698,236open jobs
41,342companies
99,387added this week
Browse all
Location
In office (Bengaluru)
Seniority
Senior · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Target is an American general merchandise retailer founded in 1902 as the Dayton Dry Goods Company, which opened the first discount store under the Target name in 1962. It runs roughly two thousand stores across the United States selling apparel, home goods, beauty, electronics, toys and groceries, and has built its position on design partnerships and owned brands that give it products competitors cannot stock. Headquartered in Minneapolis and listed on the New York Stock Exchange, it fulfils the large majority of digital orders from its own stores rather than from separate warehouses.

About us:

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

Position Overview

The Penetration Tester is a critical member of the Application Security team, focused on identifying, validating, and resolving security vulnerabilities across our cloud infrastructure and applications. You will lead technical security assessments, including application-layer and network-layer penetration testing, to ensure all information assets are secured against evolving threats. This role is vital for maintaining our security posture and ensuring remediation efforts are effectively prioritized and executed.

Key Responsibilities

  • Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies.
  • Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems.
  • Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE).
  • Triage and validate vulnerabilities reported through bug bounty program.
  • Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams.
  • Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments.
  • Collaborate with external 3rd party security firms on penetration testing and threat hunting exercises.
  • Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC).

Qualifications

  • Minimum of 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
  • Deep understanding of common web-based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level.
  • Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks.
  • Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC.
  • Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST).
  • Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT).
  • Ability to work with high autonomy and communicate technical security findings clearly to both technical and non-technical audiences.
  • Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP.

Bonus Qualifications

  • Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd).
  • Experience leveraging Slack/ChatOps to automate security tasks or reporting.
  • Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager).
  • Familiarity with containerization and orchestration tooling like Docker and Kubernetes.
  • Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
698,236 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$17k – $37k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Python
Go
JavaScript
Kotlin
TypeScript
AI/ML
AI Agents
LLM
RAG
Machine Learning
DevOps
CI/CD
Apply
$15k – $36k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Minsk
Python
JavaScript
DevOps
Rest API
CI/CD
Git
GitHub
Management
Confluence
Agile
QA
Swagger
Postman
Apply
$23k – $42k per year (Estimated) • Remote • 5+ years exp • Moscow
Python
Go
Java
Rust
Kotlin
C++
Python
FastAPI
Asyncio
C++
PyTorch C++
Databases
PostgreSQL
Redis
ClickHouse
Milvus
pgvector
Qdrant
MinIO
Apache Kafka
AI/ML
LangGraph
LangChain
Model Context Protocol
vLLM
CUDA Toolkit
Triton Inference Server
AI Agents
NLP
SGLang
LiteLLM
PyTorch
LLM
RAG
KServe
CUDA
Triton
OpenAI
A2A
Context Engineering
LLM Guardrails
Tool Use
DevOps
gRPC
Helm
OpenTelemetry
Prometheus
GitLab CI
CI/CD
Kubernetes
GitLab
Amazon S3
Apply
$50k – $118k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
Python
Go
Lua
Databases
PostgreSQL
Redis
KeyDB
Memcached
DevOps
gRPC
GCP
GitHub Actions
Datadog
Prometheus
WebSockets
GitLab CI
CI/CD
Game Dev
Nakama
Apply
$17k – $40k per year (Estimated) • Remote/Hybrid • 3+ years exp • Bachelor's Degree • Almaty
Python
JavaScript
DevOps
Rest API
CI/CD
Git
GitHub
Management
Confluence
Agile
QA
Swagger
Postman
Apply
$36k – $54k per year • In office • Portland
Mobile
Adjust
DevOps
Rest API
Apply
$32k – $48k per year • In office • Streetsboro
Apply
Starbucks Barista 4 hours ago
$40k per year • In office • Dublin
Mobile
Adjust
DevOps
Rest API
Apply
$17k – $37k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Python
Go
JavaScript
Kotlin
TypeScript
AI/ML
AI Agents
LLM
RAG
Machine Learning
DevOps
CI/CD
Apply
Starbucks Barista 4 hours ago
$40k per year • In office • San Juan Capistrano
Mobile
Adjust
DevOps
Rest API
Apply
$42k – $89k per year (Estimated) • In office • Full-Time • 12+ years exp • PhD • Bengaluru
Rust
C++
DevOps
gRPC
OpenTelemetry
Kubernetes
Apply
Admin Executive 1 day ago
$13k – $31k per year (Estimated) • In office • Full-Time • 2+ years exp • Master's Degree • Bengaluru
Management
Microsoft Office
Apply
$14k – $35k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Bengaluru
Apply
$23k – $67k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru • Hyderabad
Apply
Remote • Full-Time • Bengaluru
Marketing
LinkedIn
Instagram
Apply
See all jobs
This is one of many
698,236 more open roles from verified company boards, updated every day.