SAST and DAST (Hyderabad)

SAST and DAST (Hyderabad)

21 Aug
|
Randstad
|
Hyderabad

21 Aug

Randstad

Hyderabad

Role & responsibilities

Required Skills

SAST & Static Code Analysis

- Static Application Security Testing (SAST) Mastery: Proven experience configuring and

running static code analysis tools (Checkmarx, Fortify, SonarQube, or equivalent) across

multiple languages and frameworks.

- Strong understanding of secure coding principles, common code-level vulnerability patterns,

and remediation techniques.

- Ability to tune SAST rulesets and scan policies to reduce noise while maintaining detection

coverage.

- Experience integrating SAST scans into build pipelines and interpreting scan results at scale.

DAST & Energetic Testing

- Dynamic Application Security Testing (DAST) — Mastery: Hands-on expertise running dynamic

scans against web applications and APIs using tools such as HCL AppScan, Burp Suite, or

OWASP ZAP.

- Working knowledge of authenticated scanning, session handling, and crawling configuration for

complex applications.

- Familiarity with API security testing, including REST and SOAP endpoints, and common API-

specific vulnerability classes.

- Experience validating dynamic findings against application behavior to confirm exploitability.

Vulnerability Management & Triage

- Strong grounding in the OWASP Top 10 and related vulnerability taxonomies (Broken Access

Control, Injection, Security Misconfiguration, Sensitive Data Exposure, and others).





- Experience with false-positive analysis and root-cause triage across SAST, DAST, and software

composition analysis (SCA) findings.

- Familiarity with Vulnerability Information Tracker (VIT) workflows: creation, validation, and

closure of defects.

- Understanding of risk-rating methodologies (CVSS or equivalent) to prioritize remediation effort.

Tooling & Integration

- Experience with software composition analysis (SCA) and secret-scanning tools (e.g.,

Checkmarx SCA, Cycode, or equivalent).

- Familiarity with CI/CD platforms (Azure DevOps, GitHub Actions, GitLab CI/CD) and embedding

security scans within pipelines.

- Exposure to cloud security posture and configuration scanning tools (e.g., Prisma Cloud) is a

plus.

- Basic scripting ability (PowerShell, Python, or Bash) to support scan automation and reporting.

Collaboration & Communication

- Ability to work effectively with cross-functional teams including developers, architects, DevOps,

and platform engineering.

- Strong problem-solving, analytical, and written/verbal communication skills.
- Ability to document scan findings, remediation guidance, and risk decisions clearly and

concisely.

- Experience in client-facing roles with demonstrated ability to present security findings to non-

technical stakeholders.

Preferred candidate profile

📌 SAST and DAST (Hyderabad)
🏢 Randstad
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sast and dast (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: sast and dast (hyderabad) / hyderabad