1

Dast Tester Jobs (NOW HIRING)

Perform SAST/DAST testing and strengthen software supply chain security. * Develop and implement an immutable infrastructure strategy. * Build and execute a red team and blue team strategy to ...

Perform SAST/DAST testing and strengthen software supply chain security. * Develop and implement an immutable infrastructure strategy. * Build and execute a red team and blue team strategy to ...

Senior Platform Security Engineer

Seattle, WA · On-site +1

$163K - $192K/yr

Perform SAST/DAST testing and strengthen software supply chain security. * Develop and implement an immutable infrastructure strategy. * Build and execute a red team and blue team strategy to ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

... Testing (DAST). The ideal candidate will have hands-on experience with Burp Suite Enterprise for DAST scanning and Veracode for SAST analysis, along with a strong understanding of secure coding ...

Perform web app penetration testing (manual/automated). * Evaluate SAST/DAST findings and manage issues in Jira. * Validate bug bounty vulnerabilities. * Translate business requirements into ...

$192K - $240K/yr

Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices * Build and contribute to a culture of ...

$58.75 - $78.50/hr

You will support security activities ranging from SAST/DAST analysis to API security testing, collaborate with our Security Champions to scale secure development practices, and contribute to the ...

next page

Showing results 1-20

Dast Tester information

See salary details

$10

$38

$62

How much do dast tester jobs pay per hour?

As of Jun 15, 2026, the average hourly pay for dast tester in the United States is $38.36, according to ZipRecruiter salary data. Most workers in this role earn between $21.39 and $50.72 per hour, depending on experience, location, and employer.

What are DAST testers?

DAST testers are professionals who use Dynamic Application Security Testing (DAST) tools to identify vulnerabilities in web applications while they are running. Unlike static testing, which examines code without executing it, DAST testers simulate real-world attacks to find security flaws from the outside in, much like a hacker would. Their primary goal is to detect and help remediate issues such as SQL injection, cross-site scripting (XSS), and other security threats before malicious actors can exploit them. DAST testers work closely with development and security teams to ensure applications are secure throughout the software development lifecycle.

What are the key skills and qualifications needed to thrive as a DAST Tester, and why are they important?

To thrive as a DAST Tester, you need a solid understanding of web application security, common vulnerabilities (such as those in the OWASP Top 10), and experience in penetration testing, often supported by a degree in computer science or a related field. Familiarity with Dynamic Application Security Testing (DAST) tools like OWASP ZAP, Burp Suite, or Acunetix, as well as relevant certifications such as CEH or OSCP, is typically required. Analytical thinking, attention to detail, and strong communication skills help DAST Testers identify risks and clearly report findings to stakeholders. These skills are critical to ensuring robust application security and safeguarding organizations from cyber threats.

What is the difference between Dast Tester vs Manual Tester?

AspectDast TesterManual Tester
CertificationsISTQB, Certified Ethical Hacker (CEH)ISTQB, ISTQB Foundation
Work EnvironmentAutomated testing tools, CI/CD pipelinesTest case execution, defect reporting
Industry UsageSoftware development, DevOps teamsQuality assurance, software testing teams

While Dast Testers focus on automated security testing using tools like OWASP ZAP or Burp Suite, Manual Testers perform hands-on testing without automation. Both roles are essential in software quality assurance, but Dast Testers emphasize automation and security, whereas Manual Testers focus on detailed, exploratory testing.

What are the best DAST tools?

For a DAST (Dynamic Application Security Testing) tester, popular tools include OWASP ZAP, Burp Suite, and Acunetix, which are widely used for identifying security vulnerabilities in web applications. Proficiency with these tools, along with understanding of security testing methodologies, enhances effectiveness in the role.

What is the difference between DAST and Pentesting?

A DAST (Dynamic Application Security Testing) tester focuses on identifying security vulnerabilities in running applications through automated scanning, while penetration testing (pentesting) involves manual, in-depth attempts to exploit vulnerabilities to assess overall security. Both require knowledge of security tools and techniques but differ in scope and approach, with pentesting typically being more comprehensive and targeted. DAST is often part of a broader security assessment process, whereas pentesting may include social engineering and physical security testing as well.

What is DAST in pentesting?

In penetration testing, DAST (Dynamic Application Security Testing) is a method that analyzes running web applications to identify security vulnerabilities by simulating attacks. DAST tools, such as OWASP ZAP or Burp Suite, are commonly used by security professionals to evaluate application security without access to source code.

What does a DAST tool do?

A DAST (Dynamic Application Security Testing) tool is used by security professionals and testers to identify vulnerabilities in running web applications by simulating attacks and analyzing responses. It helps detect security flaws such as SQL injection, cross-site scripting, and other runtime issues, often integrating into security testing workflows and requiring knowledge of web security principles.

What are the typical challenges faced by a DAST Tester when integrating dynamic application security testing into the CI/CD pipeline?

