Sr. Engineer - Pen Tester

Target Brands, Inc.
United States
2 days ago
Apply on target.wd5.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Bash Shell Cloud Computing Cyber Security Cross-Site Request Forgery Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Identity and Access Management Internet Protocol Security (IP SEC) Python (Programming Language) Network Functions Virtualization
+19 more
Network Protocols OAuth OpenID Open Web Application Security PCI Data Security Standards Ruby JSON Web Token SQL Injection TCP/IP Scripting Software Security Cross-Site Scripting (XSS) Terraform Burpsuite Docker Static Application Security Testing Golang Programming Languages Dynamic Application Security Testing

Job description

The Penetration Tester is a critical member of the Application Security team, focused on identifying, validating, and resolving security vulnerabilities across our cloud infrastructure and applications. You will lead technical security assessments, including application-layer and network-layer penetration testing, to ensure all information assets are secured against evolving threats. This role is vital for maintaining our security posture and ensuring remediation efforts are effectively prioritized and executed., * Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies.

  • Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems.
  • Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE).
  • Triage and validate vulnerabilities reported through bug bounty program.
  • Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams.
  • Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments.
  • Collaborate with external 3rd party security firms on penetration testing and threat hunting exercises.
  • Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC).

Requirements

  • Minimum of 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
  • Deep understanding of common web-based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level.
  • Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks.
  • Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC.
  • Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST).
  • Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT).
  • Ability to work with high autonomy and communicate technical security findings clearly to both technical and non-technical audiences.
  • Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP., * Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd).
  • Experience leveraging Slack/ChatOps to automate security tasks or reporting.
  • Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager).
  • Familiarity with containerization and orchestration tooling like Docker and Kubernetes.
  • Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA.

Benefits & conditions

Your financial well-being is bright with TII’s comprehensive flexible insurance program, National Pension System, learning assistance program, day care support and much more.

Paid time off

TII encourages work-life balance with paid time off like privilege, casual, bereavement and parental leaves that offer support in all stages of life.

Competitive pay

TII knows our people are everything and proudly provides equitable and competitive pay.

Other benefits

From digitalized cafeteria solutions to transportation services to broadband reimbursement, enjoy special everyday perks. More about pay & benefits

Eligibility requirements may vary based on position, average hours worked, length of service and program requirements. Benefits are subject to change.

About the company

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on target.wd5.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all