> Markdown version of [/jobs/ext/2540617-principal-engineer-application-security-sdlc-sast-dast-sca-threat-modeling-pen-testing-devsecops-ai](https://www.wearedevelopers.com/jobs/ext/2540617-principal-engineer-application-security-sdlc-sast-dast-sca-threat-modeling-pen-testing-devsecops-ai). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer - Application Security (SDLC, SAST, DAST, SCA, Threat Modeling, Pen Testing, DevSecOps, AI) - **Company:** Target Brands, Inc. - **Location:** Brooklyn Park, MN, United States - **Experience:** Expert - **Salary:** $168,000.0 - $303,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Application Frameworks, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cyber Security, Software Architecture, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Google Cloud, Enterprise Software Applications, Cloud Platform System, Spring Cloud, Software Security, Build Management, Kubernetes, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Microservices, Dynamic Application Security Testing - **Published:** August 12, 2026 - **Apply:** https://target.wd5.myworkdayjobs.com/targetcareers/job/7000-Target-Pkwy-NNCD-0375-Brooklyn-ParkMN-55445/Principal-Engineer---Application-Security--SDLC--SAST--DAST--SCA--Threat-Modeling--Pen-Testing--DevSecOps--AI-_R0000446172/apply ## About the Role * BS/MS in Computer Science, Information Security, Engineering or equivalent industry work experience * 10+ years of experience in software engineering, application security or related security engineering roles * Demonstrated expertise across SSDLC, SAST, DAST, SCA, Threat Modeling, and Penetration Testing * Strong software development experience in one or more modern programming languages * Experience integrating security into modern CI/CD pipelines and DevSecOps workflows * Proven experience building and scaling Application Security programs across large engineering organizations * Experience leveraging AI and Generative AI technologies to improve engineering productivity, security operations, or software development workflows * Demonstrated ability to evaluate, implement, and govern AI-enabled solutions while considering security, privacy, and organizational risk * Excellent communication, collaboration, and stakeholder management skills * Demonstrated ability to influence technical direction across multiple teams * Experience securing cloud-native applications in AWS, Azure or Google Cloud * Experience with Kubernetes, containers, APIs, and microservices architectures * Experience developing custom security tooling or automation * Knowledge of modern software supply chain security practices * Industry certifications such as CISSP, CSSLP, GIAC, OSCP, or cloud security certifications a plus, Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_F ## Description We are seeking a Principal Application Security Engineer to provide technical leadership for our enterprise Application Security program. This role is responsible for advancing secure development practices, integrating security into the software development lifecycle, and partnering with engineering teams to reduce application risk through scalable security solutions., * Provide technical leadership across Secure Software Development Lifecycle (SSDLC), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Threat Modeling, and Penetration Testing. * Guide engineering teams in vulnerability remediation and secure coding best practices. * Evaluate emerging application security technologies, emerging risks, and recommend pragmatic, risk-based improvements to application security capabilities. * Partner with Security Architecture to ensure application security practices align with enterprise security standards and design principles. Software Engineering and Automation * Design and build automation that integrates security seamlessly into CI/CD pipelines. * Develop tooling, APIs, and automation to improve developer experience and reduce manual effort. * Partner with platform engineering teams to implement security controls within modern development workflows. * Identify and implement opportunities to leverage AI and generative AI technologies to improve application security processes, automate repetitive tasks, enhance developer enablement, and accelerate vulnerability detection and remediation while ensuring responsible and secure use of AI. Security Strategy and Program Leadership * Help define the technical roadmap for the Application Security program. * Develop strategies that scale security across a large engineering organization through automation, standardization, and self-service capabilities. * Champion developer enablement by creating security guidance, reusable frameworks, documentation, and training. * Establish and track metrics that measure program effectiveness and continuously improve security maturity. Cross-Functional Collaboration * Influence technical decisions through collaboration and technical leadership rather than organizational authority. * Communicate security risks and recommendations effectively to technical and non-technical audiences. * Mentor engineers and promote security best practices across the organization. Problem Solving and Technical Leadership * Solve complex application security challenges involving modern software architectures and cloud-native platforms. * Drive continuous improvement across security tooling, developer workflows, and vulnerability management processes. * Provide technical leadership during the investigation and remediation of significant application security issues. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Serverless Architectures with Spring Cloud Functions and Knative](https://www.wearedevelopers.com/videos/814-serverless-architectures-with-spring-cloud-functions-and-knative) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [Kubernetes Native Java](https://www.wearedevelopers.com/videos/383-kubernetes-native-java) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)