1

Security Testing Web Application Sast Jobs (NOW HIRING)

Application Security Engineer

Coral Gables, FL

$55.75 - $74.50/hr

... and web technologies. A Bachelor's degree in Computer Science and certifications such as CISSP ... Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies.

Sr Application Security Engineer-Remote

Providence, RI · On-site +1

$59.25 - $79.25/hr

... web, mobile and API environments. The role is expected to independently lead engagements from ... Conduct security-focused code reviews, static application security testing (SAST), dynamic ...

Responsibilities • Conduct research and development for automating web application attacks. • ... with automated application security testing products (SAST, DAST, etc.) a plus. • Genuine ...

Candidate would perform Network/Application and Web Application penetration testing. Also create custom scripts and perform automation while also perform security assessments on both legacy on prem ...

Technical • Oversee application security testing programs including SAST, DAST, SCA, and manual code review. • Promote secure design practices through threat modeling and architecture reviews ...

Product Security

Bellevue, WA · On-site

$66 - $88/hr

... Web Application Security Project) and SANS Top 25 (SysAdmin, Audit, Network, and Security). • ... Static Application Security Testing (SAST). • Strong communication skills with the ability to ...

Product Security

San Francisco, CA · On-site

$69.25 - $92.50/hr

... Web Application Security Project) and SANS Top 25 (SysAdmin, Audit, Network, and Security). • ... Static Application Security Testing (SAST). • Strong communication skills with the ability to ...

Leverage enterprise tooling (e.g., SAST/SCA platforms, Azure DevOps, GitHub) to support secure development workflows. Monitor emerging application security threats and adjust controls accordingly.

Preferred At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis) Hands on security tester with proficiency in tools like HP Fortify, Web Inspect ...

Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST ... API & Web Application Security * Perform regular API security assessments and integrate monitoring ...

Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST ... API & Web Application Security * Perform regular API security assessments and integrate monitoring ...

next page

Showing results 1-20

Security Testing Web Application Sast information

See salary details

$29

$66

$96

How much do security testing web application sast jobs pay per hour?

As of Jun 6, 2026, the average hourly pay for security testing web application sast in the United States is $66.40, according to ZipRecruiter salary data. Most workers in this role earn between $56.49 and $75.48 per hour, depending on experience, location, and employer.

What is Security Testing Web Application SAST?

Security Testing Web Application SAST (Static Application Security Testing) is a process used to identify vulnerabilities in the source code, bytecode, or binary code of web applications without executing the program. SAST helps developers find security flaws early in the software development lifecycle by scanning the application's codebase for common vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure data handling. This proactive approach enables organizations to fix security issues before deployment, reducing the risk of cyberattacks and data breaches. SAST tools integrate with development environments to provide real-time feedback and facilitate secure coding practices.

What are the key skills and qualifications needed to thrive as a Security Testing Web Application SAST specialist, and why are they important?

To thrive as a Security Testing Web Application SAST specialist, you need expertise in application security, software development principles, and vulnerability assessment, often supported by a degree in computer science or cybersecurity. Familiarity with static application security testing (SAST) tools like SonarQube, Checkmarx, or Veracode and relevant certifications such as CISSP or CEH is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify vulnerabilities and relay findings to development teams. These skills are crucial for proactively securing applications, meeting compliance standards, and reducing organizational risk from software vulnerabilities.

What is the difference between Security Testing Web Application Sast vs Penetration Tester?

AspectSecurity Testing Web Application SastPenetration Tester
CertificationsOWASP, CEH, CISSPOSCP, CEH, GPEN
Work EnvironmentAutomated testing, code analysis, CI/CD pipelinesManual testing, live environment assessments
Industry UsageSoftware development, DevSecOpsSecurity consulting, offensive security

Security Testing Web Application Sast focuses on automated static analysis of source code to identify vulnerabilities early in the development process. Penetration Testers perform manual and automated testing to exploit vulnerabilities in live systems. While SAST is integrated into development workflows, penetration testing is often conducted post-deployment to assess real-world security. Both roles require security certifications and are vital in securing web applications, but they differ in approach and timing.

What are some common challenges faced by professionals performing SAST (Static Application Security Testing) on web applications?

One common challenge in SAST for web applications is accurately identifying and prioritizing true security vulnerabilities while minimizing false positives, which can be time-consuming. Additionally, integrating SAST tools seamlessly into the development pipeline and ensuring timely feedback to developers can require collaboration across teams. Security testers also need to stay updated on evolving threats and new coding practices, as web application frameworks and technologies frequently change. Effective communication with developers is essential to help them understand and remediate vulnerabilities efficiently.
Application Security Engineer

Application Security Engineer

Ryder

Coral Gables, FL

$55.75 - $74.50/hr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 29 days ago


Ryder rating

7.1

Company rating: 7.1 out of 10

Based on 491 frontline employees who took The Breakroom Quiz

184th of 337 rated logistics


Job description

Job Seekers can review the Job Applicant Privacy Policy by clickinghere.

Job Description:

SUMMARY

We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates must possess a solid understanding of the security and privacy of our company's applications and data.

