BurpSuite (DAST) for web app pentesting/proxy/scanning;
SAST (Semgrep, Fortify) for static code analysis;
DAST (OWASPZAP, WebInspect, Nuclei) for runtime vuln detection.
Conduct SAST/DAST assessments using Burp Suite/Semgrep/OWASP ZAP, integrate into CI/CD, analyze code/runtime, document/remediate vulnerabilities, and stay updated on threats.
Language skills: Arabic, English