Sr. Engineer

Target Target · Retail · Bangalore, India

Sr. Engineer role focused on penetration testing and DAST for Target's applications and PCI assets. Responsibilities include managing the testing lifecycle, identifying vulnerabilities, consulting with teams, and owning the DAST program. Requires strong knowledge of security tools and scripting abilities.

What you'd actually do

  1. Perform penetration testing against our Target-developed applications, and our scoped PCI assets
  2. Manage the entire lifecycle of penetration testing from discovery, triage, testing, and validation of findings
  3. Identify and report security vulnerabilities in web applications, APIs, networks, and enterprise systems
  4. Provide clear, well-written assessments and findings with clearly defined business impact
  5. Consult with Target Tech and Security partner teams to explain findings, address security concerns, and provide guidance

Skills

Required

  • penetration testing experience
  • penetration testing and web application security testing
  • Burp Suite
  • security tools (nmap, nuclei, etc)
  • work independently and collaborate with teams
  • time management
  • meet deadlines
  • prioritize impactful findings
  • Mac, Windows, and Linux
  • automate and script tasks
  • problem-solving
  • critical-thinking skills
  • mentorship and knowledge-sharing
  • stays current with new and evolving technologies

Nice to have

  • GoLang
  • Python

What the JD emphasized

  • PCI required testing
  • DAST program lifecycle
  • Define and maintain DAST coverage strategy
  • Ensure high scan success rates and meaningful coverage
  • Continuously improve scan configurations, policies, and templates
  • Triage and validate findings to reduce false positives
  • Tune tools and rules to improve signal-to-noise ratio
  • Establish standard severity classification and risk scoring
  • Partner with vendors/tools teams for optimization