> Markdown version of [/jobs/ext/2249932-test-engineer-dast-iast-application-security](https://www.wearedevelopers.com/jobs/ext/2249932-test-engineer-dast-iast-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Test Engineer DAST IAST Application Security - **Company:** Client Server - **Location:** Cambridge, UK (Remote available) - **Salary:** £70,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Software System Penetration Testing, Burp Suite, C++ (Programming Language), Client Server Models, Python (Programming Language), Open Web Application Security, Remote Access Technology, Secure Coding, Software Engineering, SQL Injection, Software Security, Cross-Site Scripting (XSS), Synopsys Black Duck, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815185032-test-engineer-dast-iast-application-security ## About the Role * You have a strong understanding of the secure software development lifecycle and DevSecOps principles * You have a good knowledge of Application Security principles and common vulnerabilities (e.g., XSS, SQL Injection, Broken Access Control) * You have hands-on experience with DAST, IAST and Penetration Testing tools (e.g., Burp Suite, OWASP ZAP, Frida) and Static Application Security Testing (SAST) * You can read and understand code (e.g. Java, Python, C++ or similar) * You're familiar with using software composition analysis (SCA) tools such as Blackduck, Mend / Whitesource, Snyk or similar * You're collaborative and pragmatic with great communications skills ## Description Test Engineer (DAST IAST Application Security) Cambridge / WFH to £70k Are you a security focussed Test Engineer? You could be joining a market leading software house that's remote access product is used by hundreds of millions of users worldwide. What's in it for you: * Salary to £70k * Bonus * Pension, Private Medical Care, Life Assurance, Travel Insurance * Subsidised gym membership and a range of other perks Your role: As a Test Engineer you'll play a key role in building security into applications, carrying out threat modelling and risk assessments during the design phase to ensure solutions are secure by default. You'll help define security requirements for new features and take part in architecture reviews to spot and address potential risks early. Working closely with development teams, you'll carry out secure code reviews and provide guidance on best practices, including alignment with CIS Critical Security Controls and the OWASP Top 10, collaborating with engineers to embed security into development workflows rather than treating it as an afterthought. You'll be hands-on with security testing across a range of environments, running Dynamic Application Security Testing (DAST) against live applications, focusing on issues such as cross-site scripting, SQL injection and broken access control. You'll also use Interactive Application Security Testing (IAST) tools for runtime analysis, including tools such as Burp Suite, OWASP ZAP and Frida, alongside Static Application Security Testing (SAST) and software composition analysis to assess source code, binaries, and third-party dependencies. Location / WFH: You can work from home most of the time, meeting up with colleagues in the Cambridge office on a weekly / monthly basis. About you: * You have a strong understanding of the secure software development lifecycle and DevSecOps principles * You have a good knowledge of Application Security principles and common vulnerabilities (e.g., XSS, SQL Injection, Broken Access Control) * You have hands-on experience with DAST, IAST and Penetration Testing tools (e.g., Burp Suite, OWASP ZAP, Frida) and Static Application Security Testing (SAST) * You can read and understand code (e.g. Java, Python, C++ or similar) * You're familiar with using software composition analysis (SCA) tools such as Blackduck, Mend / Whitesource, Snyk or similar * You're collaborative and pragmatic with great communications skills Apply now to find out more about this Test Engineer (DAST IAST Application Security) opportunity. At Client Server we believe in a diverse workplace that allows people to play to their strengths and continually learn. We're an equal opportunities employer whose people come from all walks of life and will never discriminate based on race, colour, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. The clients we work with share our values. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)