A common challenge for DAST Testers is ensuring that security tests fit seamlessly into the existing CI/CD workflow without causing significant delays in deployment. Dynamic testing can sometimes result in false positives or require fine-tuning to accurately simulate real-world attacks, which may demand close collaboration with developers and DevOps teams. Effective communication is key, as DAST Testers often need to help interpret results and prioritize remediation of vulnerabilities. Balancing comprehensive security coverage with development speed is crucial to maintaining both secure and agile delivery cycles.
More about Dast Tester jobs
What cities are hiring for Dast Tester jobs? Cities with the most Dast Tester job openings:
What states have the most Dast Tester jobs? States with the most job openings for Dast Tester jobs include:
Infographic showing various Dast Tester job openings in the United States as of June 2026, with employment types broken down into 26% Full Time, 64% Part Time, and 10% Contract. Highlights an 59% Physical, 1% Hybrid, and 40% Remote job distribution, with an average salary of $79,791 per year, or $38.4 per hour.
Senior Platform Security Engineer

Senior Platform Security Engineer

Opala

Seattle, WA • Remote

$163K - $192K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 26 days ago


Job description

Opala develops healthcare products that tackle the most complex data challenges faced by payers and providers. As a startup originating from a major healthcare plan in the Northwest, we combine deep health-tech expertise with top-tier data and software engineering talent to create products that our customers find meaningful and valuable. These data products empower payers and their partners to find timely insights and take action to intervene in areas like value-based care analytics, interoperability compliance, and real-time streaming of clinical data.
In this remote position, we\'re seeking an experienced Senior Platform Security Engineer to join our team.  Here, you will play a critical role in securing our cloud infrastructure and embedding strong security practices across our engineering squads. You’ll bridge platform engineering and security, building paved-road guardrails that make it easy for developers to ship securely in a healthcare data environment. 
You\'ll also both "lead by doing" (designing and implementing IaC guardrails, CI/CD security checks, and software supply chain protections) AND "lead by influence" (mentoring engineers and partnering with our Security and Compliance team). 
Responsibilities:

  • Monitor and secure our Azure + AWS environments, responding to incidents and remediating vulnerabilities.
  • Design and implement Infrastructure as Code guardrails (Terraform, Bash, Azure CLI, AWS CLI, Jinja, CloudInit).
  • Embed security checks into CI/CD pipelines (GitHub Actions).
  • Build and manage secrets management, identity solutions, and key rotation.
  • Partner with squads to ensure product features are secure and compliant by design.
  • Investigate security breaches and document root cause and remediation steps.
  • Integrate logging/monitoring with SOC/MDR vendor to ensure strong detection and response.
  • Perform SAST/DAST testing and strengthen software supply chain security.
  • Develop and implement an immutable infrastructure strategy.
  • Build and execute a red team and blue team strategy to continually test defenses.
  • Research security enhancements and make recommendations to leadership.
  • Stay current on IT and security standards, advising the company on emerging risks.

Minimum Qualifications:
  • Bachelor’s degree in computer science or related field (or equivalent experience).
  • 6+ years in platform engineering, DevSecOps, or cloud security roles, with at least 4 in a senior capacity.
  • 2+ years mentoring and developing junior team members.
  • Experience with security in both AWS and Azure.
  • Experience with IaC tools and automation (Terraform, Bash, Azure CLI, AWS CLI, Jinja, CloudInit).
  • Experience with SAST/DAST and securing the software supply chain.
  • Experience with OpenAPI/Swagger JSON specifications and API security.
  • Familiarity with SOC 2 controls and know how to enforce them in cloud systems.
  • Familiarity with HIPAA controls and know how to enforce them in cloud systems.
  • Strong Bash scripting skills for automation.
  • Ability to collaborate closely with developers and product squads while setting security best practices.

Preferred Qualifications:
  • 2+ years of vendor management experience.Security certifications (AWS Security Specialty, AZ500, CISSP, etc.).
  • Experience using or administering compliance automation tools (Drata or similar GRC platforms).
  • Experience with HITRUST controls and how to enforce them in cloud systems.
  • Exposure to enterprise architecture frameworks such as TOGAF.
  • Experience in regulated industries (healthcare, fintech, etc.).
  • Experience leading or coordinating red/blue team exercises.
  • Experience with other scripting languages: PowerShell, python

Benefits:
  • The Seattle base salary range for this full-time position is $163k-$192k. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.  
  • Benefits include medical, dental, vision, life and AD&D insurance, EAP, short-term and long-term disability, 16 days PTO, 8 paid holidays, fully paid holiday closure, parental and family medical leave, 401k, stock options and annual bonuses and salary increases based on merit.

Diversity and Inclusivity Statement:
  • At Opala, we believe that diversity and inclusivity are critical to our success. We encourage and value diverse perspectives and experiences, and we believe that they are essential for driving innovation and creating products that meet the needs of our diverse customer base.  


Opala is an equal opportunity employer and makes employment decisions on the basis of merit.  We are committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity, innovation, and the success of our business. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, veteran status, disability status, pregnancy, parental status, genetic information, political affiliation, or any other status protected by the laws or regulations in the locations where we operate. Accommodations are available for applicants with disabilities.