1

Dast Jobs in Decatur, GA (NOW HIRING)

Build automation that embeds API security into CI/CD (policy-as-code, automated checks against Open API specs, secrets scanning, SAST/DAST/API testing, and runtime-to-ticket workflows). Reduce ...

... DAST), and penetration testing. 2. Lead efforts related to designing, planning, enhancing, and testing all cybersecurity technologies used throughout the enterprise including base-lining current ...

Senior Penetration Testing Engineer

Alpharetta, GA · On-site +1

$111K - $152K/yr

Experience managing application security tools, including SAST, DAST, SCA, and WAF solutions. * Experience with bug bounty programs, including platforms such as HackerOne and Bugcrowd. * Knowledge of ...

Help lead and execute all phases of the security engineering lifecycle, including threat modeling, secure design, testing (SAST, DAST, SCA), and vulnerability remediation. * Configure, integrate, and ...

Build automation that embeds API security into CI/CD (policy-as-code, automated checks against Open API specs, secrets scanning, SAST/DAST/API testing, and runtime-to-ticket workflows). Reduce ...

DevSecOps Engineer

Atlanta, GA · On-site

$50.75 - $69.50/hr

Design and own secure CI/CD pipelines using Azure DevOps and YAML-based workflows, integrating automated security scanning (SAST/DAST). * Compliance & Governance: Implement and maintain compliance ...

DevSecOps Engineer

Atlanta, GA

$50.75 - $69.50/hr

Design and own secure CI/CD pipelines using Azure DevOps and YAML-based workflows, integrating automated security scanning (SAST/DAST). * Compliance & Governance: Implement and maintain compliance ...

next page

Showing results 1-20

Dast information

See Decatur, GA salary details

$66.4K

$123.8K

$187K

How much do dast jobs pay per year?

As of Jun 26, 2026, the average yearly pay for dast in Decatur, GA is $123,832.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,500.00 and $141,600.00 per year, depending on experience, location, and employer.

What are DAST jobs?

DAST stands for Dynamic Application Security Testing. Professionals in DAST roles use tools and techniques to test web applications for security vulnerabilities while the application is running, simulating real-world attacks to find issues like SQL injection, cross-site scripting, and other flaws. DAST specialists typically analyze application behavior, report vulnerabilities, and provide recommendations for mitigation. These roles are crucial in helping organizations maintain secure software by identifying and addressing security risks before attackers can exploit them.

What does a dast do?

A DAST (Dynamic Application Security Tester) is a cybersecurity professional who tests web applications for security vulnerabilities by simulating attacks in real-time. They use specialized tools to identify issues such as SQL injection, cross-site scripting, and other security flaws, often working closely with development teams to improve application security. Knowledge of security testing tools and web technologies is essential for this role.

What are the key skills and qualifications needed to thrive as a Dast, and why are they important?

I'm sorry, but 'Dast' does not appear to be a recognized real-world professional occupation. Please provide a valid job title for an accurate response.

What is the difference between Dast vs Penetration Tester?

AspectDastPenetration Tester
CertificationsCertified Web Application Defender, OSCP (optional)OSCP, CEH, CPT
Work EnvironmentAutomated testing tools, CI/CD pipelinesManual testing, on-site or remote assessments
Industry UsageWeb app security, DevSecOpsBroader security testing, including networks

While Dast (Dynamic Application Security Testing) uses automated tools to identify vulnerabilities in web applications during runtime, Penetration Testers perform manual and automated testing to find security flaws across systems. Dast is often integrated into development pipelines, whereas Penetration Testing is more comprehensive and manual, typically conducted periodically for in-depth security assessment.

How does DAST work?

A DAST (Dynamic Application Security Testing) professional uses automated tools to analyze running web applications for security vulnerabilities by simulating attacks. The process involves scanning the application in its operational state to identify issues like SQL injection or cross-site scripting, often requiring knowledge of security testing tools and protocols. Results help developers fix security flaws before deployment.

What are some common challenges faced by DAST (Dynamic Application Security Testing) professionals in their day-to-day work?

DAST professionals often encounter challenges such as handling dynamic and complex web applications that may have frequent code changes, which can impact test accuracy and coverage. They also need to manage false positives and ensure that security scans do not disrupt development workflows or impact application performance. Collaboration with development and DevOps teams is crucial for prioritizing and remediating vulnerabilities effectively. Staying current with evolving security threats and adjusting testing methodologies is also an ongoing part of the role.

What jobs pay $10,000 a month without a degree?

For a Dast (Data Application Security Tester) or similar cybersecurity roles, high-paying positions often require specialized skills and experience rather than formal degrees. Jobs such as freelance cybersecurity consulting, penetration testing, or security auditing can pay $10,000 or more monthly, especially for those with strong technical expertise, certifications like OSCP or CISSP, and a solid portfolio. These roles typically involve remote work, flexible schedules, and continuous learning to stay current with security threats.

What jobs pay 2000 a day?

High-paying jobs that can pay around $2,000 a day include specialized roles such as experienced surgeons, anesthesiologists, corporate lawyers, and certain high-level consultants or contractors. These positions typically require advanced education, certifications, and significant experience, often working in high-stakes environments or on a contract basis. Income levels vary based on industry, location, and workload.
What are popular job titles related to Dast jobs in Decatur, GA? For Dast jobs in Decatur, GA, the most frequently searched job titles are:

API Security Engineer

Monitise

Alpharetta, GA

Full-time

Posted 21 days ago


Job description

Calling all innovators - find your future at Fiserv.

