1

Dast Tester Jobs in Arizona (NOW HIRING)

Manager - Application & AI Security

Scottsdale, AZ · On-site

$58.75 - $78.25/hr

Lead application security testing across SAST, DAST, software composition analysis (SCA), secrets detection, API security, and related capabilities. * Establish API security practices aligned with ...

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

... DAST, SCA) or manual analysis. * Manage application security workflows, including task ... Perform adversarial testing and security validation of applications, including internal AI models ...

Scrum Master

Phoenix, AZ · On-site

$70 - $75/hr

... testing, SAST, DAST, performance testing Technology operations knowledge transfer & turnover Cloud Infrastructure work Vendor Implementation Management : Assist vendor onboarding teams with coothe ...

... IAST, OSS, DAST, RASP, and vulnerability management, etc * Deep understanding of information ... Coordinate security assessments and penetration testing activities between third-party vendors ...

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

... DAST, SCA) or manual analysis. * Manage application security workflows, including task ... Perform adversarial testing and security validation of applications, including internal AI models ...

... Security testing methodologies (SAST, DAST, SCA, API security) • Familiarity with enterprise security tools and platforms • Ability to interpret vulnerability data, CVSS scoring, and ...

Application Security Engineer

Phoenix, AZ · On-site

$58.25 - $78/hr

... DAST, SCA) or manual analysis. * Manage application security workflows, including task ... Perform adversarial testing and security validation of applications, including internal AI models ...

Exposure to penetration testing engagements - scoping, vendor coordination, findings review, retest ... SAST/DAST/SCA, dependency and supply chain risk, threat modelling #J-18808-Ljbffr

New

Strong application security testing across SAST, DAST, SCA, secrets scanning, and API security (Checkmarx, Veracode, Snyk). * Knowledge of API security architecture and standards such as OAuth2 ...

Cyber Manager - Cloud DevSecOps

Tempe, AZ

$106K - $143K/yr

Guide integration of Application Security capabilities including SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, penetration testing, and ...

next page

Showing results 1-20

Dast Tester information

What is a DAST tester?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What are the typical challenges faced by a DAST tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What are popular job titles related to Dast Tester jobs in Arizona?

For Dast Tester jobs in Arizona, the most frequently searched job titles are:

What job categories do people searching Dast Tester jobs in Arizona look for?

The top searched job categories for Dast Tester jobs in Arizona are:

What cities in Arizona are hiring for Dast Tester jobs?

Cities in Arizona with the most Dast Tester job openings:

Manager - Application & AI Security

Prosum Inc.

