1

Dast Tester Jobs in Raleigh, NC (NOW HIRING)

DevSecOps Engineer

Morrisville, NC

$55 - $73.50/hr

Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools Review vulnerability findings and collaborate with development teams to ...

AppSec Sales Engineer - East

Raleigh, NC · Remote

$57 - $76.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...

AppSec Sales Engineer - East

Raleigh, NC · On-site

$57 - $76.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...

... DAST, where necessary. * Leverage AI and MCP to create intelligent, context-aware security guidance and automation. You have * 5+ years of relevant Penetration Testing, Product Security, and ...

... DAST, where necessary. * Leverage AI and MCP to create intelligent, context-aware security guidance and automation. You have * 5+ years of relevant Penetration Testing, Product Security, and ...

Coordinate with cross-functional teams to integrate medical device security requirements throughout the product lifecycle, including risk assessments, security testing (SAST, DAST, SCA, penetration ...

next page

Showing results 1-20

Dast Tester information

See Raleigh, NC salary details

$10

$37

$60

How much do dast tester jobs pay per hour?

As of Jul 31, 2026, the average hourly pay for dast tester in Raleigh, NC is $37.29, according to ZipRecruiter salary data. Most workers in this role earn between $20.82 and $49.33 per hour, depending on experience, location, and employer.

What are DAST testers?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST Tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What are the typical challenges faced by a DAST Tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.
What are popular job titles related to Dast Tester jobs in Raleigh, NC? For Dast Tester jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Dast Tester jobs in Raleigh, NC look for? The top searched job categories for Dast Tester jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Dast Tester jobs? Cities near Raleigh, NC with the most Dast Tester job openings:

Cyber Security Analyst III - App Security & Vulnerability (Remote)

First Citizens Bank

Raleigh, NC • On-site, Remote

Full-time

Re-posted 5 days ago


First Citizens Bank rating

7.4

Company rating: 7.4 out of 10

Based on 106 frontline employees who took The Breakroom Quiz

109th of 170 rated banks


Job description

Overview

This is aremote role in NC, AZ, and TX. 

We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role focuses on identifying, analyzing, and mitigating security risks across software development pipelines using SAST, DAST, and SCA tools. The ideal candidate combines hands-on technical expertise with knowledge of modern security practices and emerging technologies, including AI/ML.


Responsibilities

Application Security & Code Analysis

  • Perform static (SAST), dynamic (DAST), and software composition analysis (SCA) to identify vulnerabilities in applications and third-party components
  • Analyze scan results, triage findings, and prioritize remediation efforts based on risk
  • Partner with development teams to remediate vulnerabilities and improve secure coding practices

Vulnerability Management

  • Conduct regular security assessments and vulnerability scans across applications and environments
  • Validate and reproduce vulnerabilities, including false positive elimination
  • Track and report vulnerability metrics, risk trends, and remediation progress

Security Tools & Automation

  • Configure, deploy, and maintain security scanning tools (e.g., Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP)
  • Automate security testing processes using scripting or APIs
  • Improve scanning efficiency and coverage through tuning and optimization

#LI-IK1 


Qualifications

Bachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information Security

Required Qualifications

  • Hands-on experience with:
    • SAST, DAST, and SCA tools
    • Web application security testing (OWASP Top 10, API security)
  • Strong understanding of:
    • Secure software development lifecycle (SDLC / DevSecOps)
    • Common vulnerabilities (e.g., injection, XSS, authentication flaws)
  • Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
  • Experience interpreting and prioritizing scan results and remediation plans

Preferred Qualifications

  • Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
  • Familiarity of container and cloud security (AWS, Azure, GCP)
  • Familiarity with AI/ML concepts and security implications
  • Industry certifications such as:
    • CEH, Security+, SSCP, GIAC or comparable.

Key Skills

  • Strong analytical and problem-solving skills
  • Provide risk-based recommendations to stakeholders
  • Ability to communicate technical findings to both technical and non-technical stakeholders
  • Experience working cross-functionally with development and engineering teams
  • Attention to detail with a risk-based security mindset

Nice-to-Have Experience

  • API security testing tools (Postman, SoapUI)
  • AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
  • Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
  • AI/ML & Emerging Technologies
    • Leverage AI/ML-based security tools for enhanced detection and analysis
    • Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
    • Participate in securing AI-driven applications and data pipelines
  • Threat Analysis & Risk Management
    • Assess potential threats and attack vectors relevant to applications and APIs
    • Apply threat modeling techniques (e.g., STRIDE) during development lifecycle

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Qualifications:

Bachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information Security

Required Qualifications

  • Hands-on experience with:
    • SAST, DAST, and SCA tools
    • Web application security testing (OWASP Top 10, API security)
  • Strong understanding of:
    • Secure software development lifecycle (SDLC / DevSecOps)
    • Common vulnerabilities (e.g., injection, XSS, authentication flaws)
  • Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
  • Experience interpreting and prioritizing scan results and remediation plans

Preferred Qualifications

  • Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
  • Familiarity of container and cloud security (AWS, Azure, GCP)
  • Familiarity with AI/ML concepts and security implications
  • Industry certifications such as:
    • CEH, Security+, SSCP, GIAC or comparable.

Key Skills

  • Strong analytical and problem-solving skills
  • Provide risk-based recommendations to stakeholders
  • Ability to communicate technical findings to both technical and non-technical stakeholders
  • Experience working cross-functionally with development and engineering teams
  • Attention to detail with a risk-based security mindset

Nice-to-Have Experience

  • API security testing tools (Postman, SoapUI)
  • AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
  • Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
  • AI/ML & Emerging Technologies
    • Leverage AI/ML-based security tools for enhanced detection and analysis
    • Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
    • Participate in securing AI-driven applications and data pipelines
  • Threat Analysis & Risk Management
    • Assess potential threats and attack vectors relevant to applications and APIs
    • Apply threat modeling techniques (e.g., STRIDE) during development lifecycle

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom