{"id":2169004,"url":"https://alion.io/job/boosta-middlesenior-devsecops-engineer-webtech","title":"Middle+/Senior DevSecOps Engineer | TechCore","company":{"id":3839329,"name":"Boosta","domain":"boosta.com","url":"https://alion.io/company/boosta-2","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Kyiv, Ukraine","Lviv, Ukraine","Ukraine"],"countries":["UA"],"hiring_countries":["UA"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":37000,"max_usd":85000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1824},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"Cloudflare","optional":false},{"name":"CVSS","optional":false},{"name":"DNS","optional":false},{"name":"Docker","optional":false},{"name":"GCP","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab CI","optional":false},{"name":"Gitleaks","optional":false},{"name":"Helm","optional":false},{"name":"IAM","optional":false},{"name":"JavaScript","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Python","optional":false},{"name":"Semgrep","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Snyk","optional":false},{"name":"SonarQube","optional":false},{"name":"Terraform","optional":false},{"name":"Trivy","optional":false},{"name":"Wazuh","optional":false}],"status":"live","first_seen_at":"2026-10-09T09:59:27Z","employer_posted_date":"2026-10-09","last_verified_at":"2026-10-11T20:23:52Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Hi!\nWe are Boosta, a holding tech company that creates, develops, and invests in digital businesses with global potential. Today, we collaborate with over 800 specialists from different parts of the world, and millions of users use our products and services.\nWe are looking for a Middle+/Senior DevSecOps Engineer to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects.\nKey facts about TechCore:\n50+ skilled professionals;\n300+ projects per year;\ndiverse project portfolio.\nAs a Middle+/Senior DevSecOps Engineer, you will:\nVulnerability Management - full lifecycle:\nLaunch, monitor, and analyze scanning results across code, dependencies, containers, and IaC.\nTriage findings and prioritize them based on real risk, not only CVSS.\nPerform hands-on remediation: update dependencies, apply patches, harden Docker/K8s/IaC configurations, and create pull requests in repositories without involving developers.\nCoordinate complex fixes with development teams, monitor SLA compliance, and verify remediation through re-scans.\nSecurity in CI/CD:\nAdminister and maintain already integrated SAST, DAST, SCA, and Secret Scanning tools.\nProcess security alerts and investigate false positives.\nMonitoring and Operational Security:\nReview logs, work with existing SIEM/Wazuh rules, and escalate incidents to the SOC when needed.\nTune existing WAF/Cloudflare rules according to established instructions and procedures.\nWe value specialists who:\nHave hands-on experience with vulnerability management, including working with scanners such as Trivy, Snyk, SonarQube, Semgrep, OWASP ZAP, Gitleaks, and similar tools, and understand how they work.\nHave practical remediation skills: can independently update a package, modify a Dockerfile, make changes to Terraform/Helm, or create a basic code PR in Python, JavaScript, or another language.\nAre confident with Bash and Python for automating routine tasks and interacting with scanner APIs.\nHave practical experience with Docker and Kubernetes and understand CI/CD pipelines, such as GitLab CI, GitHub Actions, or Jenkins.\nHave a basic understanding of infrastructure and networking: Cloud (AWS/GCP/Azure), IAM, TLS, DNS, network segmentation, and firewall principles.\nHave strong communication skills and can clearly assign tasks to developers, explain the criticality of a finding, and justify the need for remediation.\nWill be a plus:\nExperience with an existing secrets management infrastructure such as Vault will be a plus.\nHave a basic understanding of SIEM, including log collection and reading existing detection rules.\nExperience with Cloudflare (WAF/rate limiting) at the level of maintaining existing configurations will be a plus.\nUnderstand OWASP Top 10 and can explain the nature of vulnerabilities to developers.\nYour journey with us:\nStep 1. Pre-screen.\nStep 2. Technical interview.\nStep 3. Interview.\nStep 4. Reference check.\nStep 5. Job Offer!\nWhat you’ll get from working with us:\nSupport for your career growth: compensation for external courses and conferences, access to our corporate library.\nFlexible schedule: you can start your working day anytime between 8:00-11:00 Kyiv time.\nWork location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote.\n28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays.\nCare for your health: medical insurance and compensation for psychologist sessions.\nSocial initiatives: Ukrainian Victory Support program and other important projects.\nRegular team-building activities, online or offline.\nExcited by the opportunity to work with an expert team and diverse clients?\nSend us your CV and let’s do great things together!","description_format":"text","description_chars":3797,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Flexible schedule","Health insurance"],"hiring_locations":[{"name":"Ukraine","iso":"UA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","EdTech Platforms","Digital Marketing"],"lifecycle":[{"event":"open","at":"2026-10-09T11:18:06Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":8,"reasons":["conf:2","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/boosta-middlesenior-devsecops-engineer-webtech","json_url":"https://alion.io/job/boosta-middlesenior-devsecops-engineer-webtech.json","meta":{"generated_at":"2026-10-11T23:20:08Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":14282,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3839329},"rest":"https://alion.io/mcp/rest/get_company?id=3839329"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fboosta-middlesenior-devsecops-engineer-webtech"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fboosta-middlesenior-devsecops-engineer-webtech"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fboosta-middlesenior-devsecops-engineer-webtech"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/boosta-middlesenior-devsecops-engineer-webtech\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fboosta-middlesenior-devsecops-engineer-webtech"}]}