1

Security Testing Web Application Sast Jobs (NOW HIRING)

Security Engineer (Web Application)

Arlington, VA · On-site

$67.50 - $90.25/hr

Security Engineer (Web Application) Location: Arlington, VA Security Clearance: Secret Duties and ... Application testing will require authenticated and non-authenticated testing to ensure full ...

Application Security Engineer

Herndon, VA · On-site

$60.50 - $80.75/hr

Strong understanding of application security testing concepts and operational support for SAST, DAST and IDE plug-in environments. * Hands-on capability with enterprise web application security and ...

Application Security Engineer

Herndon, VA · On-site

$60.50 - $80.75/hr

Strong understanding of application security testing concepts and operational support for SAST, DAST and IDE plug-in environments. * Hands-on capability with enterprise web application security and ...

$58.75 - $78.50/hr

You will support security activities ranging from SAST/DAST analysis to API security testing ... Strong understanding of common web application vulnerabilities (OWASP Top 10, SANS Top 25) and ...

OR

$58.75 - $78.50/hr

Secure SDLC (Software Development Life Cycle), DAST (Dynamic Application Security Testing), and SAST (Static Application Security Testing) experience * Demonstrated understanding of web application ...

Application Security Testing Manager

Austin, TX · On-site

$58.25 - $77.75/hr

The Application Security Testing Manager will lead the strategy and execution of application ... SAST, DAST, SCA, and manual code review. • Promote secure design practices through threat ...

Security testing at scale: Operate and tune AppSec tooling for SAST, DAST, and SCA, and ensure ... Strong understanding of modern web application security, common attack patterns, and secure design ...

next page

Showing results 1-20

Security Testing Web Application Sast information

See salary details

$29

$66

$96

How much do security testing web application sast jobs pay per hour?

As of Jun 6, 2026, the average hourly pay for security testing web application sast in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is Security Testing Web Application SAST?

Security Testing Web Application SAST (Static Application Security Testing) is a process used to identify vulnerabilities in the source code, bytecode, or binary code of web applications without executing the program. SAST helps developers find security flaws early in the software development lifecycle by scanning the application's codebase for common vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure data handling. This proactive approach enables organizations to fix security issues before deployment, reducing the risk of cyberattacks and data breaches. SAST tools integrate with development environments to provide real-time feedback and facilitate secure coding practices.

What are the key skills and qualifications needed to thrive as a Security Testing Web Application SAST specialist, and why are they important?

To thrive as a Security Testing Web Application SAST specialist, you need expertise in application security, software development principles, and vulnerability assessment, often supported by a degree in computer science or cybersecurity. Familiarity with static application security testing (SAST) tools like SonarQube, Checkmarx, or Veracode and relevant certifications such as CISSP or CEH is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify vulnerabilities and relay findings to development teams. These skills are crucial for proactively securing applications, meeting compliance standards, and reducing organizational risk from software vulnerabilities.

What is the difference between Security Testing Web Application Sast vs Penetration Tester?

AspectSecurity Testing Web Application SastPenetration Tester
CertificationsOWASP, CEH, CISSPOSCP, CEH, GPEN
Work EnvironmentAutomated testing, code analysis, CI/CD pipelinesManual testing, live environment assessments
Industry UsageSoftware development, DevSecOpsSecurity consulting, offensive security

Security Testing Web Application Sast focuses on automated static analysis of source code to identify vulnerabilities early in the development process. Penetration Testers perform manual and automated testing to exploit vulnerabilities in live systems. While SAST is integrated into development workflows, penetration testing is often conducted post-deployment to assess real-world security. Both roles require security certifications and are vital in securing web applications, but they differ in approach and timing.

What are some common challenges faced by professionals performing SAST (Static Application Security Testing) on web applications?

