1

Dast Jobs in Virginia (NOW HIRING)

Cyber Technical Engineer

Arlington, VA · On-site

$70K - $115K/yr

Perform and integrate automated security scanning tools (e.g., SAST, SCA, DAST) and compliance checks into the CI/CD process. * Write and maintain scripts in Python, Bash, and other languages to ...

AVP - Information Security - Americas

Norfolk, VA · On-site

$103K - $139K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Minimum of 2 years of experience with application security and SDLC integration (SAST, DAST, SCA, secure code review) * Working knowledge of SIEM, XDR, and SOAR platforms - including tuning ...

AVP - Information Security - Americas

Norfolk, VA · On-site

$103K - $139K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Minimum of 2 years of experience with application security and SDLC integration (SAST, DAST, SCA, secure code review) * Working knowledge of SIEM, XDR, and SOAR platforms - including tuning ...

Experience in SAST/DAST or container security scanning. * Kubernetes experience. * DevSecOps exposure. * Security+ certification. * Experience in Agile/Scrum. Target salary range: $160,001 - $200,000.

Responsibilities : • Build and maintain GitLab CI/CD pipelines for micro-frontends and microservices. • Implement automated testing, security scanning, including SAST/DAST, and deployment ...

Senior DevSecOps Engineer

Arlington, VA · On-site

$131K - $180K/yr

... DAST) directly into the CI/CD pipeline. B. On-Contract Responsibilities ● Automate infrastructure and workflows using IaC (Terraform, Ansible); build and manage CI/CD pipelines for secure ...

Experience in SAST/DAST or container security scanning. * Kubernetes experience. * DevSecOps exposure. * Security+ certification. * Experience in Agile/Scrum. Target salary range: $160,001 - $200,000.

Experience in SAST/DAST or container security scanning. * Kubernetes experience. * DevSecOps exposure. * Security+ certification. * Experience in Agile/Scrum. Target salary range: $160,001 - $200,000.

Junior DevSecOps Engineer

Reston, VA · On-site

$80K - $90K/yr

... DAST/SCA) and policy-as-code into pipelines - Automate compliance evidence for FedRAMP/NIST controls - Support environment provisioning and deployment automation (blue/green, canary) - Embed AI ...

... DAST/SCA) and policy-as-code into pipelines - Automate compliance evidence for FedRAMP/NIST controls - Support environment provisioning and deployment automation (blue/green, canary) - Embed AI ...

Junior DevSecOps Engineer

Reston, VA · On-site

$80K - $90K/yr

... DAST/SCA) and policy-as-code into pipelines - Automate compliance evidence for FedRAMP/NIST controls - Support environment provisioning and deployment automation (blue/green, canary) - Embed AI ...

DevSecOps Engineer

Reston, VA · On-site

$120K - $140K/yr

... DAST/SCA) and policy-as-code into pipelines - Automate compliance evidence for FedRAMP/NIST controls - Support environment provisioning and deployment automation (blue/green, canary) - Embed AI ...

Showing results 41-60

Dast information

What is a DAST?

DAST stands for Dynamic Application Security Testing. Professionals in DAST roles use tools and techniques to test web applications for security vulnerabilities while the application is running, simulating real-world attacks to find issues like SQL injection, cross-site scripting, and other flaws. DAST specialists typically analyze application behavior, report vulnerabilities, and provide recommendations for mitigation. These roles are crucial in helping organizations maintain secure software by identifying and addressing security risks before attackers can exploit them.

What are the key skills and qualifications needed to thrive as a DAST?

I'm sorry, but 'Dast' does not appear to be a recognized real-world professional occupation. Please provide a valid job title for an accurate response.

What is the difference between Dast vs Penetration Tester?

AspectDastPenetration Tester
CertificationsCertified Web Application Defender, OSCP (optional)OSCP, CEH, CPT
Work EnvironmentAutomated testing tools, CI/CD pipelinesManual testing, on-site or remote assessments
Industry UsageWeb app security, DevSecOpsBroader security testing, including networks

While Dast (Dynamic Application Security Testing) uses automated tools to identify vulnerabilities in web applications during runtime, Penetration Testers perform manual and automated testing to find security flaws across systems. Dast is often integrated into development pipelines, whereas Penetration Testing is more comprehensive and manual, typically conducted periodically for in-depth security assessment.

What are some common challenges faced by DAST professionals in their day-to-day work?

DAST professionals often encounter challenges such as handling dynamic and complex web applications that may have frequent code changes, which can impact test accuracy and coverage. They also need to manage false positives and ensure that security scans do not disrupt development workflows or impact application performance. Collaboration with development and DevOps teams is crucial for prioritizing and remediating vulnerabilities effectively. Staying current with evolving security threats and adjusting testing methodologies is also an ongoing part of the role.

