1

Dast Jobs in Indiana (NOW HIRING)

Software Development Tools Manager

Carmel, IN · Remote

$123K - $162K/yr

Knowledge of software security tooling (SCA, SAST, DAST) and compliance frameworks. * Experience managing distributed teams and enabling remote developer productivity. * Certifications in cloud ...

Software Development Tools Manager

Carmel, IN · On-site

$123K - $162K/yr

Knowledge of software security tooling (SCA, SAST, DAST) and compliance frameworks. * Experience managing distributed teams and enabling remote developer productivity. * Certifications in cloud ...

Experience with SAST/DAST tools, container security and vulnerability management. * Knowledge of ISO 27001 compliance requirements for cloud environments. * Experience with infrastructure as code ...

Integrate security scanning, including SAST, DAST, dependency, and container scanning. * Lead release management across environments and automate infrastructure deployments. * Implement secrets ...

Dast information

What are DAST jobs?

DAST stands for Dynamic Application Security Testing. Professionals in DAST roles use tools and techniques to test web applications for security vulnerabilities while the application is running, simulating real-world attacks to find issues like SQL injection, cross-site scripting, and other flaws. DAST specialists typically analyze application behavior, report vulnerabilities, and provide recommendations for mitigation. These roles are crucial in helping organizations maintain secure software by identifying and addressing security risks before attackers can exploit them.

What does a dast do?

A DAST (Dynamic Application Security Tester) is a cybersecurity professional who tests web applications for security vulnerabilities by simulating attacks in real-time. They use specialized tools to identify issues such as SQL injection, cross-site scripting, and other security flaws, often working closely with development teams to improve application security. Knowledge of security testing tools and web technologies is essential for this role.

What are the key skills and qualifications needed to thrive as a Dast, and why are they important?

I'm sorry, but 'Dast' does not appear to be a recognized real-world professional occupation. Please provide a valid job title for an accurate response.

What is the difference between Dast vs Penetration Tester?

AspectDastPenetration Tester
CertificationsCertified Web Application Defender, OSCP (optional)OSCP, CEH, CPT
Work EnvironmentAutomated testing tools, CI/CD pipelinesManual testing, on-site or remote assessments
Industry UsageWeb app security, DevSecOpsBroader security testing, including networks

While Dast (Dynamic Application Security Testing) uses automated tools to identify vulnerabilities in web applications during runtime, Penetration Testers perform manual and automated testing to find security flaws across systems. Dast is often integrated into development pipelines, whereas Penetration Testing is more comprehensive and manual, typically conducted periodically for in-depth security assessment.

How does DAST work?

A DAST (Dynamic Application Security Testing) professional uses automated tools to analyze running web applications for security vulnerabilities by simulating attacks. The process involves scanning the application in its operational state to identify issues like SQL injection or cross-site scripting, often requiring knowledge of security testing tools and protocols. Results help developers fix security flaws before deployment.

What are some common challenges faced by DAST (Dynamic Application Security Testing) professionals in their day-to-day work?

DAST professionals often encounter challenges such as handling dynamic and complex web applications that may have frequent code changes, which can impact test accuracy and coverage. They also need to manage false positives and ensure that security scans do not disrupt development workflows or impact application performance. Collaboration with development and DevOps teams is crucial for prioritizing and remediating vulnerabilities effectively. Staying current with evolving security threats and adjusting testing methodologies is also an ongoing part of the role.

What jobs pay $10,000 a month without a degree?

For a Dast (Data Application Security Tester) or similar cybersecurity roles, high-paying positions often require specialized skills and experience rather than formal degrees. Jobs such as freelance cybersecurity consulting, penetration testing, or security auditing can pay $10,000 or more monthly, especially for those with strong technical expertise, certifications like OSCP or CISSP, and a solid portfolio. These roles typically involve remote work, flexible schedules, and continuous learning to stay current with security threats.

What jobs pay 2000 a day?

High-paying jobs that can pay around $2,000 a day include specialized roles such as experienced surgeons, anesthesiologists, corporate lawyers, and certain high-level consultants or contractors. These positions typically require advanced education, certifications, and significant experience, often working in high-stakes environments or on a contract basis. Income levels vary based on industry, location, and workload.
What cities in Indiana are hiring for Dast jobs? Cities in Indiana with the most Dast job openings:
Sr. Principal Security Engineer, Application Security & Automation

Sr. Principal Security Engineer, Application Security & Automation

Lilly

Indianapolis, IN • On-site

$56.25 - $75/hr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired 2 days ago. Applications are no longer accepted.


Eli Lilly and Company rating

8.8

Company rating: 8.8 out of 10

Based on 62 frontline employees who took The Breakroom Quiz

10th of 72 rated pharmaceutical


Job description

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world.

What You\'ll Be Doing:

As an Application Security Engineer, you will operate at the intersection of software engineering and security engineering- leading platforms, writing code, building integrations, and designing automation. You will take part in Lilly\'s Secure SDLC program end-to-end, including SAST, DAST, SCA, and secret scanning tooling; secrets management; and our emerging software supply chain capabilities. You will use technology and apply LLM-based approaches to secure application and architecture design, vulnerability triage and remediation, and the delivery of secure‑by‑default patterns across Lilly’s development ecosystem.

How You\'ll Succeed:

  • Engineering-first mentality: You bring real software development experience and treat security problems as engineering problems, automating what can be automated, integrating deeply with developer workflows, and writing production-quality code.

