Middle+/Senior DevSecOps Engineer | WebTech

IGB Affiliate

Warszawa

Hybrid

PLN 180,000 - 260,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical insurance
Paid vacation (28 days)
Flexible schedule
External courses & conferences support
Corporate library access

Job summary

Boosta is seeking a Middle+/Senior DevSecOps Engineer to join the service team. The role focuses on full lifecycle vulnerability management, security in CI/CD, and operational security across cloud infrastructure.

You will coordinate fixes with development teams, tune WAF/Cloudflare rules, and help maintain SAST/DAST/SCA tooling. The position offers remote, full-time work with flexible hours and opportunities for career growth, including external courses and library access.

Qualifications

  • Hands-on vulnerability management using scanners and remediation skills.
  • Ability to triage findings by real risk and coordinate fixes with dev teams.

Responsibilities

  • Lead vulnerability management across code, dependencies, containers, and IaC.
  • Manage and improve SAST/DAST/SCA/Secret scanning in CI/CD.
  • Triage security alerts, investigate false positives, and document remediation steps.
  • Tune and maintain WAF/Cloudflare rules and monitor SIEM/Wazuh rules.
  • Collaborate with developers to implement fixes and verify remediation.

Skills

Vulnerability management
Remediation skills
CI/CD security
Scripting (Bash/Python)
Communication & task assignment

Tools

Trivy
Snyk
SonarQube
Semgrep
OWASP ZAP
Gitleaks
Docker
Kubernetes
Terraform
Helm
GitLab CI
GitHub Actions
Jenkins
Bash
Python
AWS
GCP
Azure

Job description

Middle+/Senior DevSecOps Engineer | WebTech We are looking for a Middle+/Senior DevSecOps Engineer to join Boosta’s service team, which provides design, development, content, and IT infrastructure creation & support services for the holding’s projects. Remote Full-time | DevOps Apply job description As a Middle+/Senior DevSecOps Engineer, you will: Vulnerability Management — full lifecycle: Launch, monitor, and analyze scanning results across code, dependencies, containers, and IaC. Triage findings and prioritize them based on real risk, not only CVSS. Perform hands-on remediation: update dependencies, apply patches, harden Docker/K8s/IaC configurations, and create pull requests in repositories without involving developers. Coordinate complex fixes with development teams, monitor SLA compliance, and verify remediation through re-scans. Security in CI/CD: Administer and maintain already integrated SAST, DAST, SCA, and Secret Scanning tools. Process security alerts and investigate false positives. Monitoring and Operational Security: Review logs, work with existing SIEM/Wazuh rules, and escalate incidents to the SOC when needed. Tune existing WAF/Cloudflare rules according to established instructions and procedures..We value specialists who: Have hands-on experience with vulnerability management, including working with scanners such as Trivy, Snyk, SonarQube, Semgrep, OWASP ZAP, Gitleaks, and similar tools, and understand how they work. Have practical remediation skills: can independently update a package, modify a Dockerfile, make changes to Terraform/Helm, or create a basic code PR in Python, JavaScript, or another language. Are confident with Bash and Python for automating routine tasks and interacting with scanner APIs. Have practical experience with Docker and Kubernetes and understand CI/CD pipelines, such as GitLab CI, GitHub Actions, or Jenkins. Have a basic understanding of infrastructure and networking: Cloud (AWS/GCP/Azure), IAM, TLS, DNS, network segmentation, and firewall principles. Have strong communication skills and can clearly assign tasks to developers, explain the criticality of a finding, and justify the need for remediation. Will be a plus: Experience with an existing secrets management infrastructure such as Vault will be a plus. Have a basic understanding of SIEM, including log collection and reading existing detection rules. Experience with Cloudflare (WAF/rate limiting) at the level of maintaining existing configurations will be a plus. Understand OWASP Top 10 and can explain the nature of vulnerabilities to developers. Do you want to know some details about this position? Dina will help! more details work Your journey with us: Step 1. Pre-screen. Step 2. Technical interview. Step 3. Interview. Step 4. Reference check. Step 5. Job Offer! Support for your career growth: compensation for external courses and conferences, access to our corporate library. Flexible schedule: you can start your working day anytime between 8:00–11:00 Kyiv time. Work location of your choice: Kyiv office, coworking in Lviv or Warsaw, or fully remote. 28 working days of paid vacation per year, up to 30 days of sick leave with medical confirmation, plus all state holidays. Care for your health: medical insurance and compensation for psychologist sessions. Social initiatives: Ukrainian Victory Support program and other important projects. Regular team-building activities, online or offline. What you’ll get from working with us: Recommend a friend apply Haven’t found a vacancy that suits you? Maybe we will find something to offer you Send resume For CV / career questions cv@boosta.co For all other questions pr@boosta.co
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps | WebTech
DevSecOps | WebTech

Igbaffiliate • Warszawa

On-site
PLN 180,000 - 280,000
Medical insurance
Career development budget
Flexible schedule
+2
Remote DevSecOps Engineer (Mid/Senior) - CI/CD Security
Remote DevSecOps Engineer (Mid/Senior) - CI/CD Security

IGB Affiliate • Warszawa

Hybrid
PLN 180,000 - 260,000
Medical insurance
Paid vacation (28 days)
Flexible schedule
+2
Senior DevOps Engineer NEW
Senior DevOps Engineer NEW

Jit • Poznań

Hybrid
PLN 200,000 - 320,000
Hybrid work model
International work environment
Community events
Middle L1 Technical Support Specialist
Middle L1 Technical Support Specialist

your Jared • Warszawa

On-site
PLN 54,000 - 74,000
Cafeteria
Annual budget for sports, medical care
Senior DevOps Engineer
Senior DevOps Engineer

TKH Technology • Poland

On-site
PLN 223,000 - 257,000
Laptop
Remote work options
Competitive salary
Senior DevOps Engineer
Senior DevOps Engineer

Tkhtechnology • Wrocław

On-site
PLN 212,040 - 301,320
Laptop (Windows/Mac)
O’Reilly platform
Multisport
+3
Senior SecOps Engineer – Security Specialist
Senior SecOps Engineer – Security Specialist

your Jared • Kraków

Hybrid
PLN 180,000 - 240,000
Private medical care
Sports card
Training courses
+1
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Talan Group • Warszawa

On-site
PLN 210,526 - 315,789
Private medical insurance
Life insurance
Training and career development
+1
Senior Security Engineer
Senior Security Engineer

your Jared • Łódź

On-site
PLN 120,000 - 180,000
Senior DevOps Engineer (Remote)
Senior DevOps Engineer (Remote)

Reppls (Techstars '24) • Polska

Remote
PLN 240,000 - 360,000
Equity incentive
Unlimited vacation
Health insurance reimbursement
+2