1

Dast Tester Jobs in Oregon (NOW HIRING)

Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines. * Support ...

DevOps Director

OR · On-site +1

$200K - $230K/yr

SAST/DAST and dependency scanning in the pipeline, SBOM generation, artifact signing, and least ... CISSP or CCSP. * SRE practice - SLI/SLO definition, error budgets, chaos and DR testing. * Zero ...

Sr. Cloud Security Engineer - FedRamp

OR · On-site +1

$114K - $156K/yr

Integrate security testing tools (SAST, DAST, SCA) into CI/CD pipelines to enable "shift-left" security practices. Secrets and Key Management: Design and maintain solutions for the secure storage and ...

... testing, or another role that taught you how applications are built and broken * You can look at a ... You have worked with tools such as SAST, DAST, dependency scanning, secret scanning, or ...

... testing, or another role that taught you how applications are built and broken * You can look at a ... You have worked with tools such as SAST, DAST, dependency scanning, secret scanning, or ...

Dast Tester information

What is a DAST tester?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What are the typical challenges faced by a DAST tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What are popular job titles related to Dast Tester jobs in Oregon?

For Dast Tester jobs in Oregon, the most frequently searched job titles are:

What cities in Oregon are hiring for Dast Tester jobs?

Cities in Oregon with the most Dast Tester job openings:

Product Cybersecurity Architect

OR • On-site, Remote


Bausch + Lomb
Medical Equipment and Supplies Manufacturing • 10K+ employees

8.6

Company rating: 8.6 out of 10

Based on 39 frontline employees who took The Breakroom Quiz

22nd of 545 rated manufacturers

People enjoy working here

Good employer

Recommended by parents


Full-time

Dental, Vision, Life, Retirement, PTO

Re-posted 19 days ago


Job description

Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world-from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better.
Our comprehensive portfolio of over 400 products is fully integrated and built to serve our customers across the full spectrum of their eye health needs throughout their lives. Our iconic brand is built on the deep trust and loyalty of our customers established over our 170-year history. We have a significant global research, development, manufacturing and commercial footprint of approximately 13,000 employees and a presence in approximately 100 countries, extending our reach to billions of potential customers across the globe. We have long been associated with many of the most significant advances in eye health, and we believe we are well positioned to continue leading the advancement of eye health in the future.
Why this Role Matters
Join the Surgical R&D organization in a role where you will help ensure the cybersecurity, safety, and reliability of innovative surgical products that support patient care. In this position, you will be responsible for embedding secure-by-design practices throughout the product lifecycle while partnering with engineering, quality, regulatory, and corporate security teams to deliver compliant and resilient solutions. This is a strong opportunity for someone who brings deep product security expertise, strong cross-functional collaboration skills, and a passion for advancing cybersecurity within a regulated medical device environment.
What You'll Do
  • Architect and implement a consistent cybersecurity strategy across surgical capital equipment product lines to establish a scalable and secure product ecosystem.
  • Embed secure-by-design principles throughout the product lifecycle, providing guidance on secure architecture, threat modeling, design controls, cryptography, and secure communication protocols.
  • Lead execution of cybersecurity requirements across development programs, ensuring alignment with regulatory expectations, corporate standards, and product quality objectives.
  • Coordinate vulnerability management activities, including intake, triage, risk assessment, remediation tracking, and documentation of product security issues through closure.
  • Serve as the Surgical R&D cybersecurity representative for vulnerability disclosure and incident response activities, supporting investigations, impact assessments, root cause analyses, and remediation efforts.
  • Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines.
  • Support supplier and third-party security initiatives by defining security requirements, managing software supply chain risks, and maintaining Software Bill of Materials (SBOM) processes.
  • Collaborate with Quality, Regulatory Affairs, IT, and Corporate Product Security teams to ensure compliance with evolving cybersecurity regulations and industry standards while enabling efficient product delivery.

What You'll Bring
Required Education & Experience:
  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, or a related technical discipline.
  • 7+ years of experience in product security, application security, medical device cybersecurity, or software security within a regulated environment.
  • Demonstrated experience supporting or leading cybersecurity activities for medical device or other regulated product development programs.
  • Strong communication, collaboration, stakeholder management, and problem-solving skills.
  • Ability to translate technical cybersecurity risks into clear, actionable guidance for engineering, quality, and regulatory stakeholders.

Specialized Technical, Regulatory & Industry Skills & Knowledge
  • Strong expertise in secure product design, threat modeling, vulnerability management, and secure software development practices.
  • Working knowledge of connected device security, embedded systems, and software-enabled product architectures.
  • Experience with security testing tools and methodologies, including SAST, DAST, SCA, and penetration testing.
  • Understanding of software supply chain security practices, including SBOM development and third-party risk management.
  • Experience working across cross-functional and global teams to drive cybersecurity outcomes and influence stakeholders without direct authority.
  • Knowledge of secure development lifecycle (SDLC) frameworks, vulnerability disclosure processes, and product incident response activities.
  • Familiarity with cybersecurity governance, risk assessment, and compliance processes within regulated industries.

Preferred
  • Advanced degree in Cybersecurity, Computer Science, Engineering, or a related field.
  • Relevant industry certifications such as CISSP, CSSLP, OSCP, GWAPT, or equivalent.
  • Experience in medical device, healthcare, or other regulated industries, and/or working within a quality-managed or GxP regulated environment.
  • Working knowledge of medical device cybersecurity regulations and standards (e.g., FDA premarket/post market guidance, IEC 81001-5-1, AAMI TIR57, UL 2900, NIST frameworks).
  • Experience developing cybersecurity documentation to support regulatory submissions and audits.

This position may be available in the following location(s): US - Remote
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
For U.S. locations that require disclosure of compensation, the starting pay for this role is between $140,000 and $180,000. The estimated salary range reflects an anticipated range for this position. The actual base salary offered may depend on a variety of factors.
U.S. based employees may be eligible for short-term and/or long-term incentives. They may also be eligible to participate in medical, dental, vision insurance, disability and life insurance, a 401(k) plan and company match, a tuition reimbursement program (select degrees), company holidays, and well-being benefits, among others. U.S. based employees are also eligible to receive sick time, floating holidays and paid vacation.
Job Applicants should be aware of job offer scams perpetrated through the use of the Internet and social media platforms.
To learn more please read Bausch + Lomb's Job Offer Fraud Statement.
Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

Bausch & Lomb logo

About Bausch & Lomb

Sourced by ZipRecruiter

Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world--from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better. Our comprehensive portfolio of over 400 products is fully integrated and built to serve our customers across the full spectrum of their eye health needs throughout their lives. Our iconic brand is built on the deep trust and loyalty of our customers established over our nearly 170-year history. We have a significant global research, development, manufacturing and commercial footprint of approximately 12,500 employees and a presence in approximately 100 countries, extending our reach to billions of potential customers across the globe. We have long been associated with many of the most significant advances in eye health, and we believe we are well positioned to continue leading the advancement of eye health in the future.

Industry

Medical equipment and supplies manufacturing

Company size

10,000+ Employees

Headquarters location

Bridgewater, NJ, US

Year founded

1853


What Bausch & Lomb employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom