Haystack
← Back to Jobs
Technology

SAST/DAST Security Engineer

Exl Neo TechnologiesTX🇺🇸United StatesPosted 3 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Title: SAST/DAST Security Engineer (Application Security)

Job Type: Contract / Full-Time (FTE)

Location: Dallas, TX | Cincinnati, OH | Minneapolis, MN | Portland, OR

Experience: 5-8 Years

Job Summary

We are seeking an experienced SAST/DAST Security Engineer with strong expertise in Application Security (AppSec), Penetration Testing, and DevSecOps. The ideal candidate will have hands-on experience with SAST, DAST, SCA, CI/CD security integration, AI/LLM security, container security, and security automation. This role involves securing enterprise applications, improving threat detection, supporting incident response, and ensuring compliance with security standards.

Required Skills

  • 5-8 years of experience in Application Security or Cybersecurity.
  • Hands-on experience with SAST, DAST, and SCA security tools.
  • Strong experience in Penetration Testing (Mandatory).
  • Experience integrating security tools with GitLab and Jenkins CI/CD pipelines.
  • Knowledge of AI/LLM Security, AI vulnerability scanning, and Agent Security.
  • Experience with Docker, Helm Charts, and cloud platforms.
  • Automation and scripting experience using Java, Python, or Groovy.
  • Strong understanding of secure SDLC, OWASP Top 10, and application security best practices.
  • Excellent analytical, troubleshooting, and communication skills.

Preferred Skills

  • Experience with DevSecOps practices and CI/CD security automation.
  • Knowledge of container and Kubernetes security.
  • Experience with cloud security (AWS, Azure, or Google Cloud Platform).
  • Familiarity with incident response, digital forensics, and threat hunting.
  • Experience supporting compliance frameworks and security audits.

Key Responsibilities

  • Perform application security assessments using SAST, DAST, and SCA tools.
  • Conduct penetration testing and identify application vulnerabilities.
  • Integrate security scanning into GitLab and Jenkins CI/CD pipelines.
  • Implement AI/LLM and Agent Security best practices.
  • Monitor security events, analyze attack patterns, and investigate security incidents.
  • Perform root cause analysis (RCA) and support incident response and disaster recovery.
  • Conduct threat analysis, forensic investigations, and implement remediation plans.
  • Collaborate with Development, DevOps, Infrastructure, Security, and Compliance teams.
  • Maintain audit documentation and support regulatory compliance initiatives.
  • Develop security automation using Java, Python, or Groovy.
  • Deliver cybersecurity awareness sessions, including phishing and secure coding best practices.
  • Continuously improve application security processes and detection capabilities.

Skills

Docker
AWS
OWASP
Azure
Google Cloud
Groovy
Helm
Java
Jenkins
Kubernetes
LLM
Penetration Testing
Python

Similar jobs