We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants and consumers to one another millions of times a day - quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we're involved. If you want to make an impact on a global scale, come make a difference at Fiserv.

Job Title

API Security Engineer

About your role:

You will help build a best-in-class API security program designed for the speed of modern financial services and shape how APIs are secured end-to-end, design through runtime, using cutting-edge protection technologies and analytics, partnering closely with top engineers across product, platform, and security. You will help turn API telemetry into actionable intelligence, reduce risk at scale, and raise the bar for secure engineering across the organization. As an API Security Engineer, you will focus on protecting critical API ecosystems by combining secure-by-design guidance, runtime protections, automation, and data-driven governance. You will be hands-on with modern API security capabilities (discovery, posture, threat detection, abuse prevention, and response) and help integrate them into the DevSecOps lifecycle so teams can move fast without compromising trust.

What you will do:

  • Runtime API protection:Implement and tune runtime controls (e.g., behavioral detection, anomaly and abuse prevention, bot defense, schema enforcement, mTLS/OAuth validation, rate limiting, and threat response) across API gateways, service mesh, and edge layers.

  • Secure API design guidance:Partner with engineering teams to define and promote secure API patterns (authentication/authorization, input validation, error handling, pagination, idempotency, versioning, and least-privilege access). Provide practical guidance aligned to OWASP API Security Top 10 and modern design standards (Open API/JSON Schema).

  • Automation and integration:Build automation that embeds API security into CI/CD (policy-as-code, automated checks against Open API specs, secrets scanning, SAST/DAST/API testing, and runtime-to-ticket workflows). Reduce friction through reusable tooling and self-service guardrails.

  • Data analytics and insights:Develop dashboards and analytics using API telemetry and security findings to measure risk, adoption, control effectiveness, and program outcomes. Translate signals into prioritized actions for engineering and leadership.

  • API security governance:Help define governance for API inventories, ownership, classification, security requirements, exception handling, and control validation. Drive consistent standards across teams while enabling delivery velocity.

  • DevSecOps lifecycle partnership:Work with product and platform teams to integrate security requirements into backlog planning, threat modeling, design reviews, testing, release readiness, and incident response.

  • Framework alignment (financial services):Map controls and program outcomes to relevant industry frameworks and expectations (e.g., NIST, ISO 27001, PCI DSS, FAPI, and OWASP guidance). Support audit readiness through clear control documentation and evidence automation.

  • Continuous improvement and innovation:Evaluate emerging technologies and techniques for API discovery, posture management, and runtime detection. Pilot, measure, and scale what works.

What you will need to have:

  • 5+ years related IT and cyber protection experience desired.

  • Strong foundation in API security concepts: authN/authZ (OAuth2/OIDC, JWT), session/token handling, scopes/claims, rate limiting, schema validation, and common API abuse patterns.

  • Practical experience with runtime protection in one or more of API gateways, WAF/WAAP, service mesh, ingress controllers, or specialized API security platforms.

  • Experience building automation in CI/CD and cloud-native environments (policy-as-code, scripting, pipelines, Git-based workflows).

  • Ability to use data and telemetry (logs, traces, metrics) to detect issues, tell a clear story, and drive priorities and working knowledge of secure software development and DevSecOps practices, and the ability to influence engineering outcomes through partnerships.

  • Comfort collaborating across security, SRE, platform, and application teams with clear communication, pragmatic decision-making, and strong follow-through.

  • Expert knowledge of and experience with maintaining cyber technologies that can protect operational API systems, such as:

    • Traceable

    • Salt Security

    • NoName

  • Bachelor's degree in computer science, or a relevant field, or an equivalent combination of education, work, and/or military experience

What would be great to have:

  • Experience with Open API tooling, API testing, fuzzing, and contract testing.

  • Familiarity with threat modeling approaches and abuse-case analysis for APIs.

  • Experience aligning security controls to financial industry expectations and. producing evidence that stands up to audit scrutiny.

  • CISSP or other professional cyber certification desirable.

How you'll work

  • This role is on-site Monday through Friday. Fiserv considers in-person collaboration to be an essential part of this role as in-person office experiences help you with your overall onboarding experience and leads to stronger productivity.

Travel

  • Approximately 10% travel off-site or to other office locations is expected.

Sponsorship

  • You must currently possess valid and unrestricted U.S. work authorization to be considered for this role. Individuals with temporary visas including, but not limited to, F-1 (OPT, CPT, STEM), H-1B, H-2, or TN, or any candidate requiring sponsorship, now or in the future, will not be considered.

#LI-RM1

Salary Range

$110,000.00 - $186,000.00

These pay ranges apply to employees in New Jersey and New York. Pay ranges for employees in other states may differ.

It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.

For incentive eligible associates, the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Company's sole discretion.

Thank you for considering employment with Fiserv. Please:

  • Apply using your legal name
  • Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).

Our commitment to Equal Opportunity:

Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, gender, gender identity, sexual orientation, age, disability, protected veteran status, or any other category protected by law.

If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process, please contactAskHR.US@fiserv.com. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiserv's Disability Accommodation Policy for additional information.

Note to agencies:

Fiserv does not accept resume submissions from agencies outside of existing agreements.Please do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.

Warning about fake job posts:

Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.