Pay range: $168,000.00 – $303,000.00. Pay is based on labor markets, education, work experience and certifications.
Target offers comprehensive health benefits (medical, vision, dental, life insurance), 401(k), employee discount, short‑term disability, long‑term disability, paid sick leave, paid national holidays, and paid vacation. See https://corporate.target.com/careers/benefits for details.
About Target
Target is one of the world’s most recognized brands and a leading retailer. Our security team helps innovate daily; we focus on security and continuous improvement of AI systems and platforms.
Position Overview
As a Principal Engineer, you will collaborate with technical and leadership teams across Target Tech to assess, validate, and continuously improve the security of AI systems and platforms. You will identify security risks, evaluate controls, perform architectural reviews, and provide actionable recommendations. You will serve as a trusted advisor, driving continuous improvement and helping teams identify emerging risks.
Expect To
- Collaborate with AI platform, product, and engineering teams to evaluate the security posture of AI systems throughout their lifecycle
- Assess AI architectures, models, agents, and supporting infrastructure to identify security risks, vulnerabilities, and design weaknesses
- Develop and execute security validation strategies for AI systems, including threat modeling, attack simulation, and adversarial testing
- Evaluate the effectiveness of existing security controls, guardrails, and mitigations protecting AI applications and platforms
- Identify emerging AI‑specific threats, attack techniques, and vulnerabilities, and communicate their potential business impact
- Recommend risk mitigation strategies and prioritized remediation plans to improve the security and resilience of AI systems
- Conduct deep technical reviews of AI products, platforms, and architectures to identify opportunities for security improvement
- Partner with engineering teams to validate secure deployment patterns for AI workloads across cloud and hybrid environments
- Define security assessment methodologies, testing frameworks, and assurance standards for AI technologies
- Provide expert guidance on AI security best practices, including model security, prompt injection defenses, agent security, supply chain security, and data protection
- Prioritize high‑impact security improvements that measurably reduce risk while enabling innovation and business objectives
- Perform hands‑on security analysis and testing of complex AI‑enabled systems, identifying gaps in architecture, implementation, and operational controls
- Collaborate with security, architecture, and engineering teams to continuously improve AI security controls and governance practices
- Efficiently assess and communicate security risks to stakeholders, balancing technical realities, business priorities, and organizational objectives
- Serve as a trusted advisor on AI security, helping teams make informed decisions as AI capabilities evolve across the enterprise
About You
- 4‑year degree or equivalent experience
- Polyglot programmer comfortable in many languages across different platforms
- 10+ years of hands‑on experience in technology, with extensive knowledge of cybersecurity domains including Information Protection, Cloud Security (GCP strongly preferred), Networking Security, IAM, Automation, and SIEM
- LLM Security expertise (RAG, MCP, Input validation, Sandboxing, etc.)
- In‑depth understanding of OWASP top 10 for Large Language Model Applications
- Expertise in AI and ML
- Understanding of prompt injection and its various styles (direct, indirect, RAG poisoning, etc.)
- Understanding of MCP auth patterns including dynamic client registration
- Knowledge in RAG authorization patterns – “How do you implement RBAC in a RAG?”
- Understanding of OAuth roles and flows, and how it pertains to minimizing risky permissions
- Experience mitigating the security risks of local coding agents
- Solid understanding of containerization technologies and tools
- Seeks out cross‑team collaboration opportunities
- Demonstrated curiosity and ability to learn
- Stays current on relevant technologies with self‑directed learning
- Excellent written and verbal interpersonal skills with strong presentation abilities
- Proven history of effectively utilizing a variety of security tools and technologies across diverse environments
- Strong understanding of security frameworks, standards, and best practices (e.g., NIST, ISO/IEC 27001)
- Strong understanding of network security, cryptography, and secure software development
- Experience with security technologies such as firewalls, IDS/IPS, SIEM, and DLP
- Excellent analytical, problem‑solving, and communication skills
Preferred
- GCP native security product experience with LLM Security expertise
- Vertex AI experience
- AWS or Azure experience
This position may be considered for a Remote or Hybrid (Flex for Your Day) work arrangement based on Target's needs. Remote means working full‑time from home or an alternate location that is not a Target location. Hybrid means the core role may be performed either remotely or onsite at a Target location depending on the team's needs. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target.
Benefits Eligibility
For benefits eligibility for this role, please see https://tgt.biz/BenefitsForYou_F.
Americans With Disabilities Act (ADA)
In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com. Non‑accommodation‑related requests, such as application follow‑ups or technical issues, will not be addressed through this channel.