1

Dast Tester Jobs in Florida (NOW HIRING)

Implement both SaaS-based security testing (SaaST) and dynamic application security testing (DAST) for major platforms. * Focus primarily on security and testing for core business systems: Salesforce ...

AppSec Sales Engineer - East

Tampa, FL · Remote

$55.50 - $74.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...

Senior SecDevOps Engineer

Tampa, FL · On-site

$108K - $148K/yr

Develop automated security validation processes including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container ...

New

Experience conducting penetration testing. * Strong understanding of: * OWASP Top 10 * OWASP API Top 10 * Authentication & Authorization * OAuth / OIDC * Secure SDLC * Experience with SAST, DAST, SCA ...

Senior Product Security Engineer

Miami, FL · On-site

$109K - $150K/yr

Experience conducting penetration testing. * Strong understanding of: * OWASP Top 10 * OWASP API Top 10 * Authentication & Authorization * OAuth / OIDC * Secure SDLC * Experience with SAST, DAST, SCA ...

AppSec Sales Engineer - East

Tampa, FL · On-site

$55.50 - $74.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...

AI DevSecOps Senior Engineer

Tampa, FL · Hybrid

$108K - $148K/yr

Define and implement secure SDLC practices, including automated testing, threat modeling, and ... Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline ...

AI DevSecOps Senior Engineer

Tampa, FL · Hybrid

$108K - $148K/yr

Define and implement secure SDLC practices, including automated testing, threat modeling, and ... Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline ...

AI DevSecOps Senior Engineer

Miami, FL · Hybrid

$109K - $150K/yr

Define and implement secure SDLC practices, including automated testing, threat modeling, and ... Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline ...

next page

Showing results 1-20

Dast Tester information

What is a DAST tester?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What are the typical challenges faced by a DAST tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What cities in Florida are hiring for Dast Tester jobs?

Cities in Florida with the most Dast Tester job openings:

Application Penetration Tester at ASM Research, An Accenture Federal Services Company Tallahass[...]

Hong Kong Study Skills Research Institute

Tallahassee, FL • On-site

$80 - $110/hr

Other

Posted 4 days ago


Job description

Application Penetration Tester – ASM Research, An Accenture Federal Services Company (Tallahassee, FL)

As an Application Security Penetration Tester, you will safeguard web applications and REST APIs from potential threats. Your role requires a deep understanding of the OWASP Top 10 and SANS 25 frameworks and involves performing thorough security assessments of third‑party libraries, analyzing dependencies, and conducting both automated and manual code reviews.

Responsibilities
  • Perform security assessments of third‑party libraries and conduct dependency analysis.
  • Conduct vulnerability assessments and manual/automated code reviews of Java and Scala applications.
  • Identify security issues such as CSRF, XSS, SQL Injection, and Privilege Escalation, and provide actionable remediation recommendations.
  • Use tools such as BurpSuite Pro, Postman/Bruno, SAST, DAST, and SCA to analyze scan reports and identify vulnerabilities across applications and platforms.
  • Execute static, dynamic, and penetration testing of web applications and REST APIs.
  • Write comprehensive reports detailing findings and proposing enhancements to bolster system security.
  • Serve as a liaison between development teams, stakeholders, and application owners to communicate and enforce application security best practices.
  • Participate in software security architecture and design reviews to integrate security from the ground up.
  • Integrate and automate security tools within DevOps CI/CD pipelines using scripting languages.
Qualifications
  • 3+ years of experience in secure code review, specifically with Scala, Java, JavaScript, and the Spring Framework.
  • 3+ years of practical experience with SAST and DAST.
  • 3+ years of hands‑on experience with manual penetration testing of web applications and REST APIs using BurpSuite Pro and Postman/Bruno.
  • Deep understanding of OWASP Top 10, SANS 25, secure coding best practices, and DevSecOps principles.
  • Proficiency in continuous integration and continuous deployment (CI/CD) concepts, AWS security principles, Jenkins, and GitHub.
  • Knowledge of scripting languages for integrating and automating security tools in DevOps pipelines.
  • Strong communication skills and the ability to translate security requirements into actionable practices.
Certifications
  • GPEN, GWAPT, OSCP, or CompTIA PenTest are desirable.

ASM is an equal‑opportunity employer. The policy of ASM is that an individual's race, color, religion, sex, disability, age, sexual orientation, or national origin are not and will not be considered in any personnel or management decisions. ASM affirms its commitment to these fundamental policies and to equal employment.

#J-18808-Ljbffr