SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
SAST, DAST, and SCA tools * Web application security testing (OWASP Top 10, API security) * Strong understanding of: * Secure software development lifecycle (SDLC / DevSecOps) * Common ...
DevSecOps Engineer
$55 - $73.50/hr
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools Review vulnerability findings and collaborate with development teams to ...
DevSecOps Engineer
$55 - $73.50/hr
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools Review vulnerability findings and collaborate with development teams to ...
AppSec Sales Engineer - East
Raleigh, NC · Remote
$57 - $76.25/hr
Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...
AppSec Sales Engineer - East
Raleigh, NC · Remote
$57 - $76.25/hr
Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools • Review vulnerability findings and collaborate with development teams to ...
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools • Review vulnerability findings and collaborate with development teams to ...
DevSecOps Engineer
Morrisville, NC · On-site
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools • Review vulnerability findings and collaborate with development teams to ...
DevSecOps Engineer
Morrisville, NC · On-site
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Management and Scanning Tools • Review vulnerability findings and collaborate with development teams to ...
AI Threat Modeling Engineer
Cary, NC · On-site
$85K - $100K/yr
... Testing • Integrate SAST, DAST, and AI-specific security testing frameworks within CI/CD pipelines • Conduct security reviews of AI models, APIs, and data pipelines • Drive remediation ...
AI Threat Modeling Engineer
Cary, NC · On-site
$85K - $100K/yr
... Testing • Integrate SAST, DAST, and AI-specific security testing frameworks within CI/CD pipelines • Conduct security reviews of AI models, APIs, and data pipelines • Drive remediation ...
AI Threat Modeling Engineer
Cary, NC · On-site
... DAST, and AI-specific security testing frameworks within CI/CD pipelines • Conduct security reviews of AI models, APIs, and data pipelines • Drive remediation strategies for identified risks ...
AI Threat Modeling Engineer
Cary, NC · On-site
... DAST, and AI-specific security testing frameworks within CI/CD pipelines • Conduct security reviews of AI models, APIs, and data pipelines • Drive remediation strategies for identified risks ...
AppSec Sales Engineer - East
Raleigh, NC · On-site
$57 - $76.25/hr
Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...
AppSec Sales Engineer - East
Raleigh, NC · On-site
$57 - $76.25/hr
Deliver world-class platform presentations and demos focused on Application Security Testing and ... SAST, DAST, and runtime protection * Connect business security risks and compliance problems to ...
Senior Application Security Engineer
Durham, NC · On-site
$56.75 - $75.75/hr
Automate SAST, DAST, SCA, and container image scanning in the build and release pipelines ... Perform secure code reviews and support automated security testing coverage across pipelines.
Senior Application Security Engineer
Durham, NC · On-site
$56.75 - $75.75/hr
Automate SAST, DAST, SCA, and container image scanning in the build and release pipelines ... Perform secure code reviews and support automated security testing coverage across pipelines.
Senior Application Security Engineer
Durham, NC · On-site
$56.75 - $75.75/hr
Automate SAST, DAST, SCA, and container image scanning in the build and release pipelines ... Perform secure code reviews and support automated security testing coverage across pipelines.
Senior Application Security Engineer
Durham, NC · On-site
$56.75 - $75.75/hr
Automate SAST, DAST, SCA, and container image scanning in the build and release pipelines ... Perform secure code reviews and support automated security testing coverage across pipelines.
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Scanning * Review vulnerability scan findings. * Collaborate with developers to remediate security findings.
New
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Scanning * Review vulnerability scan findings. * Collaborate with developers to remediate security findings.
New
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Scanning * Review vulnerability scan findings. * Collaborate with developers to remediate security findings.
New
Dynamic Application Security Testing (DAST) * Software Composition Analysis (SCA) * Secrets Scanning * Review vulnerability scan findings. * Collaborate with developers to remediate security findings.
