1

Dast Tester Jobs in Oregon (NOW HIRING)

Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines. * Support ...

Knowledge of security testing methodologies and tools (SAST, DAST, SCA). * Experience with CI/CD security integration and DevSecOps practices. * Strong incident response skills and experience ...

Sr. Cloud Security Engineer - FedRamp

OR · On-site +1

$114K - $156K/yr

Integrate security testing tools (SAST, DAST, SCA) into CI/CD pipelines to enable "shift-left" security practices. Secrets and Key Management: Design and maintain solutions for the secure storage and ...

Dast Tester information

What is a DAST tester?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What are the typical challenges faced by a DAST tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What are popular job titles related to Dast Tester jobs in Oregon?

For Dast Tester jobs in Oregon, the most frequently searched job titles are:

What cities in Oregon are hiring for Dast Tester jobs?

Cities in Oregon with the most Dast Tester job openings:

Software Security Engineer (Entry-Level)

Beaverton, OR • On-site


Tektronix
Electrical Equipment, Appliance, and Component Manufacturing • 5 - 10K employees

9.1

Company rating: 9.1 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

People enjoy working here

Good employer

Paid breaks


Full-time

Re-posted 20 days ago


Job description

Job Summary:
Tektronix is a leading company in electronic test and measurement instruments, fostering a culture of learning and collaboration. They are seeking an early-career engineer to support Secure Product Development initiatives, focusing on secure coding, vulnerability management, and advising software engineers on security requirements.
Responsibilities:
• Assist in the implementation and maintenance of security standards and best practices.
• Help identify, triage, and track remediation of vulnerabilities.
• Contribute to the integration and tuning of security tools (SAST, SCA, DAST, secrets scanning, etc.).
• Provide guidance and support to engineers regarding security requirements.
• Participate and guide product teams in threat modeling to identify potential risks using STRIDE and DREAD frameworks.
• Develop and maintain automation scripts (Python, Bash, PowerShell, etc.) to improve security processes and workflows.
• Create small internal tools or utilities that support engineering productivity and security visibility.
• Help manage and administer security-related platforms (e.g., SAST, DAST, SCA scanners).
• Assist with onboarding engineers to security tools and workflows.
• Support documentation efforts for operational procedures and tool usage.
• Work closely with software engineers, DevOps, and IT to promote secure practices.
• Participate in security incident response activities as needed.
• Stay up to date with emerging security trends, threats, and technologies.
Qualifications:
Required:
• Bachelor’s degree in Computer Science, Computer Engineering, Information Security, or a related technical field.
• Strong familiarity with one or more scripting languages (e.g., Python, Bash, PowerShell).
• Working knowledge of Linux and/or Windows operating systems.
• Understanding of core cybersecurity topics such as OWASP Top 10, SSDLC, and common vulnerability types.
• Ability to learn new tools, technologies, and security concepts quickly.
• Strong communication and documentation skills.
Preferred:
• Coursework, internships, or projects related to cybersecurity.
• Exposure to cloud platforms (AWS, Azure, or GCP).
• Familiarity with GitHub or similar version control systems.
• Experience with CI/CD pipelines or developer tooling.
• Basic knowledge of networking fundamentals and security protocols.
• Relevant certifications (Security+, GSEC, etc.) are a plus but not required.
Company:
Tektronix specializes in calibration, testing, repair, asset management, and factory services. It is a sub-organization of Telestream. Founded in 1946, the company is headquartered in Beaverton, USA, with a team of 1001-5000 employees. The company is currently Late Stage.

Tektronix logo

About Tektronix

Sourced by ZipRecruiter

Industry

Electrical equipment, appliance, and component manufacturing

Company size

5,001 - 10,000 Employees

Headquarters location

Beaverton, OR, US

Year founded

1946

Social media


What Tektronix employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom