R

SAST and DAST

Randstad · Bengaluru, Karnataka, India - Chennai, Tamil Nadu, India - Hyderabad, Telangana, India

3–10 yrs experiencefull_timePosted 1w ago

Job description

**Role & responsibilities** Required Skills SAST & Static Code Analysis - Static Application Security Testing (SAST) Mastery: Proven experience configuring and running static code analysis tools (Checkmarx, Fortify, SonarQube, or equivalent) across multiple languages and frameworks. - Strong understanding of secure coding principles, common code-level vulnerability patterns, and remediation techniques. - Ability to tune SAST rulesets and scan policies to reduce noise while maintaining detection coverage. - Experience integrating SAST scans into build pipelines and interpreting scan results at scale. DAST & Dynamic Testing - Dynamic Application Security Testing (DAST) — Mastery: Hands-on expertise running dynamic scans against web applications and APIs using tools such as HCL AppScan, Burp Suite, or OWASP ZAP. - Working knowledge of authenticated scanning, session handling, and crawling configuration for complex applications. - Familiarity with API security testing, including REST and SOAP endpoints, and common API- specific vulnerability classes. - Experience validating dynamic findings against application behavior to confirm exploitability. Vulnerability Management & Triage - Strong grounding in the OWASP Top 10 and related vulnerability taxonomies (Broken Access Control, Injection, Security Misconfiguration, Sensitive Data Exposure, and others). - Experience with false-positive analysis and root-cause triage across SAST, DAST, and software composition analysis (SCA) findings. - Familiarity with Vulnerability Information Tracker (VIT) workflows: creation, validation, and closure of defects. - Understanding of risk-rating methodologies (CVSS or equivalent) to prioritize remediation effort. Tooling & Integration - Experience with software composition analysis (SCA) and secret-scanning tools (e.g., Checkmarx SCA, Cycode, or equivalent). - Familiarity with CI/CD platforms (Azure DevOps, GitHub Actions, GitLab CI/CD) and embedding security scans within pipelines. - Exposure to cloud security posture and configuration scanning tools (e.g., Prisma Cloud) is a plus. - Basic scripting ability (PowerShell, Python, or Bash) to support scan automation and reporting. Collaboration & Communication - Ability to work effectively with cross-functional teams including developers, architects, DevOps, and platform engineering. - Strong problem-solving, analytical, and written/verbal communication skills. - Ability to document scan findings, remediation guidance, and risk decisions clearly and concisely. - Experience in client-facing roles with demonstrated ability to present security findings to non- technical stakeholders. **Preferred candidate profile**