DAST Program & Technical Lead

Tata Consultancy Services

Letterkenny

Hybrid

EUR 90,000 - 120,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health care
Pension
Discounts within Tata network

Job summary

Tata Consultancy Services in Letterkenny is seeking a DAST Program & Technical Lead to drive automated DAST within the DevSecOps CI/CD pipeline for a major US-based financial services client. You will define tooling, scan design, and governance while coordinating across teams to deliver secure, scalable testing.

You will balance hands-on security work with program leadership, guiding remediation efforts and maintaining alignment with risk priorities.

Qualifications

  • Industry experience in application security or application penetration testing (web & API).
  • Hands-on experience operating DAST scanners including authenticated scans and tuning.
  • Versatile profile as both hands-on security expert and program driver.
  • Experience integrating security tooling into CI/CD/DevSecOps pipelines with credible direction to DevOps.
  • Understanding of web, API vulnerabilities and CVSS risk prioritization.
  • Ability to triage scanner output and communicate remediation across teams.
  • Strong program-management skills with stakeholder reporting and governance.
  • Familiarity with Jira for issue tracking and workflow management.
  • Excellent communication and documentation of policies and reports.

Responsibilities

  • Act as the subject matter expert and technical design authority for automated DAST in the CI/CD pipeline.
  • Lead vendor DAST evaluation, testing, and POC, and drive procurement decisions.
  • Define how DAST integrates into CI/CD pipelines and provide technical direction to DevOps.
  • Author and tune scan policies and authentication configurations for maximum coverage.
  • Validate scanner findings, triage results, and communicate risk to application teams.
  • Define program processes including onboarding criteria, cadence, SLAs, escalation, and reporting.
  • Collaborate with development teams through remediation lifecycle and verify fixes.
  • Ensure DAST complements manual penetration testing for high-risk apps.
  • Produce clear documentation, policies, and governance reporting.
  • Stay current with emerging DAST tools and application security threats.

Skills

Application security
DAST proficiency
CI/CD security tooling
Vulnerability management
Program leadership
Jira
CVSS scoring
Remediation guidance

Tools

Jenkins
GitLab CI
Azure DevOps
GitHub Actions

Job description

Job Type: Permanent
Location: Letterkenny GDC, Co. Donegal (Onsite – Hybrid option after probation)
Join a global tech leader right here in Donegal

With over 850 employees and a state-of-the-art global delivery centre, we’re proud to offer world-class career opportunities without having to leave the Northwest. Recognised as Workplace of the Year by the Letterkenny Chamber, we foster a culture of continuous learning, innovation, and respect. Our people are at the heart of everything we do – collaborating across teams, geographies, and disciplines to drive real change for clients around the world. Be part of something global, grounded in Donegal.

Careers at TCS: It means more

TCS is a purpose-led transformation company, built on belief. We do not just help businesses to transform through technology. We support them in making a meaningful difference to the people and communities they serve - our clients include some of the biggest brands in the UK and worldwide. For you, it means more to make an impact that matters, through challenging projects which demand ambitious innovation and thought leadership.

The Role

Join the customer's Attack Surface Management team as the DAST Program & Technical Lead. Our client, a major U.S.-based financial services group, runs a mature, risk-based, product-focused penetration testing program. The client is now extending coverage across its entire application portfolio by embedding automated Dynamic Application Security Testing (DAST) into its DevSecOps CI/CD pipeline.

This is a deliberately broad, hands-on role for someone comfortable operating across both deep technical ownership and program delivery.

On one side, you act as the technical security authority for DAST responsible for selecting and validating tooling, designing how scanning operates, tuning configurations, and triaging results.

On the other hand, you are the driving force behind the program coordinating across teams, tracking rollout progress, defining processes, and ensuring the initiative continues to move forward effectively.

The DevOps team owns the CI/CD pipelines and will deliver much of the implementation. However, they take their security direction from you. You define the technical design, standards, and requirements, and DevOps build to them.

You are equally comfortable working on scan policies and configurations as you are engaging in stakeholder planning discussions and can move fluidly between the two.

