1

Dast Tester Jobs (NOW HIRING)

Job Title Senior Penetration Tester About your role: At Fiserv, we deliver technology solutions ... Hands-on experience with SAST/DAST/SCA platforms (e.g., Veracode, Checkmarx, Fortify) and ...

SUD Counselor

Auburn, CA · On-site

$23 - $27/hr

Obtain monthly reports that summarize and identify results of AUDIT/DAST testing; Identify individuals needing SBIRT based on these results and provides initial care planning for possible SUD ...

Implement both SaaS-based security testing (SaaST) and dynamic application security testing (DAST) for major platforms. * Focus primarily on security and testing for core business systems: Salesforce ...

The Research Architect for Dynamic Application Security Testing (DAST) is responsible for overseeing the security capabilities of Veracode's dynamic scanner offerings. Responsibilities · Conduct ...

Application Security Engineer

Herndon, VA · On-site

$60.50 - $80.75/hr

Support and operate application security testing capabilities across SAST, DAST and IDE plug-in environments, with primary focus on Burp Suite and Veracode. * Configure, maintain and troubleshoot ...

Application Security Engineer

Herndon, VA

$60.50 - $80.75/hr

Support and operate application security testing capabilities across SAST, DAST and IDE plug-in environments, with primary focus on Burp Suite and Veracode. * Configure, maintain and troubleshoot ...

next page

Showing results 1-20

Dast Tester information

See salary details

$10

$38

$62

How much do dast tester jobs pay per hour?

As of Jun 15, 2026, the average hourly pay for dast tester in the United States is $38.36, according to ZipRecruiter salary data. Most workers in this role earn between $21.39 and $50.72 per hour, depending on experience, location, and employer.

What are DAST testers?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST Tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What are the best DAST tools?

For a DAST (Dynamic Application Security Testing) tester, popular tools include OWASP ZAP, Burp Suite, and Acunetix, which are widely used for identifying security vulnerabilities in web applications. Proficiency with these tools, along with understanding of security testing methodologies, enhances effectiveness in the role.

What is the difference between DAST and Pentesting?

A DAST (Dynamic Application Security Testing) tester focuses on identifying security vulnerabilities in running applications through automated scanning, while penetration testing (pentesting) involves manual, in-depth attempts to exploit vulnerabilities to assess overall security. Both require knowledge of security tools and techniques but differ in scope and approach, with pentesting typically being more comprehensive and targeted. DAST is often part of a broader security assessment process, whereas pentesting may include social engineering and physical security testing as well.

What is DAST in pentesting?

In penetration testing, DAST (Dynamic Application Security Testing) is a method that analyzes running web applications to identify security vulnerabilities by simulating attacks. DAST tools, such as OWASP ZAP or Burp Suite, are commonly used by security professionals to evaluate application security without access to source code.

What does a DAST tool do?

A DAST (Dynamic Application Security Testing) tool is used by security professionals and testers to identify vulnerabilities in running web applications by simulating attacks and analyzing responses. It helps detect security flaws such as SQL injection, cross-site scripting, and other runtime issues, often integrating into security testing workflows and requiring knowledge of web security principles.

What are the typical challenges faced by a DAST Tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.
More about Dast Tester jobs
What cities are hiring for Dast Tester jobs? Cities with the most Dast Tester job openings:
What states have the most Dast Tester jobs? States with the most job openings for Dast Tester jobs include:
Infographic showing various Dast Tester job openings in the United States as of June 2026, with employment types broken down into 26% Full Time, 64% Part Time, and 10% Contract. Highlights an 59% Physical, 1% Hybrid, and 40% Remote job distribution, with an average salary of $79,791 per year, or $38.4 per hour.

Senior Penetration Tester

Monitise

Milwaukee, WI

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 19 hours ago


Job description

Calling all innovators - find your future at Fiserv.

We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we're involved. If you want to make an impact on a global scale, come make a difference at Fiserv.

Job Title

Senior Penetration Tester

About your role:
At Fiserv, we deliver technology solutions that help clients move money and manage financial services securely and reliably. The Application Security team focuses on protecting our products and client data through proactive testing and advanced security practices. As a Senior Penetration Tester, you will lead in-depth assessments of web, API, mobile, and thick-client applications to reduce risk and strengthen our security posture.

