---
title: "OWASP ZAP Specialists | Dedicated Security Team | Azendo"
description: "OWASP ZAP for automated web security scans in CI: baseline and active scans, and the dedicated Azendo specialists who work with it. Fully managed."
url: "https://azendo.co/skills/owasp-zap/"
---

1. [Home](https://azendo.co/)
2. [Skills](https://azendo.co/skills/)
3. OWASP ZAP

# OWASP ZAP specialists for your dedicated team.

ZAP, long known as OWASP ZAP and now maintained as ZAP by Checkmarx, is an open-source web application security scanner. It works as an intercepting proxy for manual testing and runs passive and active scans, and its packaged Docker scans make it a common choice for automated security checks in a CI pipeline.

## Where OWASP ZAP fits in a long-term product team.

ZAP is free and open source, so it can run on every branch with no licences to count, and the baseline scan is the easiest place to start. It spiders the application, watches the responses passively and reports issues such as missing security headers and insecure cookies, without sending attacks, so it is safe to run against a shared environment on every build. The full scan adds active attacks and belongs on an environment set up for it, with test data that can be damaged. Both run from the images on Docker Hub or through the official GitHub Actions, and the Automation Framework describes a whole scan plan in one YAML file kept in the repository.

Noise is the problem to manage. A first scan of an existing application produces a long list, much of it low risk, and a pipeline that fails on all of it gets switched off. A rules file that marks each alert as fail, warn or ignore, reviewed and kept in the repository, turns the scan into a gate the team trusts. Authenticated scanning needs the same care: without a working login context, ZAP tests little beyond the sign-in page.

## What your dedicated team does with OWASP ZAP.

Scan configuration ages with the application. New routes appear, the login flow changes, and an alert that was ignored for good reason becomes relevant after a redesign. Someone has to own the rules file and the authentication context, or the scan keeps passing while testing less and less.

That ownership belongs with a DevSecOps engineer who stays on the product, which is how we run [offshore cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/).

## Common OWASP ZAP use cases.

* A passive scan on every build Baseline checks that are safe for shared environments and fail only on the rules the team agreed.
* Active scans on a separate environment Full scans run on a schedule against test data, away from anything customers use.
* API scanning from a definition OpenAPI or GraphQL definitions imported, so endpoints without a user interface are tested too.

## Adding OWASP ZAP skills to your team.

Pipeline scanning is set up and tuned within one committed monthly capacity across the security discipline, alongside the manual testing it supports.

OWASP ZAP specialists join your team remotely as dedicated, full-time team members, selected, employed and managed by us in Chiang Mai and Bangkok. Companies that [hire offshore developers](https://azendo.co/hire-a-dedicated-development-team-in-thailand/) through Azendo add the skill at the next monthly cycle.

## Roles that use OWASP ZAP

* [DevSecOps Engineer Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/devsecops-engineer/)
* [Penetration Tester Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/penetration-tester/)

## Disciplines it belongs to

* [Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/)

Capacity is agreed across your whole team, with one monthly fee, not per skill.

## Related in security

* [threat modelling, a skill in our teams](https://azendo.co/skills/threat-modelling/)
* [Burp Suite, a skill in our teams](https://azendo.co/skills/burp-suite/)
* [Semgrep, a skill in our teams](https://azendo.co/skills/semgrep/)
* [Snyk, a skill in our teams](https://azendo.co/skills/snyk/)
* [Trivy, a skill in our teams](https://azendo.co/skills/trivy/)
* [HashiCorp Vault, a skill in our teams](https://azendo.co/skills/hashicorp-vault/)
* [OWASP Top 10, a skill in our teams](https://azendo.co/skills/owasp-top-10/)

## Tell us what your roadmap needs OWASP ZAP for.

A service delivery manager will reply with the specialists we'd suggest, the monthly capacity and what the first month looks like.

[Browse all skills](https://azendo.co/skills/)