Scottsdale, AZ • On-site

$58.75 - $78.25/hr

Other

Posted 20 days ago


Job description

Job Description
Manager, Application & AI Security
Location: Scottsdale, AZ (hybrid)
About the Role
We are seeking a Manager, Application & AI Security to lead the security of internally developed applications, cloud application environments, CI/CD pipelines, and enterprise AI usage.
This role will establish and operate secure-by-default practices across the software development lifecycle while serving as a central technical leader for AI security and governance. The ideal candidate brings strong hands-on experience in application security and DevSecOps, along with a practical understanding of emerging AI security risks.
You will build security guardrails into development and deployment processes, oversee application security testing, manage AI and model inventories, assess prompt-injection and jailbreak risks, and establish controls for MCPs and AI-agent runtimes.
This is a highly technical leadership role focused on building scalable security capabilities rather than simply reviewing or documenting controls.
What You'll DoApplication Security & DevSecOps
  • Lead the secure software development lifecycle, incorporating NIST SSDF and ISO/IEC 27001 practices.
  • Establish application security requirements and conduct security reviews for major releases and critical applications.
  • Build and maintain secure CI/CD "golden pipelines," embedding security guardrails directly into development and deployment workflows.
  • Implement pipeline and artifact integrity controls and monitor production pipelines for security risks.
  • Lead application security testing across SAST, DAST, software composition analysis (SCA), secrets detection, API security, and related capabilities.
  • Establish API security practices aligned with OWASP standards, including the OWASP Top 10 and API Security Top 10.
  • Oversee container, Kubernetes, and Infrastructure-as-Code security scanning.
  • Lead application threat modeling and secure-code development practices.
  • Establish and maintain SBOM generation for internally developed applications.
  • Develop and deliver secure development training for engineering teams.
  • Establish application- and PaaS-level cloud security guardrails in partnership with cloud and infrastructure teams.
  • Provide application and cloud security expertise during broader technology and security reviews.
  • Help establish security guardrails for customer-facing platforms, workflows, and contact-center technologies.
AI Security & Governance
  • Serve as the technical owner for enterprise AI security controls and AI usage governance.
  • Establish controls for LLM and AI assistant usage, including public and internally hosted models.
  • Identify and manage risks associated with shadow AI, unauthorized AI tools, and potential data leakage.
  • Maintain an enterprise AI/model inventory, AI bill of materials (AI-BOM), model registry, and approval workflows.
  • Assess AI applications and models for security risks before production use.
  • Conduct prompt-injection and jailbreak testing and lead LLM security red-teaming.
  • Apply relevant AI security practices, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Establish security controls for MCPs (Model Context Protocol) and AI-agent runtimes, including per-tool authorization, runtime guardrails, and containment.
  • Partner with governance, risk, compliance, data security, identity, infrastructure, and other teams to ensure AI security controls are implemented effectively.
  • Translate emerging AI security risks into practical technical controls and repeatable processes.
Key Initiatives
  • Enterprise AI Governance & Shadow AI: Establish AI usage policies, discovery, risk assessment, and security controls.
  • Secure CI/CD Golden Pipelines: Build DevSecOps guardrails-as-code and automated blocking of critical security findings.
  • Cloud Application Security: Strengthen security controls across cloud tenants, SaaS, and PaaS environments.
  • AI Agent & MCP Security: Develop runtime security capabilities for AI agents and tool integrations, including authorization and containment.
What Success Looks Like
In this role, success will include:
  • AI tools are risk-assessed and governed before approved enterprise use.
  • Shadow AI is identified, assessed, and addressed within established service levels.
  • Production CI/CD pipelines are covered by security guardrails and monitoring.
  • Major application releases receive appropriate security reviews.
  • Critical application security findings are prevented from reaching production.
  • SAST, DAST, SCA, API security, and secrets scanning are automated across applicable development pipelines.
  • AI/model inventories and approval workflows are accurate, current, and operational.
  • Prompt-injection, jailbreak, and AI-agent security risks are regularly assessed.
  • Application and AI security practices are embedded into engineering workflows rather than operating as a separate manual review process.
What We're Looking For
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
  • 5+ years of experience in application security, DevSecOps, software security, or a closely related discipline.
  • Experience leading or mentoring security engineers or technical security teams.
  • Hands-on experience building security controls into CI/CD pipelines and development workflows.
  • Experience with CI/CD platforms such as Azure DevOps, GitHub Actions, GitLab, Jenkins, or similar technologies.
  • Strong experience with application security testing, including SAST, DAST, SCA/open-source security, secrets scanning, and API security.
  • Strong understanding of API security architecture and standards, including OAuth 2.0, OWASP, and related security practices.
  • Experience securing containers, Kubernetes environments, and Infrastructure-as-Code.
  • Experience with threat modeling and software supply-chain security, including SBOMs.
  • Practical experience with AI/LLM security, including AI usage governance, prompt-injection and jailbreak testing, red-teaming, or AI-agent security.
  • Understanding of AI security and governance frameworks such as NIST AI RMF and ISO/IEC 42001.
  • Familiarity with NIST and ISO/IEC 27001 security frameworks and practices.
  • Experience translating complex technical security issues into clear recommendations for technical and non-technical audiences.
  • Strong communication, collaboration, prioritization, and problem-solving skills.
Helpful Experience
  • Familiarity with AI productivity and development tools such as Claude, GitHub Copilot, or similar platforms.
  • Experience securing MCPs or AI-agent architectures.
  • Experience with AI/model registries, AI inventories, or AI-BOM initiatives.
  • Experience with security platforms and tools such as Checkmarx, Veracode, Snyk, or comparable solutions.
  • CISSP or another relevant security certification is preferred. Additional certifications such as CSSLP, CCSP, or CISM are a plus.

Please view our Privacy Policy.