技能档案

SAST/DAST

SonarQube, Semgrep, Snyk, OWASP ZAP: static and dynamic analysis

Security Application Security

角色数

5

包含此技能的角色

级别数

5

结构化成长路径

必要要求

23

其余 2 个可选

领域

Security

skills.group

Application Security

最后更新

2026/3/17

如何使用

选择当前级别并对比期望。下方卡片显示晋升所需掌握的内容。

各级别期望

表格展示从初级到首席的技能深度变化。点击行查看详情。

角色 必要性 描述
Application Security Engineer 必要 Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes typical code vulnerabilities.
DevSecOps Engineer 必要 Runs SonarQube and Semgrep locally for static code analysis. Studies SAST reports, classifies vulnerabilities by severity. Configures basic DAST scan with OWASP ZAP against test application. Understands difference between SAST, DAST and IAST approaches to security testing.
Penetration Testing Engineer 必要 Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes common vulnerabilities in code.
QA Security Engineer Runs SAST/DAST tools: SonarQube for static analysis, ZAP for dynamic analysis. Reads reports, classifies findings. Distinguishes true positives from false positives.
Security Analyst 必要 Understands basic SAST/DAST concepts. Follows security guidelines. Recognizes common code vulnerabilities.
角色 必要性 描述
Application Security Engineer 必要 Configures and runs SAST/DAST tools to identify vulnerabilities in application code and running services. Conducts security code reviews using static analysis findings as input. Triages scanner results, eliminates false positives, and tracks confirmed issues to resolution.
DevSecOps Engineer 必要 Integrates SonarQube and Semgrep into CI/CD pipelines with quality gates blocking merge on critical vulnerabilities. Configures OWASP ZAP in API scanning mode with OpenAPI specification. Writes custom Semgrep rules for project-specific vulnerability patterns.
Penetration Testing Engineer 必要 Uses DAST tools alongside manual penetration testing to discover runtime vulnerabilities. Validates SAST findings through exploitation to confirm real attack vectors. Integrates dynamic scanning into penetration testing workflows to maximize coverage of web application attack surfaces.
QA Security Engineer Configures SAST/DAST pipeline: Semgrep/SonarQube rules customization, ZAP automated scan profiles, IAST integration. Tunes rules to reduce false positives. Prioritizes findings.
Security Analyst 必要 Analyzes SAST/DAST scan results to assess risk levels and prioritize remediation efforts. Correlates scanner findings with threat intelligence and known vulnerability databases. Generates actionable security reports from scanning data for development and management teams.
角色 必要性 描述
Application Security Engineer 必要 Designs security solutions with SAST/DAST. Conducts threat modeling. Implements security practices in SDLC. Mentors the team.
DevSecOps Engineer 必要 Develops centralized SAST/DAST platform for all teams. Tunes SonarQube quality profiles, minimizing false positives to less than 10%. Introduces IAST (Contrast Security) for runtime analysis. Configures SAST and DAST result correlation for vulnerability prioritization.
Penetration Testing Engineer 必要 Designs advanced SAST/DAST testing strategies combining automated scanning with manual exploitation techniques. Conducts threat modeling to identify gaps in scanner coverage. Integrates SAST/DAST into CI/CD security gates with custom rule sets. Mentors team on interpreting and validating scanner results.
QA Security Engineer 必要 Designs SAST/DAST strategy: tool selection by technology stack, custom rules for business logic, finding correlation between SAST and DAST. Creates custom Semgrep/CodeQL rules.
Security Analyst 必要 Designs comprehensive SAST/DAST analytics frameworks for vulnerability trend analysis. Conducts threat modeling to map scanner coverage against real attack scenarios. Integrates scanning results into SIEM for continuous security monitoring. Mentors analysts on vulnerability classification and risk scoring.
角色 必要性 描述
Application Security Engineer 必要 Defines organization-wide SAST/DAST strategy and tool selection standards. Establishes security scanning policies, quality gates, and remediation SLAs for development teams. Coordinates vulnerability response across products when critical scanner findings arise. Trains engineers on effective SAST/DAST adoption.
DevSecOps Engineer 必要 Defines AST (Application Security Testing) strategy with SonarQube Enterprise, Semgrep Pro, OWASP ZAP and Burp Suite. Manages AppSec engineering team. Builds SAST/DAST effectiveness metrics: detection time, false positive rate, coverage. Integrates results into Defect Dojo.
Penetration Testing Engineer 必要 Defines SAST/DAST integration strategy for penetration testing across all products. Establishes scanner validation policies and custom rule development standards. Coordinates offensive security efforts combining automated scanning with manual testing. Trains pentest engineers on advanced SAST/DAST usage.
QA Security Engineer 必要 Defines SAST/DAST standards: mandatory scanning gates, triage process, remediation SLA. Coordinates tooling between security and development. Evaluates tool effectiveness.
Security Analyst 必要 Defines SAST/DAST monitoring and reporting strategy across the organization. Establishes vulnerability management policies based on scanner data and risk classification. Coordinates cross-team remediation tracking for critical scanner findings. Trains security analysts on scan result analysis and prioritization.
角色 必要性 描述
Application Security Engineer 必要 Defines enterprise SAST/DAST security testing architecture spanning all development platforms. Shapes scanning strategy for multi-cloud and microservice environments at scale. Coordinates with vendors on tool capabilities and compliance requirements. Drives SAST/DAST best practices adoption across the industry.
DevSecOps Engineer 必要 Designs corporate security testing architecture unifying SAST, DAST, IAST, SCA and fuzzing into a single pipeline. Defines standards for dozens of teams. Evaluates and introduces innovative approaches: AI-driven SAST, semantic code analysis, runtime protection.
Penetration Testing Engineer 必要 Defines enterprise offensive security strategy integrating SAST/DAST with manual penetration testing at scale. Shapes security testing architecture for complex distributed systems. Coordinates with tool vendors and regulatory bodies on scanning standards. Represents the organization in offensive security community.
QA Security Engineer 必要 Designs application security testing platform: integrated SAST/DAST/IAST/SCA, automated triage, vulnerability correlation. Defines organizational AppSec testing strategy.
Security Analyst 必要 Defines enterprise vulnerability intelligence strategy powered by SAST/DAST data across all business units. Shapes security analytics architecture integrating scanner output with threat intelligence platforms. Coordinates compliance reporting with regulatory bodies. Drives vulnerability management standards in the industry.

社区

👁 关注 ✏️ 建议修改 登录以建议修改
📋 提案
暂无提案 SAST/DAST
正在加载评论...