Have hands-on experience with vulnerability management, including working with scanners such as Trivy, Snyk, SonarQube, Semgrep, OWASP ZAP, Gitleaks, and similar tools, and understand how they work.
  • Have practical remediation skills: can independently update a package, modify a Dockerfile, make changes to Terraform/Helm, or create a basic code PR in Python, JavaScript, or another language.
  • Are confident with Bash and Python for automating routine tasks and interacting with scanner APIs.
  • Have practical experience with Docker and Kubernetes and understand CI/CD pipelines, such as GitLab CI, GitHub Actions, or Jenkins.
  • Have a basic understanding of infrastructure and networking: Cloud (AWS/GCP/Azure), IAM, TLS, DNS, network segmentation, and firewall principles.
  • Have strong communication skills and can clearly assign tasks to developers, explain the criticality of a finding, and justify the need for remediation.

Will be a plus:

  • Experience with an existing secrets management infrastructure such as Vault will be a plus.
  • Have a basic understanding of SIEM, including log collection and reading existing detection rules.
  • Experience with Cloudflare (WAF/rate limiting) at the level of maintaining existing configurations will be a plus.
  • Understand OWASP Top 10 and can explain the nature of vulnerabilities to developers.

Your journey with us:

  • Step 1. Pre-screen.
  • Step 2. Technical interview.
  • Step 3. Interview.
  • Step 4. Reference check.
  • Step 5. Job Offer!

What you’ll get from working with us:

  • Support for your career growth: compensation for external courses and conferences, access to our corporate library.
  • Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time.
  • Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.
  • 28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.
  • Care for your health: medical insurance and compensation for psychologist sessions.
  • Social initiatives: Ukrainian Victory Support program and other important projects.
  • Regular team-building activities, online or offline.

Excited by the opportunity to work with an expert team and diverse clients? Send us your CV and let’s do great things together!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Boosta's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Boosta's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Boosta's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.