The Application Security Engineer must understand development, coding, security engineering, and secure systems configurations. This position ensures that every step of the software development lifecycle (SDLC) follows security best practices. This involves conducting security assessments with SAST and DAST tools, reading source code, threat modeling, and designing and implementing secure software development practices. They will determine where security vulnerabilities exist and implement fixes. They must understand how an application may be misused and exploited. The Application Security Engineer will collaborate with software development teams and provide guidance on best practices for secure coding. They will also stay up to date on the latest security trends and technologies and integrate them into the organization's security strategy. The ideal candidate will have strong analytical and problem-solving skills, as well as experience in application security and knowledge of programming languages and web technologies. A Bachelor's degree in Computer Science and certifications such as CISSP, OSCP, or CASE are preferred.


ESSENTIAL FUNCTIONS

  • Conduct security assessments that require expertise of our organization's applications using both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies.

  • Collaborate with software development teams to integrate security into the development life cycle.

  • Conduct security assessments of web, mobile, and other applications. Analyze security assessment results to identify security vulnerabilities and provide guidance on remediation.

  • Design and implement secure software development practices, including threat modeling, secure coding standards, and code review.

  • Stay current with security threats, trends, and technologies, and recommend new security controls as needed.

  • Conduct application security investigations and provide recommendations to mitigate risk.

  • Maintain security documentation, provide subject matter expertise, and collaborate on security policies, procedures, and standards.


ADDITIONAL RESPONSIBILITIES

  • Performs other duties as assigned.


EDUCATION

  • Bachelor's degree in computer science, information security, or a related field

EXPERIENCE

  • Five (5) years or more experience with OWASP, SAST, DAST, SCA, RASP and common security tools, required.

  • Seven (7) years or more application security, security engineering, software development, or a related field, required.

  • Five (5) years or more strong understanding of web application security and common attack vectors. (e.g. SQL injection, XSS, CSRF), required.

  • Five (5) years or more experience with secure coding practices, threat modeling, and secure software development life cycle (SDLC) methodologies. required

  • Five (5) years or more proven experience in diagnosing, isolating, resolving complex issues and recommending/implementing strategies to resolve problems, required.

  • Five (5) years or more demonstrated experience with systems integration processes, methodology and tools, required.

  • Seven (7) years or more development and scripting experience, required.

  • Five (5) years or more professional application security role, required.

  • Five (5) years or more experience with API and Web Security, required.

  • Three (3) years or more experience with WAF, or similar application security infrastructure a plus, preferred.

  • Seven (7) years or more experience in integrating security in CI/CD, DevOps, required.

  • Six (6) years or more experience process or operation management

  • Six (6) years or more experience Value Stream Mapping, Continuous Flow, Pull Replenishment and other process improvement experience.


SKILLS

  • Excellent communication skills, both verbal and written, and the ability to work effectively with cross-functional teams.

  • Ability to create and maintain professional relationships within all levels of the organization (peers, work groups, customers, supervisors).

  • Ability to work independently and as a member of a team.

  • Flexibility to operate and self-driven to excel in a fast-paced environment.

  • Capable of multi-tasking, highly organized, with excellent time management skills

  • Proficiency in at least one programming language (e.g. Python, .NET, Javascript) with .NET preferred., advanced, required.

  • Proficiency in at least one common scripting language (e.g. PowerShell, bash, etc.), advanced, required.

  • Familiarity of NIST framework, PCI, ISO 27001, SOC, SOX, CCPA, GDPR and global regulations, expert, required.

  • CI/CD experience with Azure Devops, Terraform or other automation and integration technologies, expert, required.

  • Risk management findings, vulnerability prioritization, threat modeling, and mitigation strategy, advanced, required.

LICENSES

  • CISSP, OSCP, CASE, or other industry-leading certifications, preferred.

TRAVEL

1-10%

Job Category

Information Security

Compensation Information:

Thecompensationofferedtoa candidate may be influenced by a variety of factors, including the candidate's relevant experience; education, including relevant degrees or certifications; work location; market data/ranges; internal equity; internal salary ranges; etc.The position may also be eligible to receive an annual bonus, commission, and/or long-term incentive plan based on the level and/ortype.Compensationranges for the position are below:

Pay Type:

Salaried

Minimum Pay Range:

$110,000.00

Maximum Pay Range:

$130,000.00

Benefits Information:

For all Full-time positions only: Ryder offers comprehensive health and welfare benefits, to include medical, prescription, dental, vision, life insurance and disability insurance options, as well as paid time off for vacation, illness, bereavement, family and parental leave, and a tax-advantaged 401(k) retirement savings plan.

Ryder is proud to be an Equal Opportunity Employer and Drug Free workplace.

All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, among other things, or status as a qualified individual with disability.

Important Note:

Some positions require additional screening that may include employment and education verification; motor vehicle records check and a road test; and/or badging or background requirements of the customer to which you are assigned.

Security Notice for Applicants:

Ryder will only communicate with an applicant directly from a [@ryder.com] email address and will never conduct an interview online through a chat type forum, messaging app (such as WhatsApp or Telegram), or via an online questionnaire. During an interview, Ryder will never ask for any form of payment or banking details and will never solicit personal information outside of the formal submitted application throughwww.ryder.com/careers.

Should you have any questions regarding the application process or to verify the legitimacy of an interview or Ryder representative, please contact Ryder atcareers@ryder.comor800-793-3754.

Current Employees:

If you are a current employee at Ryder, please click here to log in to Workday to apply using the internal application process.

Job Seekers can review the Job Applicant Privacy Policy by clickinghere.


What Ryder employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom