Sr. Engineer – Pen Tester

Target

Bengaluru

On-site

INR 2,800,000 - 3,800,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Target is seeking a Penetration Tester to join our Application Security team in Bengaluru. You will perform manual and automated tests across cloud infrastructure and applications, focusing on identifying vulnerabilities and guiding remediation with engineering teams.

You will leverage BurpSuite, SAST/DAST/IAST tools and scripting in Python/Go to automate tasks, while maintaining PCI DSS and SOC compliance and working with external security partners when needed.

Qualifications

  • 4+ years of hands-on penetration testing, ethical hacking, or app security.
  • Knowledge of web attacks (SQLi, XSS, CSRF, XXE) and mitigations at the app layer.
  • Scripting in Python/Go/Ruby/Bash to automate security tasks.
  • Understanding of TCP/IP, DNS, HTTP/S, TLS, IPSEC networking concepts.
  • Experience with BurpSuite Enterprise, SAST/DAST/IAST tools.
  • Familiarity with OWASP security concepts and API identity management.
  • Ability to communicate findings clearly to technical and non-technical audiences.
  • Relevant information security certifications (OSCP, CEH, OSWE, CISSP).

Responsibilities

  • Perform manual and automated application-layer penetration tests.
  • Conduct network-layer penetration tests across components and OS.
  • Validate segmentation controls around the CDE and after changes.
  • Triage and validate vulnerabilities reported via bug bounty programs.
  • Document risk ratings and provide remediation guidance to teams.
  • Re-test and verify remediation of exploitable vulnerabilities.
  • Collaborate with external security firms on testing and threat hunting.
  • Ensure assessments meet PCI DSS, SOC and regulatory requirements.

Skills

Penetration testing
Scripting (Python/Go)
Network security
OWASP knowledge
Communication

Education

OSCP/CEH/OSWE/CISSP

Tools

BurpSuite Enterprise
SAST
DAST
IAST
Terraform
Docker
Kubernetes

Job description

About us:

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

Position Overview

The Penetration Tester is a critical member of the Application Security team, focused on identifying, validating, and resolving security vulnerabilities across our cloud infrastructure and applications. You will lead technical security assessments, including application-layer and network-layer penetration testing, to ensure all information assets are secured against evolving threats. This role is vital for maintaining our security posture and ensuring remediation efforts are effectively prioritized and executed.

Key Responsibilities
  • Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies.
  • Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems.
  • Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE).
  • Triage and validate vulnerabilities reported through bug bounty program.
  • Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams.
  • Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments.
  • Collaborate with external 3rd party security firms on penetration testing and threat hunting exercises.
  • Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC).
Qualifications
  • Minimum of 4+ years of hands‑on experience in penetration testing, ethical hacking, or application security engineering.
  • Deep understanding of common web‑based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level.
  • Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks.
  • Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC.
  • Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST).
  • Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT).
  • Ability to work with high autonomy and communicate technical security findings clearly to both technical and non‑technical audiences.
  • Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP.
Bonus Qualifications
  • Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd).
  • Experience leveraging Slack/ChatOps to automate security tasks or reporting.
  • Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager).
  • Familiarity with containerization and orchestration tooling like Docker and Kubernetes.
  • Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer -Pentesting
Senior Engineer -Pentesting

Target • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior Penetration Tester
Senior Penetration Tester

Motadata • Ahmedabad District

On-site
INR 1,200,000 - 2,400,000
Penetration Tester (SMB)
Penetration Tester (SMB)

BreachLock, Inc. • Dadri

On-site
INR 1,200,000 - 2,400,000
Private Health Insurance
Application and Product Security I Analyst III (Pen Tester)
Application and Product Security I Analyst III (Pen Tester)

Vertiv Co • Pune District

On-site
INR 2,500,000 - 4,200,000
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Penetration Tester (ME)
Penetration Tester (ME)

BreachLock, Inc. • Dadri

On-site
INR 1,200,000 - 2,400,000
Private Health Insurance
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

Hybrid
INR 2,500,000 - 5,500,000
Penetration Tester
Penetration Tester

Alignity Solutions • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
Security Test Engineer
Security Test Engineer

Cyient • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Security Tester
Security Tester

Disprz • Chennai District

On-site
INR 1,800,000 - 3,600,000