Skill · 02
← All skills
Security

SAST

Static analysis that finds flaws in source before it ships.

At a glance
30–40%
Production defects reduced
Pre-merge
Findings caught in CI
Capabilities
5
Tools & platforms
5
Discipline
Security
Overview

Embed static application security testing across the SDLC — scanning source and dependencies for vulnerabilities early, with automated gates that catch issues before code reaches production.

Capabilities
5 areas
  • Static code analysis across .NET, Java and Node.js
  • CI/CD-integrated SAST gating and policy enforcement
  • Triage, false-positive tuning and finding prioritization
  • Secure code review of authentication and input handling
  • Software composition analysis (SCA) for dependencies
Software & Tools

The stack behind the work.

The tools I reach for day to day — with a rough sense of where my depth sits.

Expert
Advanced
Proficient

Checkmarx

Advanced

Enterprise static analysis (SAST)

SonarQube

Advanced

Code quality & security gating

Snyk Code

Advanced

Developer-first SAST & SCA

Semgrep

Proficient

Custom rule-based static scanning

CodeQL

Proficient

Query-based code scanning in CI

Let's work together

Have a project that needs SAST?