> Markdown version of [/jobs/ext/3040932-sr-engineer-pen-tester](https://www.wearedevelopers.com/jobs/ext/3040932-sr-engineer-pen-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Engineer - Pen Tester - **Company:** Target Brands, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, Bash Shell, Cloud Computing, Cyber Security, Cross-Site Request Forgery, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Identity and Access Management, Internet Protocol Security (IP SEC), Python (Programming Language), Network Functions Virtualization, Network Protocols, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Ruby, JSON Web Token, SQL Injection, TCP/IP, Scripting, Software Security, Cross-Site Scripting (XSS), Terraform, Burpsuite, Docker, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** September 23, 2026 - **Apply:** https://target.wd5.myworkdayjobs.com/targetcareers/job/BangaloreIndia/Sr-Engineer---Pen-Tester_R0000453961/apply ## About the Role * Minimum of 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering. * Deep understanding of common web-based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level. * Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks. * Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC. * Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST). * Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT). * Ability to work with high autonomy and communicate technical security findings clearly to both technical and non-technical audiences. * Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP., * Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd). * Experience leveraging Slack/ChatOps to automate security tasks or reporting. * Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager). * Familiarity with containerization and orchestration tooling like Docker and Kubernetes. * Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA. ## Description The Penetration Tester is a critical member of the Application Security team, focused on identifying, validating, and resolving security vulnerabilities across our cloud infrastructure and applications. You will lead technical security assessments, including application-layer and network-layer penetration testing, to ensure all information assets are secured against evolving threats. This role is vital for maintaining our security posture and ensuring remediation efforts are effectively prioritized and executed., * Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies. * Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems. * Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE). * Triage and validate vulnerabilities reported through bug bounty program. * Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams. * Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments. * Collaborate with external 3rd party security firms on penetration testing and threat hunting exercises. * Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)