Application Security Testing Lead – DAST

Methodius IT Recruitment

Ulster

Hybrid

EUR 95,000 - 135,000

Full time

13 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus
Pension
Medical Insurance
Life Insurance
Employee Assistance
Relocation
Lunch & Learn
On-site parking
Bike-to-work

Job summary

Methodius IT Recruitment is assisting a global financial services client in Ireland to hire an experienced Application Security Lead to drive the rollout of DAST across a large-scale enterprise. The role blends deep security expertise with programme leadership to embed automated testing throughout the SDLC.

You will define scanning standards, evaluate enterprise DAST solutions for web apps and APIs, and integrate with CI/CD.

Qualifications

  • Strong experience in Application Security, Penetration Testing, or AppSec Engineering.
  • Hands-on experience with DAST tools, authenticated scanning, and policy tuning.
  • Deep understanding of web and API security, including OWASP WSTG.
  • Experience integrating security testing into CI/CD and DevSecOps pipelines.
  • Knowledge of Jenkins, GitLab CI, GitHub Actions, Azure DevOps, or similar.
  • Ability to analyse findings, identify true positives, and communicate risk effectively.
  • Strong stakeholder management and programme delivery experience.
  • Experience selecting or implementing enterprise DAST platforms.
  • Python scripting or security automation experience.
  • API security testing (REST, GraphQL, SOAP, OpenAPI).
  • Knowledge of SAST, SCA, ServiceNow, Vault, or CyberArk.
  • Certifications such as OSCP, BSCP, HTB CPTS, or equivalent.
  • Financial services or regulated industry experience.

Responsibilities

  • Act as the technical lead and SME for DAST within the DevSecOps ecosystem.
  • Evaluate, select, and implement enterprise DAST solutions for web applications and APIs.
  • Define scanning standards, methodologies, and CI/CD integration requirements.
  • Support engineering teams with DAST onboarding, configuration, and optimisation.
  • Review and validate findings, prioritising remediation based on risk.
  • Establish programme governance, reporting, metrics, and stakeholder engagement.
  • Partner with development, DevOps, and security teams to drive remediation and adoption.
  • Ensure DAST complements existing penetration testing and application security activities.
  • Provide regular technical and executive-level reporting on programme performance and risk.

Skills

DAST tooling
CI/CD integration
DevSecOps
Jenkins
GitLab CI
GitHub Actions
Azure DevOps
Python scripting
API security
OWASP WSTG
Risk communication

Education

OSCP
BSCP
HTB CPTS

Tools

SAST
SCA
ServiceNow
Vault
CyberArk

Job description

Our client, a global financial services organisation, is seeking an experienced Application Security Lead to drive the rollout of Dynamic Application Security Testing (DAST) across a large-scale enterprise environment.

This is a high-impact role combining deep technical application security expertise with programme leadership. You'll lead the selection, implementation, and adoption of DAST capabilities, helping embed automated security testing across the software development lifecycle.

Key Responsibilities
  • Act as the technical lead and SME for DAST within the DevSecOps ecosystem.
  • Evaluate, select, and implement enterprise DAST solutions for web applications and APIs.
  • Define scanning standards, methodologies, and CI/CD integration requirements.
  • Support engineering teams with DAST onboarding, configuration, and optimisation.
  • Review and validate findings, prioritising remediation based on risk.
  • Establish programme governance, reporting, metrics, and stakeholder engagement.
  • Partner with development, DevOps, and security teams to drive remediation and adoption.
  • Ensure DAST complements existing penetration testing and application security activities.
  • Provide regular technical and executive-level reporting on programme performance and risk.
Requirements
  • Strong experience in Application Security, Penetration Testing, or AppSec Engineering.
  • Hands-on experience with DAST tools, authenticated scanning, and policy tuning.
  • Deep understanding of web and API security, including OWASP WSTG.
  • Experience integrating security testing into CI/CD and DevSecOps pipelines.
  • Knowledge of Jenkins, GitLab CI, GitHub Actions, Azure DevOps, or similar platforms.
  • Ability to analyse findings, identify true positives, and communicate risk effectively.
  • Strong stakeholder management and programme delivery experience.
  • Experience selecting or implementing enterprise DAST platforms.
  • Python scripting or security automation experience.
  • API security testing (REST, GraphQL, SOAP, OpenAPI).
  • Knowledge of SAST, SCA, ServiceNow, Vault, or CyberArk.
  • Certifications such as OSCP, BSCP, HTB CPTS, or equivalent.
  • Financial services or regulated industry experience.
Why Apply?

This is an opportunity to shape and lead a strategic application security programme within a complex global organisation. You'll influence security tooling, standards, and DevSecOps practices while working with senior security and engineering stakeholders across the business.

Salary dependent on candidate experience. Benefits: Annual Bonus Scheme. Contributory Pension. Private Medical Insurance. Life Assurance & Long-Term Disability. Employee Assistance Programme. 22 days annual leave + 10 public holidays. Relocation package. Continuous Learning & Development. Access to extensive training & certification resources. Lunch & Learn sessions. Additional perks including company discounts, on-site parking, and bike-to-work scheme

Based in Letterkenny, Co. Donegal. Hybrid (3 days onsite per week)

Candidates must be eligible to work in Ireland/EU. Permanent role.

For more information, please contact David Coyle at 01 635 1748 or email david@methodius.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Lead – DAST
Application Security Lead – DAST

Methodius Ltd • Roscommon

Hybrid
EUR 90,000 - 120,000
Annual Bonus Scheme
Contributory Pension
Private Medical Insurance
+5
Application Security Lead - DAST & DevSecOps (Hybrid)
Application Security Lead - DAST & DevSecOps (Hybrid)

Methodius Ltd • Roscommon

Hybrid
EUR 90,000 - 120,000
Annual Bonus Scheme
Contributory Pension
Private Medical Insurance
+5
DAST Programme Lead for Enterprise Security (Hybrid)
DAST Programme Lead for Enterprise Security (Hybrid)

Methodius IT Recruitment • Ulster

Hybrid
EUR 95,000 - 135,000
Annual bonus
Pension
Medical Insurance
+6
Senior Application Security Engineer
Senior Application Security Engineer

Uniting Holding • Dublin

Hybrid
EUR 75,000 - 95,000
Competitive remuneration
Company-paid health insurance
Hybrid Working Model
+2
Product Security Architect
Product Security Architect

Alldus International Consulting Ltd • Dublin

On-site
EUR 75,000 - 95,000
Senior Application Security Engineer
Senior Application Security Engineer

SoftCo • Dublin

Hybrid
EUR 120,000 - 180,000
Performance bonus
Health insurance
Pension
+6
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Davy • Ireland

On-site
EUR 85,000 - 120,000
Health and wellness benefits
Flexible working options
Professional development opportunities
Java Architect
Java Architect

Methodius Ltd • Letterkenny

Hybrid
EUR 75,000 - 95,000
Annual Bonus Scheme
Contributory Pension
Private Medical Insurance
+9
IT Security Automation Engineer
IT Security Automation Engineer

Cpl • Dublin

Hybrid
EUR 75,000 - 81,000
Hybrid and flexible working
Discretionary bonus
Private medical cover
+5
Cyber Security Platform Engineer
Cyber Security Platform Engineer

Methodius Ltd • Dublin

Hybrid
EUR 60,000 - 80,000
Annual Bonus Scheme
Contributory Pension
Private Medical Insurance
+6