1

Dast Jobs (NOW HIRING)

No H1B Transfer Candidates OR OPT/CPT This is a DevSecOps Role and not DevOps. Strong Azure Services, SAST/DAST , GitHub, Kubernetes, AKS , Terraform and Python Scripting experience is required. Our ...

$58.75 - $78.50/hr

You will support security activities ranging from SAST/DAST analysis to API security testing, collaborate with our Security Champions to scale secure development practices, and contribute to the ...

Security Engineer

Minneapolis, MN · On-site

$69.23 - $115.38/hr

Experience with dynamic application security testing (DAST) tools and vulnerability assessment methodologies * Familiarity with CI/CD pipelines and automated security testing integrations

next page

Showing results 1-20

Dast information

See salary details

$68K

$126.8K

$191.5K

How much do dast jobs pay per year?

As of May 30, 2026, the average yearly pay for dast in the United States is $126,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,000.00 and $145,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Dast, and why are they important?

I'm sorry, but 'Dast' does not appear to be a recognized real-world professional occupation. Please provide a valid job title for an accurate response.

What are some common challenges faced by DAST (Dynamic Application Security Testing) professionals in their day-to-day work?

DAST professionals often encounter challenges such as handling dynamic and complex web applications that may have frequent code changes, which can impact test accuracy and coverage. They also need to manage false positives and ensure that security scans do not disrupt development workflows or impact application performance. Collaboration with development and DevOps teams is crucial for prioritizing and remediating vulnerabilities effectively. Staying current with evolving security threats and adjusting testing methodologies is also an ongoing part of the role.

What are DAST jobs?

DAST stands for Dynamic Application Security Testing. Professionals in DAST roles use tools and techniques to test web applications for security vulnerabilities while the application is running, simulating real-world attacks to find issues like SQL injection, cross-site scripting, and other flaws. DAST specialists typically analyze application behavior, report vulnerabilities, and provide recommendations for mitigation. These roles are crucial in helping organizations maintain secure software by identifying and addressing security risks before attackers can exploit them.

What is the difference between Dast vs Penetration Tester?

AspectDastPenetration Tester
CertificationsCertified Web Application Defender, OSCP (optional)OSCP, CEH, CPT
Work EnvironmentAutomated testing tools, CI/CD pipelinesManual testing, on-site or remote assessments
Industry UsageWeb app security, DevSecOpsBroader security testing, including networks

While Dast (Dynamic Application Security Testing) uses automated tools to identify vulnerabilities in web applications during runtime, Penetration Testers perform manual and automated testing to find security flaws across systems. Dast is often integrated into development pipelines, whereas Penetration Testing is more comprehensive and manual, typically conducted periodically for in-depth security assessment.

More about Dast jobs
What cities are hiring for Dast jobs? Cities with the most Dast job openings:
What states have the most Dast jobs? States with the most job openings for Dast jobs include:
Infographic showing various Dast job openings in the United States as of May 2026, with employment types broken down into 91% Full Time, 1% Part Time, and 8% Contract. Highlights an 75% Physical, 8% Hybrid, and 17% Remote job distribution, with an average salary of $126,833 per year, or $61 per hour.

Cyber Security Application Security (AppSec) Lead

Technoidentity

Houston, TX

$56 - $75/hr

Other

Posted yesterday


Job description

About Techno Identity:
Technoidentity is a product-based company focused on designing and developing innovative, scalable digital solutions. With a strong emphasis on quality, performance, and user-centric design, the company leverages modern technologies to build reliable software products that address evolving business needs. Technoidentity is committed to delivering impactful solutions that drive efficiency, growth, and long-term value for its clients.

Job Description:

  • Leverage Security Scorecard and vulnerability intel sources on application side (i.e.) Invicti, Checkmarx, Wiz to analyze open Vulnerabilities, risk posture, prioritize vulnerabilities, and align remediation based on CVSS scores and business criticality.
  • Act as a hands-on technical lead, actively fixing vulnerabilities in code and setting remediation standards for the team.
  • Should have excellent knowledge of SDLC controls including PR checks, severity thresholds, branch protection, and release gates.
  • Perform secure code reviews and directly remediate vulnerabilities such as injection flaws, authentication issues, insecure APIs, and data exposure risks.
  • Translate SAST/DAST findings into practical code fixes (input validation, encryption, auth controls, secure configurations).
  • Partner with developers to triage vulnerabilities (CWE/OWASP) and drive faster remediation (MTTR reduction).
  • Demonstrate strong development expertise (.NET / Java / APIs / Web apps) with ability to debug, refactor, and resolve security issues.
  • Integrate security into CI/CD pipelines by implementing automated scanning, security gates, and remediation workflows.
  • Oversee cloud vulnerability remediation (Wiz), prioritizing internet-facing risks, identity exposure, and misconfigurations.
  • Establish and track AppSec KPIs (MTTR, false positives, recurring vulnerabilities, SLA adherence) and present insights to stakeholders.
  • Lead and mentor teams by providing hands-on guidance, enforcing secure coding practices, and driving continuous improvement in vulnerability remediation and risk reduction.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology, or related field, with 8–12+ years of experience in application development and security.
  • Proven hands-on experience in secure application development (.NET / Java / APIs / Web apps) with strong expertise in identifying and fixing code-level vulnerabilities.
  • Deep knowledge of application security practices, including SAST/DAST tools (Checkmarx, Invicti), OWASP Top 10, CWE, and CVSS-based risk prioritization.
  • Strong experience in DevSecOps and CI/CD integration, including implementing security gates, automated scanning, and secure SDLC controls.