Your responsibilities:
  • Act as the subject matter expert and technical design authority for automated DAST within the DevSecOps CI/CD pipeline, defining and driving security best practices.
  • Lead the evaluation, testing, and proof of concept of vendor DAST solutions, assessing depth of coverage across web applications and APIs and driving the procurement decision.
  • Define how and where DAST scanning integrates into CI/CD pipelines (e.g., build/release gates, scheduled scans, authenticated scanning, environment requirements) and provide clear technical direction to the DevOps team.
  • Author and tune scan policies, profiles, and authentication configurations to maximize true positive coverage while minimizing false positives and pipeline friction.
  • Validate and triage scanner findings, distinguishing real vulnerabilities from noise, and ensuring results are accurate before being shared with application teams.
  • Define operational processes for the program, including application onboarding criteria, scan cadence, SLAs, escalation paths, and reporting that demonstrates portfolio-wide coverage.
  • Define how the program runs: application onboarding criteria, scan cadence, SLAs, escalation paths, metrics, and reporting that demonstrate portfolio-wide coverage.
  • Partner with application development teams throughout the remediation lifecycle explaining findings, advising on fixes, prioritizing based on risk, and verifying remediation.
  • Ensure automated DAST complements (not replace) the existing risk-based penetration testing program, maintaining deep manual testing for high-risk applications.
  • Contribute to security policies, standards, and governance, producing clear documentation and reporting for both technical and leadership audiences.
  • Stay current with emerging DAST tools, techniques, and application security threats to ensure continued effectiveness and coverage.
Your Profile
Essential skills/knowledge/experience:
  • Industry experience in application security or application penetration testing (web & API), with a strong working understanding of the OWASP WSTG.
  • Hands-on experience operating DAST scanners including configuring authenticated scans and tuning scan policies.
  • A versatile profile capable of operating as both a hands-on security expert and a program driver, able to plan, coordinate, and report across multiple teams.
  • Demonstrated understanding of integrating security tooling into CI/CD / DevSecOps pipelines (e.g., Jenkins, GitLab CI, Azure DevOps, GitHub Actions), including build/release gating concepts and API-driven scan orchestration enough to set requirements and direct the DevOps team with credibility.
  • Solid grasp of web, API, and desktop application vulnerability classes and how they manifest in automated vs. manual testing.
  • Proficient in using the CVSS calculator to assess and prioritize risk by severity and impact.
  • Ability to triage scanner output at scale, separating true positives from false positives and articulating real-world risk.
  • Demonstrated expertise in communicating clear, actionable remediation advice and partnering with development teams throughout the remediation lifecycle.
  • Experience coordinating and driving workstreams to completion, comfortable with the program-management side (planning, tracking, stakeholder updates)
  • Familiarity with issue-tracking and workflow tooling such as Jira.
  • Excellent communication and interpersonal skills, with the ability to provide technical direction to engineering teams and explain risk to both technical and non-technical stakeholders.
  • Proven ability to write clear, structured, evidence-based documentation, policies, and reports.
Desirable skills/knowledge/experience:
  • Experience selecting, piloting, or procuring a commercial DAST solution, including vendor evaluation and proof-of-concept testing.
  • Scripting / development experience (e.g., Python, scripting against scanner APIs) to support automation and pipeline integration.
  • Experience with API security testing specifically (REST, GraphQL, SOAP), including OpenAPI/Swagger-driven scanning.
  • Familiarity with complementary AppSec tooling (SAST, SCA/software composition analysis) and how it fits a broader DevSecOps program.
  • Familiarity with ServiceNow, including using it for vulnerability/workflow management and remediation tracking.
  • Familiarity with secrets management / vault tooling (e.g., HashiCorp Vault, CyberArk, or similar) for handling scan credentials and authenticated scanning secrets securely.
  • Industry certifications such as Burp Suite Certified Practitioner (BSCP), HTB Certified Penetration Testing Specialist (HTB CPTS), or Offensive Security Certified Professional (OSCP).
  • Experience defining or operating an application security program at portfolio scale (onboarding, SLAs, metrics, governance).
  • Experience working within the financial services industry or another highly regulated environment.
  • Japanese, Spanish, or Portuguese language skills an advantage
Rewards & Benefits

TCS is consistently voted a Top Employer in the UK and globally. Our competitive salary packages feature pension, health care, life assurance, laptop and access to extensive training resources and discounts within the larger Tata network.

We offer health & wellness initiatives and sports events; we are the proud sponsor of the London Marathon and partner with our local communities in Ireland.

Diversity, Inclusion and Wellbeing

Tata Consultancy Services UK&I is committed to meeting the accessibility needs of all individuals in accordance with the Ireland Employment Equality Acts 1998-2011 (as amended) and the Equal Status Acts 2000-2012 (as amended).

We welcome and embrace diversity in race, nationality, ethnicity, disability, neurodiversity, gender identity, age, physical ability, gender reassignment, sexual orientation. We are a disability inclusive employer and encourage disabled people to apply for this role.

As a Disability Confident Employer, we offer an interview to applicants with disabilities or long-term conditions who meet the minimum criteria for the role. Please email us at UKI.recruitment@tcs.com if you would like to opt in.

Due to the high volume of applications, we will be unable to contact each applicant individually on the status of their application. If you have not received a direct response within 30 days, then it should be deemed unsuccessful on this occasion.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Penetration Tester
Application Penetration Tester

Tata Consultancy Services • Letterkenny

Hybrid
EUR 55,000 - 85,000
Pension
Health care
Life assurance
+4
Application Penetration Tester
Application Penetration Tester

Tata Consultancy Services • Ireland

On-site
EUR 70,000 - 90,000
Pension
Health care
Life assurance
+2
Software Development Engineer (Mid to Senior Level)
Software Development Engineer (Mid to Senior Level)

Tata Consultancy Services • Dublin

Hybrid
EUR 70,000 - 110,000
IT Delivery Manager
IT Delivery Manager

Tata Consultancy Services • Leinster

On-site
EUR 90,000 - 130,000
Pension
Health care
Life assurance
+7
Software Engineer
Software Engineer

Tata Consultancy Services • Dublin

Hybrid
EUR 90,000 - 120,000
Pension
Health care
Life assurance
+2
Software Development Engineer (Mid to Senior Level) at Tata Consultancy Services (TCS)
Software Development Engineer (Mid to Senior Level) at Tata Consultancy Services (TCS)

Tata Consultancy Services (TCS) • Dublin

Hybrid
EUR 90,000 - 120,000
ETL/Data Test Engineer
ETL/Data Test Engineer

Tata Consultancy Services • Letterkenny

Hybrid
EUR 55,000 - 75,000
Customer Service Representative
Customer Service Representative

Tata Consultancy Services • Letterkenny

On-site
EUR 27,000 - 36,000
Health care
Pension
Laptop
+1
Senior Engagement Manager (ServiceNow)
Senior Engagement Manager (ServiceNow)

Candidate Manager LTD • Letterkenny

On-site
EUR 100,000 - 130,000
Pension
Health care
Life Assurance
+2
.Net Full Stack Developer
.Net Full Stack Developer

Tata Consultancy Services • Letterkenny

Hybrid
EUR 60,000 - 80,000
Pension
Health care
Life assurance
+2