SAST vs. DAST vs. SCA
Three kinds of automated security scanning that JDs often list as one skill. SAST reads the company's own source code for weaknesses before it runs. DAST attacks the running application from the outside, like a hacker would. SCA checks the open-source libraries the code depends on for known vulnerabilities. Each catches problems the others miss, and each has its own tools.
How to tell them apart on a resume
SAST (code scanning)
SonarQube, Checkmarx, Semgrep, Fortify, Veracode, CodeQL, secure code review — run in the build pipeline.
DAST (running-app testing)
Burp Suite, OWASP ZAP, Acunetix, scanning staging environments, web application security testing — close to penetration testing.
SCA (dependency scanning)
Snyk, Dependabot, Black Duck, Mend, SBOMs, CVE triage, licence compliance — managing third-party and open-source risk.
The question that settles it
“Which kind of scanning did you set up — your own code, the running app, or third-party libraries — and how did you stop developers ignoring the results?”
Read the full definitions
Open the full tool for the other look-alike pairs, role profiles, and the JD decoder.