1

Dast Tester Jobs in Alabama (NOW HIRING)

Plans and executes investigations and tests of considerable complexity, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application ...

Plans and executes investigations and tests of considerable complexity, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application ...

New

... testing, and deployment through the entire Continuous Integration and Continuous Deployment ... Experience with **application security tools** (SAST, DAST, vulnerability scanning)* Familiarity ...

next page

Showing results 1-20

Dast Tester information

What is a DAST tester?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What are the typical challenges faced by a DAST tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What cities in Alabama are hiring for Dast Tester jobs?

Cities in Alabama with the most Dast Tester job openings:

Software Assurance (SwA) Engineer

COLSA Corporation

Huntsville, AL

Full-time

Posted 6 days ago


Job description

COLSA Corporation is seeking an experienced Software Assurance (SwA) Engineer to join our team in Huntsville, Alabama. This role will support the security and integrity of complex software applications throughout the software development lifecycle (SDLC), with a focus on identifying vulnerabilities, conducting application security testing, and supporting software assessment, authorization, and readiness for materiel release.

The ideal candidate brings strong technical expertise in software assurance and application security, with the ability to analyze complex software systems, identify and assess security weaknesses, and develop effective solutions to mitigate risk.

Principal Duties and Responsibilities (*Essential functions)

  • Conducts Application Security Testing: Plans and executes investigations and tests of considerable complexity, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), fuzzing, and penetration testing.*

  • Vulnerability Analysis & Remediation: Analyzes source code and compiled binaries to identify security flaws, mapping findings to Common Weakness Enumerations (CWEs) and Common Vulnerabilities and Exposures (CVEs).*

  • Advanced Problem Solving: Develops and applies advanced methods, theories, and research techniques in the investigation and solution of complex and advanced software security problems.*

  • Project Coordination: Coordinates efforts of software engineers, development teams, and technical support staff in the performance of assigned SwA projects, ensuring security is integrated throughout the SDLC.*

  • Materiel Release Support: Plans, conducts, and technically directs major phases of significant SwA projects to ensure software meets the rigorous safety and security standards required for materiel release.*

  • Technical Review: Reviews the completion and implementation of technical products, ensuring that vulnerability remediations are effective and compliant with current security practices.*

  • Tool & Vendor Evaluation: May evaluate vendor capabilities and commercial/open-source SwA tools (e.g., Fortify, Coverity, Semgrep, Cppcheck, etc.) to provide required security testing products or services.

  • Industry Research: Reviews literature, patents, and current practices relevant to the solution of assigned application security projects and threat landscapes.*

  • Technical Leadership: May provide technical consultation to other organizations regarding secure coding practices and may provide work leadership to lower-level employees.

At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our “Family of Professionals!” Learn about our employee-centric culture and benefits here: https://www.colsa.com/culture_benefits  


Required Skills
Required Experience
  • Bachelors’ degree in Computer Science, Software Engineering, Cybersecurity, Information Systems, Engineering, or a related field (or equivalent experience).
  • Minimum of 8 years of related experience
  • Experience integrating security practices throughout the Software Development Lifecycle (SDLC).
  • Experience supporting software assessments, authorization, or materiel release activities
  • Hands-on experience performing application security testing, such as SAST, DAST, IAST, fuzzing, and/or penetration testing.
  • Ability to obtain and maintain a Secret Security Clearance prior to start; and willing and able to obtain a Top Secret clearance, if required by the customer
  • US Citizenship required 

Preferred Qualifications

  • Active Secret clearance
  • Proficiency in technical documentation, reporting, and vulnerability tracking using standard desktop applications, spreadsheets, and database/issue-tracking programs.
  • Working knowledge of modern operating systems (e.g., Linux, Windows) and programming languages common in defense and complex systems (e.g., C/C++, Java, Python, Ada, and Rust) to effectively analyze and secure diverse codebases.

Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. COLSA Corporation is an Equal Opportunity Employer, Minorities/Females/Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.