1

Dast Jobs (NOW HIRING)

... DAST/Secrets/SBOM) in pipelines. Requirements • Strong with GitHub Actions/Azure DevOps/GitLab CI/Jenkins; Terraform; Kubernetes; secrets & policy-as-code. • Proven stakeholder management and ...

SAST, DAST, IAST, SCA * Web, Mobile & API Security Testing * Manual Penetration Testing & Business Logic Testing * Threat Modelling * Vulnerability Management * Secure Code Review * CI/CD Security ...

Automate security gates in CI/CD pipelines (SAST, DAST, dependency scanning, secrets detection). * Security Architecture & Controls * Design secure system and API architectures for multi-tenant cloud ...

DevSecOps Engineer IV

$54 - $74/hr

... DAST, SCA) into development workflows. • Ability to collaborate with developers to enforce secure coding practices • 3 year's Expertise Secure Coding Standards enforced during development • ...

Showing results 41-60

Dast information

See salary details

$68K

$126.8K

$191.5K

How much do dast jobs pay per year?

As of Aug 15, 2026, the average yearly pay for dast in the United States is $126,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,000.00 and $145,000.00 per year, depending on experience, location, and employer.

What is a DAST?

DAST stands for Dynamic Application Security Testing. Professionals in DAST roles use tools and techniques to test web applications for security vulnerabilities while the application is running, simulating real-world attacks to find issues like SQL injection, cross-site scripting, and other flaws. DAST specialists typically analyze application behavior, report vulnerabilities, and provide recommendations for mitigation. These roles are crucial in helping organizations maintain secure software by identifying and addressing security risks before attackers can exploit them.

What are the key skills and qualifications needed to thrive as a DAST?

I'm sorry, but 'Dast' does not appear to be a recognized real-world professional occupation. Please provide a valid job title for an accurate response.

What is the difference between Dast vs Penetration Tester?

AspectDastPenetration Tester
CertificationsCertified Web Application Defender, OSCP (optional)OSCP, CEH, CPT
Work EnvironmentAutomated testing tools, CI/CD pipelinesManual testing, on-site or remote assessments
Industry UsageWeb app security, DevSecOpsBroader security testing, including networks

While Dast (Dynamic Application Security Testing) uses automated tools to identify vulnerabilities in web applications during runtime, Penetration Testers perform manual and automated testing to find security flaws across systems. Dast is often integrated into development pipelines, whereas Penetration Testing is more comprehensive and manual, typically conducted periodically for in-depth security assessment.

What are some common challenges faced by DAST professionals in their day-to-day work?

DAST professionals often encounter challenges such as handling dynamic and complex web applications that may have frequent code changes, which can impact test accuracy and coverage. They also need to manage false positives and ensure that security scans do not disrupt development workflows or impact application performance. Collaboration with development and DevOps teams is crucial for prioritizing and remediating vulnerabilities effectively. Staying current with evolving security threats and adjusting testing methodologies is also an ongoing part of the role.
More about Dast jobs

What cities are hiring for Dast jobs?

Cities with the most Dast job openings:

What states have the most Dast jobs?

States with the most job openings for Dast jobs include:

Infographic showing various Dast job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 1% Part Time, and 8% Contract. Highlights an 73% Physical, 8% Hybrid, and 19% Remote job distribution, with an average salary of $126,833 per year, or $61 per hour.

Application Security Engineer (Senior) ID71672

AgileEngine

Irving, IL • Remote

$51.25 - $68.50/hr

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.
WHY JOIN US
If you\'re looking for a place to grow, make an impact, and work with people who care, we\'d love to meet you!
ABOUT THE ROLE
We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program. You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks. The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus.
WHAT YOU WILL DO
- Engineer and deploy AI-enabled secure code scanning capabilities and “Golden Images” to drive secure-from-the-start adoption;
- Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows;
- Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise;
- Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance.
MUST HAVES
- You must be authorized to work for ANY employer in the US (e.g., Green card holders, TN visa holders, GC EAD, H4 EAD, U4U with EAD), as we are unable to sponsor or take over employment visa sponsorship at this time;
- 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps;
- Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code);
- Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems;
- Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks;
- Upper-intermediate English level.
NICE TO HAVES
- Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation;
- Advanced application threat modeling experience.
PERKS AND BENEFITS
- Professional growth: Mentorship, TechTalks, and personalized growth roadmaps.
- Competitive compensation: USD-based pay with education, fitness, and team activity budgets.
- Exciting projects: Modern solutions with Fortune 500 and top product companies.
- Flextime: Flexible schedule with remote and office options.