  • AI fluency: You are genuinely excited about LLMs and agentic tooling and have built things with them. You understand MCP, agent harnesses, and how to wire LLMs into real workflows — and you can tell where AI meaningfully accelerates security work versus where it shouldn\'t be trusted.

  • Platform management: Success requires running AppSec tooling as platforms with clear SLAs, telemetry, and continuous improvement rather than one-off scans and tickets.

  • Secure coding credibility: You have written code in multiple languages and ecosystems and can speak the developer\'s language. When you flag a finding or propose a control, engineers trust that you understand the tradeoffs.

  • Developer partnership: You build leverage through partnership—meeting development teams where they are, shipping secure-by-default patterns, and making the secure path the path of the least resistance.

  • Build system security: You understand that CI/CD is itself a high-value target. You have opinions on GitHub Actions OIDC, pinning actions to commit SHAs, least-privilege runners, and protecting secrets and artifacts as they move through the pipeline.

Key Responsibilities:

  • Evolve one or more AppSec platforms within the Secure SDLC program.

  • Design and build automation within Security Architecture and Engineering.

  • Apply LLMs, agentic frameworks, MCP servers, and tool-calling patterns.

  • Partner with development teams on secure coding practices, threat modeling, and remediation of findings from SAST, DAST, SCA, and secret scanning tools.

  • Contribute to Lilly\'s Secure SDLC standards and vulnerability management policy, translating policy into enforceable pipeline and platform controls.

  • Support the secrets management rollout and migration of applications off legacy secret stores, including code-level guidance for SDK-based and injected consumption patterns.

  • Produce developer-facing content, reference architectures, secure patterns, short-form instructional content and reusable code samples.

  • Harden Lilly\'s CI/CD environment against software supply chain attacks— pinned actions, OIDC-based cloud auth, runner isolation, workflow permissions, and protection of build-time secrets and artifacts.

  • Partner with the Cloud Security team on Infrastructure-as-Code (IaC) security — extending secure-by-default patterns and developer guardrails from application code into the infrastructure that runs it.

Your Basic Qualifications:

  • Bachelor\'s Degree in Computer Science, Information Security, Software Engineering, or related fields.

  • At least 2 years of dedicated application security experience

  • At least 2 years of software development experience with individual contributions to production systems,

  • At least a total of 5 years of combined experience across both rigors.

  • Proven production coding experience in at least one of: Python, TypeScript/JavaScript, Java, Go, or C# — not solely in an advisory, review, or scripting capacity.

  • Experience building or integrating security automation within a GitHub environment, including GitHub Actions.

  • Familiarity with threat modeling in a professional setting

  • Hands-on experience with large language models (LLMs) in a professional or project context, such as prompt engineering, API integration, or workflow automation.

What You Should Bring:

  • Hands-on software development experience in at least one modern language (Python, TypeScript/JavaScript, Java, Go, or C#) with a track record of shipping working code- not just reviewing others\'.

  • Strong expertise in application security fundamentals—OWASP Top 10, CWE, secure coding practices, threat modeling, and vulnerability assessment.

  • Experience operating or deeply integrating with SAST, DAST, SCA, and secret scanning tools.

  • Genuine enthusiasm for and hands-on experience with LLMs, prompt engineering, agentic workflows, or LLM-powered tooling—bonus points for things you have actually built and shipped.

  • Familiarity with secrets management platforms and patterns and with software supply chain / artifact management.

  • Working knowledge of cloud environments (AWS preferred; Azure or GCP welcome) and containerized workloads (ECS, EKS, Docker).

  • Familiarity with IaC scanning and the IaC ecosystem (Terraform, CloudFormation, Kubernetes manifests)

  • Strong communication skills; ability to translate security requirements into actionable engineering guidance and to represent AppSec in conversations with engineering partners.

  • Commitment to staying ahead of with emerging AppSec threats, tooling, and AI/LLM capabilities.

Location & Work Flexibility
This role is based at our Corporate Center in Indianapolis, IN. We offer a flexible hybrid work model, with three days onsite and two days working remotely each week, supporting both collaboration and work‑life balance.

We are also open to considering fully remote candidates based on role requirements and business needs.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.

Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.


Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia Network, Black Employees at Lilly, Chinese Culture Network, Japanese International Leadership Network (JILN), Lilly India Network, Organization of Latinx at Lilly (OLA), PRIDE (LGBTQ+ Allies), Veterans Leadership Network (VLN), Women’s Initiative for Leading at Lilly (WILL), enAble (for people with disabilities). Learn more about all of our groups.

Actual compensation will depend on a candidate’s education, experience, skills, and geographic location.  The anticipated wage for this position is

$126,000 - $224,400

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

#WeAreLilly


What Eli Lilly and Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Eli Lilly logo

About Eli Lilly

Sourced by ZipRecruiter

Eli Lilly, based in Indianapolis, IN, US, is one of the pioneers in the pharmaceutical industry with a rich history dating back to 1876. This global pharmaceutical company focuses on discovering, developing, manufacturing and selling pharmaceutical products in approximately 120 countries. The company's product categories include endocrinology, oncology, cardiovascular, neuroscience, and immunology. Having invested over $9 billion in research and development in the past decade, Eli Lilly is also committed to creating high-quality medicines that meet real needs. As a recipient of several awards and recognitions, Eli Lilly is known for its focus on life-saving research and drug development. Their mission is to make medicines that help people live longer, healthier, and more active lives.

Industry

Pharmaceutical product wholesalers

Company size

10,000+ Employees

Headquarters location

Indianapolis, IN, US

Year founded

1876