What you'll do:

  • Perform thorough penetration testing across web applications, RESTful APIs, mobile applications (iOS/Android), and thick clients using manual and automated techniques to identify and exploit vulnerabilities.
  • Develop and implement advanced penetration testing strategies, frameworks, and test plans tailored to different application architectures.
  • Lead security assessments, execute exploit development and proof-of-concept creation, and validate remediation effectiveness.
  • Provide technical guidance on remediation, secure coding practices, and risk mitigation to development and product teams.
  • Monitor and respond to application security incidents; conduct root-cause analysis and drive corrective actions.
  • Research and apply emerging tools, techniques, and threat intelligence to continuously improve testing coverage and automation.
  • Mentor and support team members, promoting a culture of application security engineering and secure SDLC integration.
  • Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.

Experience you'll need to have:

  • 10+ years of experience in application penetration testing for web applications, RESTful APIs, mobile applications, and thick clients using manual exploitation and advanced assessment techniques.
  • 10+ years of experience in vulnerability research, exploit development, binary analysis, and proof-of-concept development.
  • 8+ years of experience in cloud and container security assessments (AWS, Azure, GCP, Docker, Kubernetes) for cloud-native applications.
  • 8+ years of experience with secure SDLC practices, threat modeling, and application security standards (OWASP Top 10, NIST, SANS) and compliance frameworks (e.g., PCI DSS).
  • 8+ years of experience integrating security into CI/CD and IaC pipelines, and testing automation (Jenkins, GitHub Actions, Terraform).
  • 6+ years of experience with scripting and automation (Python, Bash), and hands-on use of tools such as Burp Suite, Metasploit, MobSF, Postman, and fuzzing frameworks.
  • 6+ years of equivalent combination of educational background, related experience, and/or military experience.

Experience that would be great to have:

  • Experience working in the financial services industry with secure application development and regulatory/compliance requirements.
  • Professional certifications such as OSCP, GWAPT, CPENT, or equivalent.
  • Experience applying LLMs and automation for vulnerability discovery, exploit generation, or security testing orchestration.
  • Hands-on experience with SAST/DAST/SCA platforms (e.g., Veracode, Checkmarx, Fortify) and integrating findings into developer workflows.
  • Proven experience mentoring engineers and collaborating with product, engineering, and risk teams to operationalize application security.

How you'll work:

  • This role is on-site Monday through Friday. Fiserv considers in-person collaboration to be an essential part of this role as in-person office experiences help you with your overall onboarding experience and leads to stronger productivity.
  • This role requires the use of a computer and audio equipment.

Travel:

Approximately 0% travel off-site or to other office locations is expected.

Sponsorship:

  • You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered for this role.

Benefits at Fiserv:

  • Fuel Your Life program to support physical, financial, social, and emotional well-being.
  • Paid holidays and generous time away policies.
  • No-cost mental health support through Employee Assistance Programs.
  • Living Proof program to recognize your peers' extra effort with points used for rewards.
  • Eight Employee Resource Groups to foster a collaborative culture.
  • Unparalleled professional growth with training, development, and internal mobility opportunities.
  • Retirement planning and discounted shares with the Employee Stock Purchase Plan.
  • Medical, dental, vision, life, and disability insurance options available day one.
  • Tuition assistance and reimbursement program.
  • Paid parental, caregiver, and military leave.

#LI-RM1

Salary Range

$90,000.00 - $158,400.00

These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.

It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.

For incentive eligible associates, the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Company's sole discretion.

Thank you for considering employment with Fiserv. Please:

  • Apply using your legal name
  • Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).

Our commitment to Equal Opportunity:

Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, gender, gender identity, sexual orientation, age, disability, protected veteran status, or any other category protected by law.

If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process, please contactAskHR.US@fiserv.com. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiserv's Disability Accommodation Policy for additional information.

Note to agencies:

Fiserv does not accept resume submissions from agencies outside of existing agreements.Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.

Warning about fake job posts:

Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.