





Early-mid metro AppSec role: common experience band increases applicants, but niche SAST/DAST skills moderate competition.
Specialized application security tooling and vulnerability remediation raise domain sensitivity but skills remain partly transferable across industries.
Mandatory SAST/DAST tooling experience and ~2 years requirement create moderately strict technical filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify security vulnerabilities in web applications, APIs, and software.
Analyze scan results, validate findings, prioritize by severity and business impact, and coordinate remediation with development teams.
Integrate security testing into CI/CD pipelines and prepare vulnerability assessment reports for tracking remediation progress.
Around 2 years of experience in Application Security focusing on SAST and DAST tools.
Hands-on experience with SAST tools like Checkmarx, Veracode, Fortify, SonarQube, or similar, and DAST tools such as Burp Suite, OWASP ZAP, Acunetix, Netsparker, or similar.
Good understanding of OWASP Top 10 vulnerabilities and basic knowledge of web technologies (HTTP, HTTPS, REST APIs, JavaScript, HTML).
Work Experience Required: Around 2 years in Application Security. Notice period: Not explicitly mentioned in the JD.
Experienced with security tools and adept at distinguishing true positive vulnerabilities from false positives in complex applications.
Capable of collaborating effectively with development teams to implement secure coding and remediation best practices.
Familiarity with secure SDLC integration (CI/CD pipelines) and some scripting or cloud security knowledge is a plus but not mandatory.