Senior Engineer -Pentesting

Target

Bengaluru

On-site

INR 1,800,000 - 3,000,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Target in Bengaluru is seeking a seasoned Penetration Tester to lead security assessments across cloud and applications. You will perform manual and automated testing to identify vulnerabilities, and work with engineering teams to prioritize remediations.

You should have 4+ years' experience, strong knowledge of OWASP top attacks, and hands-on in BurpSuite, Python, and cloud security. Certifications like OSCP/CEH are preferred. The role emphasizes PCI DSS and SOC compliance.

Qualifications

  • Minimum of 4+ years in penetration testing or application security.
  • Strong knowledge of web attack vectors and mitigations.
  • Proficiency in scripting for automation (Python/Go/Bash).
  • Experience with Burp Suite, SAST/DAST/IAST tools.
  • Certifications such as OSCP/CEH/OSWE/CISSP preferred.

Responsibilities

  • Perform manual and automated application-layer penetration tests to identify vulnerabilities.
  • Conduct network-layer tests across supporting components and OS.
  • Validate segmentation and controls to protect the Cardholder Data Environment (CDE).
  • Triage vulnerabilities from bug bounty programs and provide remediation guidance.
  • Document findings with risk ratings and work with engineering teams on fixes.
  • Verify fix correctness through re-testing and post-remediation assessments.
  • Collaborate with external security firms on testing and threat hunting.
  • Ensure compliance with PCI DSS, SOC and other regulatory obligations.

Skills

Penetration testing
Ethical hacking
Python
Network security
Burp Suite
Cloud security

Education

OSCP
CEH
CISSP

Tools

Burp Suite
OWASP ZAP
Nessus
Terraform
Docker/Kubernetes

Job description

As a Fortune 50 company with more than 400,000 team members worldwide, Target is an iconic brand and one of America's leading retailers. Joining Target means promoting a culture of mutual care and respect and striving to make the most meaningful and positive impact. Becoming a Target team member means joining a community that values different voices and lifts each other up. Here, we believe your unique perspective is important, and you'll build relationships by being authentic and respectful.

Position Overview

The Penetration Tester at is a critical member of the Application Security team, focused on identifying, validating, and resolving security vulnerabilities across our cloud infrastructure and applications. You will lead technical security assessments, including application-layer and network-layer penetration testing, to ensure all information assets are secured against evolving threats. This role is vital for maintaining our security posture and ensuring remediation efforts are effectively prioritized and executed.

Key Responsibilities
  • Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies.
  • Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems.
  • Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE).
  • Triage and validate vulnerabilities reported through bug bounty program.
  • Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams.
  • Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments.
  • Collaborate with external 3rd party security firms on penetration testing and threat hunting exercises.
  • Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC).
Qualifications
  • Minimum of 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
  • Deep understanding of common web-based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level.
  • Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks.
  • Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC.
  • Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST).
  • Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT).
  • Ability to work with high autonomy and communicate technical security findings clearly to both technical and non-technical audiences.
  • Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP.
Preferred Qualifications
  • Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd).
  • Experience leveraging Slack/ChatOps to automate security tasks or reporting.
  • Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager).
  • Familiarity with containerization and orchestration tooling like Docker and Kubernetes.
  • Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Penetration Tester
Senior Penetration Tester

Target Corporation India Pvt Ltd • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Sr. Engineer – Pen Tester
Sr. Engineer – Pen Tester

Target • Bengaluru

On-site
INR 2,800,000 - 3,800,000
Penetration Testing Senior Consultant
Penetration Testing Senior Consultant

Alignity Solutions • Hyderabad

Hybrid
INR 1,800,000 - 3,000,000
Hybrid work
VAPT Security Engineer
VAPT Security Engineer

Zohorecruit • Hyderabad

Hybrid
INR 1,800,000 - 2,800,000
Senior Penetration Tester
Senior Penetration Tester

Motadata • Ahmedabad District

On-site
INR 1,200,000 - 2,400,000
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

Hybrid
INR 2,500,000 - 5,500,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Technical Lead-Cybersecurity
Technical Lead-Cybersecurity

Birlasoft • Dadri

On-site
INR 1,200,000 - 2,400,000
Penetration Tester
Penetration Tester

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Senior Penetration Tester
Senior Penetration Tester

Booking Holdings • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000