What cities in Virginia are hiring for Dast jobs?

Cities in Virginia with the most Dast job openings:

Infographic showing various Dast job openings in Virginia as of August 2026, with employment types broken down into 91% Full Time, 3% Part Time, and 6% Contract. Highlights an 73% Physical, 8% Hybrid, and 19% Remote job distribution.

Cyber Technical Engineer

Technomics Inc

Arlington, VA • On-site

$70K - $115K/yr

Full-time

Re-posted 21 days ago


Job description

Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster. We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.
Analysts use problem-solving principles, processes and methods and complementary software applications to support client engagements and have a direct and significant impact on deliverables to clients. Your work will be guided by more experienced team members, but you will work with autonomy.
Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems.
This position may be located in Arlington, VA (Headquarters), Washington D.C., Pentagon, Springfield, VA., Chantilly, VA., Tysons Corner, VA.
Overview
This position plays a critical role in implementing secure CI/CD pipelines, container security, and Risk Management Framework (RMF) compliance activities. The ideal candidate has foundational experience across DevSecOps, containerization, and security engineering and is eager to grow in a fast-paced, mission-critical environment.
Roles and Responsibilities
  • Implement and maintain secure CI/CD pipelines using GitLab CI/CD and automation tools.
  • Support the RMF process, including System Security Plan (SSP) development, control implementation, Plan of Action and Milestones (POA&M), and preparation for ATO (Authority to Operate).
  • Support the development and maintenance of a DevSecOps automation framework for RMF compliance.
  • Assist in the design, development, and deployment of secure containerized applications using Docker, Podman and Kubernetes.
  • Apply DoD STIGs, CIS Benchmarks, and other hardening guides.
  • Perform and integrate automated security scanning tools (e.g., SAST, SCA, DAST) and compliance checks into the CI/CD process.
  • Write and maintain scripts in Python, Bash, and other languages to automate system tasks, scans, and reports.
  • Collaborate with security, development, and operations teams to design secure, scalable infrastructure and workflows.
  • Collaborate with development and security teams to remediate vulnerabilities and implement security best practices.
  • Create and manage tickets in Jira, participate in Agile ceremonies, and support backlog grooming with technical input.
  • Perform basic Linux system administration, configuration, and troubleshooting.
  • Document system designs, security controls, and standard operating procedures.
  • Map security controls to NIST 800-53 and other relevant DoD security standards.
  • Stay up-to-date on the latest RMF guidance, security threats, and DevSecOps technologies.

Qualifications
  • Bachelor's degree in computer science, Cybersecurity, Information Systems, or a related technical field (or equivalent work experience).
  • 1-3 years of hands-on experience in DevSecOps, Cybersecurity, or Cloud Engineering.
  • Basic understanding of the NIST RMF and experience assisting in the ATO process.
  • Working knowledge of Docker, Podman, Kubernetes, and container orchestration platforms.
  • Experience with GitLab CI/CD pipelines and security automation tools.
  • Familiarity with Linux commands and system administration.
  • Scripting proficiency in Python and Bash.
  • Exposure to vulnerability scanning tools like Nessus, and integration of SAST, SCA, DAST into DevOps pipelines.
  • Experience applying STIGs, DISA SRGs, or hardening guidelines to systems.
  • Strong communication skills, with the ability to document and present findings effectively.
  • Knowledge of NIST SP 800-53, DoDI 8500.01, and DoDI 8510.01
  • Active DoW Secret Clearance

Desired Qualifications
  • Experience with eMASS or other GRC (Governance, Risk, and Compliance) Tools.
  • Familiarity with DoW security policies and procedures.
  • Experience with container security and Kubernetes security.
  • Familiarity with cloud platforms (AWS, Azure).
  • Exposure to infrastructure as code (IaC) using Terraform, Ansible, or similar tools.
  • Experience with tools like SCAP, OpenSCAP, or ACAS.
  • Familiarity with Agile/Scrum processes and tools (Jira, Confluence)
  • Certifications such as IAT Level II/IAM Level I (e.,g CompTIA Security+), Certified Kubernetes Administrator (CKA), others as applicable.
  • Familiarity with combat systems such as SSDS and AEGIS.
  • A working knowledge of cyber regulations.

Salary range: $70,000- 115,000 USD
The salary range listed is one part of our total compensation package, which may also include bonuses, incentives and benefits. Individual compensation is determined based on qualifications such as relevant years of experience, education, certifications and geographic location
Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status.