One common challenge in SAST for web applications is accurately identifying and prioritizing true security vulnerabilities while minimizing false positives, which can be time-consuming. Additionally, integrating SAST tools seamlessly into the development pipeline and ensuring timely feedback to developers can require collaboration across teams. Security testers also need to stay updated on evolving threats and new coding practices, as web application frameworks and technologies frequently change. Effective communication with developers is essential to help them understand and remediate vulnerabilities efficiently.

Senior Application Security Engineer

Network Temp Inc

Manhattan, NY

$64.50 - $86/hr

Other

Posted 4 days ago


Job description

Description

TASKS:

? Perform comprehensive cybersecurity risk analysis, identifying and prioritizing risks specifically 

related to application security.

? Develop, socialize, and implement security strategies to address vulnerabilities in web 

applications, microservices, APIs, and mobile applications.

? Track and manage progress against security plans, ensuring timely remediation of identified 

vulnerabilities.

? Lead the security implementation in application development projects, ensuring "secure by 

design" practices.

? Create and maintain architecture diagrams, outlining secure communication flows, and 

develop both high-level and low-level security design documents.

? Troubleshoot and resolve application security issues in collaboration with internal teams and 

external vendors.

? Translate application compliance requirements into specific security controls, recommending 

compensating measures where appropriate.

? Regularly report on the organization's security posture, with a focus on application 

vulnerabilities, to senior management.

? Perform/coordinate application vulnerability assessments and ensure timely remediation in 

collaboration with the Development, IT, and Systems teams.

? Implement secure coding practices, perform static and dynamic application security testing 

(SAST/DAST), and support developers with secure code reviews.

? Monitor security incidents and respond to application-level threats, ensuring quick resolution 

of potential vulnerabilities.

? Establish and enforce secure configurations for applications and their underlying 

infrastructure, such as databases and APIs.

? Perform threat simulations to detect risks and recommend improvements for securing 

application designs, API security, identity management, and access control measures.

? Collaborate with teams to ensure continuous integration and continuous deployment (CI/CD) 

pipelines incorporate security control


Requirements

Senior Application Security Engineer 

Mandatory Skills/Experience 

12 years of experience in application security, with a proven track record of conducting vulnerability assessments, penetration testing, and secure code reviews. Extensive experience in secure application development, including knowledge of security frameworks like OWASP Top 10, and the ability to guide development teams in implementing secure coding practices. Proficiency in Software Composition Analysis (SCA) tools (e.g., Veracode, AppSec) for identifying and managing vulnerabilities in open-source libraries and third-party components. Advanced knowledge of static and dynamic application security testing (SAST/DAST) tools (e.g., Veracode, AppSec, Burp Suite) and integrating these tools into CI/CD pipelines for automated security checks. Strong cloud security expertise, including securing applications and workloads on AWS, Azure, or GCP, and experience with Web Application Firewalls (WAF) and cloud-native security services. Desirable Skills/Experience Advanced cloud security experience: Experience securing cloud environments (AWS, Azure, GCP) with tools like Web Application Firewalls (WAF), and implementing IAM, encryption, and monitoring tools. Experience with scripting and automation, using Python, Bash, or PowerShell, to automate security tasks, integrate security testing tools, and improve the efficiency of security operations. Strong communication skills: Ability to effectively explain complex security concepts and risks to both technical teams and non-technical stakeholders, ensuring alignment on security measures. Leadership and mentoring skills: Experience leading security teams or initiatives, mentoring junior engineers, and fostering a culture of security awareness within the organization. Collaboration and cross-functional teamwork: Proven ability to work effectively with development, DevOps, and IT teams to integrate security into all aspects of the business, ensuring security goals align with business objectives. Highly flexible/willing to learn new technologies. Highly organized with excellent analytical, problem solving and decision-making skills.

Additional Qualifications:

Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Cloud Security Professional (CCSP), or GIAC Web Application Penetration Tester (GWAPT) are highly preferred.

Knowledge of compliance standards like NIST, PCI-DSS, and GDPR and how they apply to application security.