New
Senior Product Security Engineer
Raleigh, NC · On-site
$168K - $210K/yr
... DAST, where necessary. * Leverage AI and MCP to create intelligent, context-aware security guidance and automation. You have * 5+ years of relevant Penetration Testing, Product Security, and ...
Senior Product Security Engineer
Raleigh, NC · On-site
$168K - $210K/yr
... DAST, where necessary. * Leverage AI and MCP to create intelligent, context-aware security guidance and automation. You have * 5+ years of relevant Penetration Testing, Product Security, and ...
Senior Product Security Engineer
$168K - $210K/yr
... DAST, where necessary. * Leverage AI and MCP to create intelligent, context-aware security guidance and automation. You have * 5+ years of relevant Penetration Testing, Product Security, and ...
Senior Product Security Engineer
$168K - $210K/yr
... DAST, where necessary. * Leverage AI and MCP to create intelligent, context-aware security guidance and automation. You have * 5+ years of relevant Penetration Testing, Product Security, and ...
Coordinate with cross-functional teams to integrate medical device security requirements throughout the product lifecycle, including risk assessments, security testing (SAST, DAST, SCA, penetration ...
Coordinate with cross-functional teams to integrate medical device security requirements throughout the product lifecycle, including risk assessments, security testing (SAST, DAST, SCA, penetration ...
Product Security Engineer
Raleigh, NC · On-site
Coordinate with cross-functional teams to integrate medical device security requirements throughout the product lifecycle, including risk assessments, security testing (SAST, DAST, SCA, penetration ...
Product Security Engineer
Raleigh, NC · On-site
Coordinate with cross-functional teams to integrate medical device security requirements throughout the product lifecycle, including risk assessments, security testing (SAST, DAST, SCA, penetration ...
Dast Tester information
See Raleigh, NC salary details
$10.52 - $15.10
7% of jobs
$15.10 - $19.69
16% of jobs
$20.71 is the 25th percentile. Wages below this are outliers.
$19.69 - $24.28
9% of jobs
$24.28 - $28.87
3% of jobs
$28.87 - $33.46
10% of jobs
The median wage is $35.29 / hr.
$33.46 - $38.05
10% of jobs
$38.05 - $42.63
7% of jobs
$42.63 - $47.22
9% of jobs
$47.84 is the 75th percentile. Wages above this are outliers.
$47.22 - $51.81
16% of jobs
$51.81 - $56.40
6% of jobs
$56.40 - $60.99
5% of jobs
$10
$37
$60
How much do dast tester jobs pay per hour?
What are DAST testers?
What are the key skills and qualifications needed to thrive as a DAST Tester, and why are they important?
What is the difference between Dast Tester vs Manual Tester?
| Aspect | Dast Tester | Manual Tester |
|---|---|---|
| Certifications | ISTQB, Certified Ethical Hacker (CEH) | ISTQB, ISTQB Foundation |
| Work Environment | Automated testing tools, CI/CD pipelines | Test case execution, defect reporting |
| Industry Usage | Software development, DevOps teams | Quality assurance, software testing teams |
While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.
What are the typical challenges faced by a DAST Tester when integrating dynamic application security testing into the CI/CD pipeline?
Cyber Security Analyst III - App Security & Vulnerability (Remote)
Raleigh, NC • On-site, Remote
Full-time
Re-posted 5 days ago
First Citizens Bank rating
7.4
Based on 106 frontline employees who took The Breakroom Quiz
109th of 170 rated banks
Job description
This is aremote role in NC, AZ, and TX.
We are seeking a highly skilled Cyber Security Analyst with a strong background in application security and vulnerability management. This role focuses on identifying, analyzing, and mitigating security risks across software development pipelines using SAST, DAST, and SCA tools. The ideal candidate combines hands-on technical expertise with knowledge of modern security practices and emerging technologies, including AI/ML.
