1

Dast Jobs (NOW HIRING)

Application Security Engineer

$60.25 - $80.25/hr

Embed sast / dast / sca into agent ci/cd pipelines. * Build and maintain an ai/llm software bill of materials (sbom) capability. * Lead threat modeling for agents against the owasp llm top-10 and ...

Implement both SaaS-based security testing (SaaST) and dynamic application security testing (DAST) for major platforms. * Focus primarily on security and testing for core business systems: Salesforce ...

NJ · On-site

$68 - $97/hr

SAST, DAST, IAST, SCA * Web, Mobile & API Security Testing * Manual Penetration Testing & Business Logic Testing * Threat Modelling * Vulnerability Management * Secure Code Review * CI/CD Security ...

Embed security into the SDLC and CI/CD pipelines using SAST, DAST, SCA, and other security tools. * Ensure secure coding practices aligned with OWASP Top 10 and API Security . * Secure cloud-native ...

DevSecOps Lead/Architect

Alameda, CA · On-site

$180 - $240/hr

Integrate security into CI/CD pipelines, including SAST, DAST, SCA, and dependency scanning using GitHub. * Lead investigations and response to complex cybersecurity incidents, including malware ...

... DAST/Secrets/SBOM) in pipelines. Requirements • Strong with GitHub Actions/Azure DevOps/GitLab CI/Jenkins; Terraform; Kubernetes; secrets & policy-as-code. • Proven stakeholder management and ...

DevOps

San Jose, CA · On-site

$61.75 - $84.75/hr

Responsibilities : • DevOps, DevSecOps and Security Architecture with NIST CSF • AWS Cloud, Atlassian/BitBucket, etc. from a security perspective. • SAST/DAST/SCA/IAST and impact of integration ...

Showing results 21-40

Dast information

See salary details

$68K

$126.8K

$191.5K

How much do dast jobs pay per year?

As of Sep 5, 2026, the average yearly pay for dast in the United States is $126,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,000.00 and $145,000.00 per year, depending on experience, location, and employer.

What is a DAST?

DAST stands for Dynamic Application Security Testing. Professionals in DAST roles use tools and techniques to test web applications for security vulnerabilities while the application is running, simulating real-world attacks to find issues like SQL injection, cross-site scripting, and other flaws. DAST specialists typically analyze application behavior, report vulnerabilities, and provide recommendations for mitigation. These roles are crucial in helping organizations maintain secure software by identifying and addressing security risks before attackers can exploit them.

What are the key skills and qualifications needed to thrive as a DAST?

I'm sorry, but 'Dast' does not appear to be a recognized real-world professional occupation. Please provide a valid job title for an accurate response.

What are some common challenges faced by DAST professionals in their day-to-day work?

DAST professionals often encounter challenges such as handling dynamic and complex web applications that may have frequent code changes, which can impact test accuracy and coverage. They also need to manage false positives and ensure that security scans do not disrupt development workflows or impact application performance. Collaboration with development and DevOps teams is crucial for prioritizing and remediating vulnerabilities effectively. Staying current with evolving security threats and adjusting testing methodologies is also an ongoing part of the role.

What is the difference between Dast vs Penetration Tester?

AspectDastPenetration Tester
CertificationsCertified Web Application Defender, OSCP (optional)OSCP, CEH, CPT
Work EnvironmentAutomated testing tools, CI/CD pipelinesManual testing, on-site or remote assessments
Industry UsageWeb app security, DevSecOpsBroader security testing, including networks

While Dast (Dynamic Application Security Testing) uses automated tools to identify vulnerabilities in web applications during runtime, Penetration Testers perform manual and automated testing to find security flaws across systems. Dast is often integrated into development pipelines, whereas Penetration Testing is more comprehensive and manual, typically conducted periodically for in-depth security assessment.

More about Dast jobs

What cities are hiring for Dast jobs?

Cities with the most Dast job openings:

What states have the most Dast jobs?

States with the most job openings for Dast jobs include:

What job categories do people searching Dast jobs look for?

The top searched job categories for Dast jobs are:

Infographic showing various Dast job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 1% Part Time, and 5% Contract. Highlights an 79% Physical, 7% Hybrid, and 14% Remote job distribution, with an average salary of $126,833 per year, or $61 per hour.

W2 Contract || Vulnerability Management || Somerset, NJ || (Day-1-Oniste)

Noblesoft Technologies

Somerset, NJ • On-site

$40 - $50/hr

Contractor

Re-posted 4 days ago


Job description

Job Title: Vulnerability Management

Location: Somerset, NJ (Onsite)

Look for profiles with vulnerability management, Rapid7, Qualys, Attack Surface Management, OWASP ZAP, Burp Suite etc.

Job Description

We are seeking a technically strong Vulnerability Management Analyst / Engineer to lead vulnerability identification, prioritization, and remediation across infrastructure, web applications, and cloud environments. This role combines hands-on scanning, threat-informed prioritization, and cross-functional remediation coordination to reduce risk and improve time to remediation.

Experience

•           5+ years of vulnerability management, application security, or penetration testing experience preferred.

Required Skills

  • 5+ years of experience in Vulnerability Management, Application Security, or Penetration Testing
  • Hands-on experience with:
    • Qualys VMDR
    • Rapid7 InsightVM
    • Tenable / Nessus
    • Wiz
    • Burp Suite
    • OWASP ZAP
    • Veracode
    • Checkmarx
    • InsightAppSec
  • Strong understanding of:
    • Vulnerability Management Lifecycle
    • Attack Surface Management (ASM)
    • Web Application Security
    • DAST Testing
    • OWASP Top 10
    • SANS Top 25
    • CVSS, EPSS, and CISA KEV
  • Experience performing manual validation of vulnerabilities including:
    • SQL Injection (SQLi)
    • Cross-Site Scripting (XSS)
    • CSRF
    • SSRF
    • IDOR
    • Authentication Bypass
  • Experience with cloud security across AWS, Azure, and GCP
  • Strong scripting experience with Python, PowerShell, or Bash
  • Experience with vulnerability remediation tracking, reporting, and executive dashboards

Preferred Qualifications

  • OSCP, GWAPT, CEH, CSSLP, or equivalent certifications
  • Experience with penetration testing and application security assessments
  • Knowledge of PCI-DSS, NIST, CIS Controls, ISO 27001, HIPAA, and GDPR
  • Experience with external attack surface monitoring and exposure management tools such as Shodan, SecurityScorecard, BitSight, and SSLScan
  • Experience with container security and CI/CD security integrations

Responsibilities

  • Manage the end-to-end vulnerability management lifecycle
  • Conduct vulnerability assessments across infrastructure, cloud, applications, and web environments
  • Perform DAST and manual web application security testing
  • Prioritize vulnerabilities using CVSS, EPSS, threat intelligence, and business impact
  • Partner with Infrastructure, DevOps, Engineering, and Security teams to drive remediation
  • Develop executive-level risk and remediation reporting
  • Respond to critical and zero-day vulnerabilities
  • Improve vulnerability management processes and security posture across the organization

Keywords

Vulnerability Management, Attack Surface Management, ASM, Qualys, Rapid7, InsightVM, Tenable, Nessus, Wiz, Burp Suite, OWASP ZAP, Veracode, Checkmarx, InsightAppSec, DAST, Application Security, Web Security, Cloud Security, AWS, Azure, GCP, CVSS, EPSS, CISA, Python, Penetration Testing, OWASP Top 10.