1

Dast Tester Jobs in Florida (NOW HIRING)

Implement both SaaS-based security testing (SaaST) and dynamic application security testing (DAST) for major platforms. * Focus primarily on security and testing for core business systems: Salesforce ...

Senior SecDevOps Engineer

Tampa, FL · On-site

$108K - $148K/yr

Develop automated security validation processes including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container ...

AppSec Sales Engineer - East

Tampa, FL · Remote

$55.50 - $74.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...

Senior Product Security Engineer

Miami, FL · On-site

$109K - $150K/yr

Experience conducting penetration testing. * Strong understanding of: * OWASP Top 10 * OWASP API Top 10 * Authentication & Authorization * OAuth / OIDC * Secure SDLC * Experience with SAST, DAST, SCA ...

Senior .NET Software Engineer

Tampa, FL · On-site

$115K - $152K/yr

... testing, or monitoring). * Debug and troubleshoot production issues using Grafana and related observability tooling. * Identify and remediate security vulnerabilities using SonarQube (SAST) , DAST ...

Senior .NET Software Engineer

Tampa, FL · On-site

$115K - $152K/yr

... testing, or monitoring). * Debug and troubleshoot production issues using Grafana and related observability tooling. * Identify and remediate security vulnerabilities using SonarQube (SAST) , DAST ...

AppSec Sales Engineer - East

Tampa, FL · On-site

$55.50 - $74.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...

... testing tools (SAST, DAST, SCA) Experience with IaC tools (Terraform, Ansible, etc.) Experience with performance and load testing tools Experience writing Helm charts - What You Can Expect: A culture ...

New

next page

Showing results 1-20

Dast Tester information

What is a DAST tester?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What are the typical challenges faced by a DAST tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What cities in Florida are hiring for Dast Tester jobs?

Cities in Florida with the most Dast Tester job openings:

Senior Application Security Engineer

Real Soft, Inc / Diversity Direct

Jacksonville, FL • On-site

$54.50 - $72.75/hr

Other

Posted 4 days ago


Job description

Description:

Location: Jacksonville, FL - In office 5 days

Onsite Interviews (1-Hour)

Eligible for Conversion – Based on performance and budget approval

Must Haves:

Experience managing and tuning SAST, DAST, or SCA security scanning platforms.

Experience in integrating application security controls into CI/CD and DevSecOps workflows.

Experience analyzing vulnerabilities and partnering with development teams to drive remediation.

Nice-to-Have

Experience in regulated environments (financial services preferred).

Automation, scripting, and security reporting/dashboard experience.

Code Quality Analysis tool administration and configuration experience.

POSITION PURPOSE: Own and optimize application security testing capabilities across the software development lifecycle, with emphasis on SAST, DAST, SCA, SonarQube, scanning configuration, vulnerability triage, and actionable reporting.

Position Summary

The Senior Application Security Engineer is responsible for designing, implementing, and optimizing application security capabilities across the software development lifecycle. Working under limited supervision, this individual contributor partners with development, DevOps, architecture, risk, and cybersecurity teams to integrate security testing into delivery processes, identify application vulnerabilities, and improve secure development practices.

The role provides technical expertise for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secure code review, and code quality analysis. The engineer configures and tunes scanning technologies, validates findings, supports remediation, and develops meaningful reporting for technical and executive stakeholders.

Key Responsibilities and Duties

Administer, configure, tune, and optimize application security platforms supporting SAST, DAST, and SCA capabilities.

Manage and maintain SonarQube and similar code analysis technologies, including scanning configurations, rule profiles, quality gates, access, integrations, and reporting.

Develop and maintain application security scanning standards, procedures, runbooks, and operating documentation.

Integrate application security testing into CI/CD pipelines and DevSecOps workflows in partnership with development and platform engineering teams.

Triage and validate security findings, reduce false positives, document risk decisions, and improve the accuracy and usefulness of scan results.

Partners with application teams to prioritize and remediate vulnerabilities based on exploitability, business context, compensating controls, and organizational risk criteria.

Provide secure coding guidance and technical consultation aligned with OWASP practices, the NIST Secure Software Development Framework, and internal security standards.

Create dashboards, metrics, and key risk indicators that communicate application security coverage, finding trends, remediation performance, scan health, and control effectiveness.

Analyze recurring vulnerability patterns and recommend preventive controls, developer education, rule changes, or pipeline improvements.

Support threat modeling, architecture reviews, secure design assessments, and targeted code reviews for new and existing applications.

Assist with audit, examination, and risk assessment requests by providing accurate evidence and documentation for application security controls.

Research emerging application security threats, vulnerabilities, attack techniques, and testing methods to continuously improve the program.

Serve as a senior technical subject matter expert and mentor, without formal responsibility for assigning, reviewing, or delegating the work of other employees.

Minimum Qualifications

Bachelor’s degree in Information Security, Computer Science, Software Engineering, or a related field preferred, or equivalent relevant experience.

5 or more years of cybersecurity, software engineering, DevSecOps, vulnerability management, or application security experience.

3 or more years of direct experience operating, administering, or integrating application security scanning technologies.

Hands-on experience with SAST and DAST scanning configuration, execution, tuning, triage, and reporting.

Working knowledge of SCA, secure code review, vulnerability management, and remediation practices.

Experience with SonarQube or a comparable code quality and security analysis platform.

Understanding of modern application architectures, APIs, containers, microservices, and cloud-native delivery patterns.

Familiarity with CI/CD platforms, source code management, build automation, and DevSecOps processes.

Ability to communicate technical risk and remediation guidance clearly to developers, engineers, managers, and nontechnical stakeholders.

Preferred Qualifications

7 or more years of cybersecurity, software security, software engineering, or application security experience.

Advanced experience with SonarQube administration, custom rule profiles, quality gates, project onboarding, integration, and reporting.

Experience with commercial application security technologies such as Veracode, Checkmarx, Fortify, Contrast Security, Burp Suite Enterprise, or comparable platforms.

Experience integrating security testing into GitHub, GitLab, Azure DevOps, Jenkins, or similar CI/CD platforms.

Knowledge of OWASP Top 10, OWASP ASVS, NIST SSDF, secure SDLC practices, and common application weakness classifications.

Experience producing operational dashboards, executive metrics, key risk indicators, and trend reporting.

Experience working in regulated financial services or another highly regulated enterprise environment.

Experience supporting FFIEC, OCC, SOX, PCI DSS, or comparable audit and regulatory requirements.

Experience automating application security workflows and reporting through PowerShell, Python, APIs, or vendor scripting.

Preferred Certifications

CSSLP

GWAPT, GWEB, GSSP, or another relevant GIAC certification

OSWE or a comparable advanced application security certification

CISSP

Microsoft Azure Security Engineer Associate, AWS Certified Security – Specialty, or a comparable cloud security certification

Core Competencies

Application Security Engineering

SAST, DAST, SCA, code analysis, secure SDLC

Platform Ownership

Configuration, tuning, integrations, health, upgrades

Vulnerability Management

Validation, prioritization, remediation, exceptions

DevSecOps Collaboration

CI/CD integration, developer enablement, automation

Risk Communication

Technical guidance, dashboards, KRIs, executive reporting

Governance

Standards, procedures, evidence, regulated environments