Responsibilities
Application Security & Code Analysis
- Perform static (SAST), dynamic (DAST), and software composition analysis (SCA) to identify vulnerabilities in applications and third-party components
- Analyze scan results, triage findings, and prioritize remediation efforts based on risk
- Partner with development teams to remediate vulnerabilities and improve secure coding practices
Vulnerability Management
- Conduct regular security assessments and vulnerability scans across applications and environments
- Validate and reproduce vulnerabilities, including false positive elimination
- Track and report vulnerability metrics, risk trends, and remediation progress
Security Tools & Automation
- Configure, deploy, and maintain security scanning tools (e.g., Checkmarx, Veracode, Fortify, Snyk, Burp Suite, OWASP ZAP)
- Automate security testing processes using scripting or APIs
- Improve scanning efficiency and coverage through tuning and optimization
#LI-IK1
Qualifications
Bachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information Security
Required Qualifications
- Hands-on experience with:
- SAST, DAST, and SCA tools
- Web application security testing (OWASP Top 10, API security)
- Strong understanding of:
- Secure software development lifecycle (SDLC / DevSecOps)
- Common vulnerabilities (e.g., injection, XSS, authentication flaws)
- Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
- Experience interpreting and prioritizing scan results and remediation plans
Preferred Qualifications
- Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
- Familiarity of container and cloud security (AWS, Azure, GCP)
- Familiarity with AI/ML concepts and security implications
- Industry certifications such as:
- CEH, Security+, SSCP, GIAC or comparable.
Key Skills
- Strong analytical and problem-solving skills
- Provide risk-based recommendations to stakeholders
- Ability to communicate technical findings to both technical and non-technical stakeholders
- Experience working cross-functionally with development and engineering teams
- Attention to detail with a risk-based security mindset
Nice-to-Have Experience
- API security testing tools (Postman, SoapUI)
- AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
- Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
- AI/ML & Emerging Technologies
- Leverage AI/ML-based security tools for enhanced detection and analysis
- Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
- Participate in securing AI-driven applications and data pipelines
- Threat Analysis & Risk Management
- Assess potential threats and attack vectors relevant to applications and APIs
- Apply threat modeling techniques (e.g., STRIDE) during development lifecycle
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.
Qualifications:Bachelor's Degree and 6 years of experience in Information Security OR High School Diploma or GED and 10 years of experience in Information Security
Required Qualifications
- Hands-on experience with:
- SAST, DAST, and SCA tools
- Web application security testing (OWASP Top 10, API security)
- Strong understanding of:
- Secure software development lifecycle (SDLC / DevSecOps)
- Common vulnerabilities (e.g., injection, XSS, authentication flaws)
- Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash)
- Experience interpreting and prioritizing scan results and remediation plans
Preferred Qualifications
- Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps)
- Familiarity of container and cloud security (AWS, Azure, GCP)
- Familiarity with AI/ML concepts and security implications
- Industry certifications such as:
- CEH, Security+, SSCP, GIAC or comparable.
Key Skills
- Strong analytical and problem-solving skills
- Provide risk-based recommendations to stakeholders
- Ability to communicate technical findings to both technical and non-technical stakeholders
- Experience working cross-functionally with development and engineering teams
- Attention to detail with a risk-based security mindset
Nice-to-Have Experience
- API security testing tools (Postman, SoapUI)
- AI-assisted security tooling (e.g., anomaly detection, code analysis assistants)
- Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2)
- AI/ML & Emerging Technologies
- Leverage AI/ML-based security tools for enhanced detection and analysis
- Assess risks related to AI/ML models (e.g., data poisoning, model inversion, adversarial attacks)
- Participate in securing AI-driven applications and data pipelines
- Threat Analysis & Risk Management
- Assess potential threats and attack vectors relevant to applications and APIs
- Apply threat modeling techniques (e.g., STRIDE) during development lifecycle
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.
Education:UNAVAILABLEEmployment Type: FULL_TIMEWhat First Citizens Bank employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom