NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Penetration Tester in India
22 hours agoBe an early applicant
Apply with autofill
Apply with autofill
Target·Retail·22 hours ago
22 hours agoBe an early applicant

Sr. Engineer – Pen Tester

Bengaluru, IndiaSenior · 5-8 yearsPenetration Tester

Sign up free to see how well your resume matches this role.

Boost your chances at Target

How you compare FREE

?
Your scoreYour score: not yet known
→
67
Top 10%Top 10%: 67 out of 100

Top 10% of NextRaise users matched against Penetration Tester roles in India.

Must-have skills for this role

  • penetration testing
  • application security engineering
  • ethical hacking
  • python

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies.
  • Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems.
  • Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE).
  • Triage and validate vulnerabilities reported through bug bounty program.
  • Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams.
  • Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments.
  • Collaborate with external 3rd party security firms on penetration testing and threat hunting exercises.
  • Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC).

What they're looking for

  • Minimum of 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
  • Deep understanding of common web-based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level.
  • Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks.
  • Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC.
  • Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST).
  • Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT).
  • Ability to work with high autonomy and communicate technical security findings clearly to both technical and non-technical audiences.
  • Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP.

Nice to have

  • Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd).
  • Experience leveraging Slack/ChatOps to automate security tasks or reporting.
  • Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager).
  • Familiarity with containerization and orchestration tooling like Docker and Kubernetes.
  • Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About us:

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

Position Overview

The Penetration Tester is a critical member of the Application Security team, focused on identifying, validating, and resolving security vulnerabilities across our cloud infrastructure and applications. You will lead technical security assessments, including application-layer and network-layer penetration testing, to ensure all information assets are secured against evolving threats. This role is vital for maintaining our security posture and ensuring remediation efforts are effectively prioritized and executed.

Key Responsibilities

  • Perform comprehensive manual and automated application-layer penetration tests to identify vulnerabilities, adhering to industry standards and internal methodologies.
  • Conduct network-layer penetration tests encompassing all components supporting network functions and operating systems.
  • Validate segmentation and scope-reduction controls at least annually and after any significant changes to ensure isolation of the Cardholder Data Environment (CDE).
  • Triage and validate vulnerabilities reported through bug bounty program.
  • Document and risk-rate all findings, providing actionable remediation guidance to engineering and product teams.
  • Verify the correction of exploitable vulnerabilities through re-testing and post-remediation assessments.
  • Collaborate with external 3rd party security firms on  penetration testing and threat hunting exercises.
  • Ensure all security assessments and remediation activities meet compliance and regulatory obligations (e.g., PCI DSS, SOC).

Qualifications

  • Minimum of 4+ years of hands-on experience in penetration testing, ethical hacking, or application security engineering.
  • Deep understanding of common web-based attacks (SQLi, XSS, CSRF, XXE, etc.) and how to mitigate them at the application level.
  • Proficiency in scripting or programming languages such as Python, Go, Ruby, or Bash to automate security tasks.
  • Comprehensive knowledge of network protocols and security concepts, including TCP/IP, DNS, HTTP/S, TLS, and IPSEC.
  • Strong experience with security testing tools (e.g., BurpSuite Enterprise, SAST, DAST, and IAST).
  • Working knowledge of OWASP security fundamentals and API identity/access management (OAuth 2.0, OIDC, JWT).
  • Ability to work with high autonomy and communicate technical security findings clearly to both technical and non-technical audiences.
  • Relevant information security certification(s) such as OSCP, CEH, OSWE, or CISSP.

Bonus Qualifications

  • Direct experience managing or triaging a public bug bounty program (e.g., HackerOne, BugCrowd).
  • Experience leveraging Slack/ChatOps to automate security tasks or reporting.
  • Experience with cloud orchestration and Infrastructure as Code (e.g., Terraform, Google Deployment Manager).
  • Familiarity with containerization and orchestration tooling like Docker and Kubernetes.
  • Knowledge of compliance frameworks such as ISO 27001, PCI DSS, SOC2, or CCPA.

Retail

Company

TargetRetail
Bengaluru, India

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Target's careers site·first seen 21 Sept 2026·last verified 21 Sept 2026·How we source jobs

Similar jobs

  • Penetration Tester (AEV) at breachlockPune, India–match not yet calculated
  • Senior Penetration Testing Analyst 2 at sophosIndia–match not yet calculated
  • Penetration Testing Analyst 3 at sophosIndia–match not yet calculated
  • Red Team Engineer at infiosBengaluru, India–match not yet calculated
  • Content Adversarial Red Team Analyst at GoogleHyderabad, India–match not yet calculated

Browse more jobs

  • Penetration Tester jobs in India
  • Security Engineer jobs in India
  • Security Analyst jobs in India
  • Cloud Security Engineer jobs in India
  • Penetration Tester jobs in United States
  • Penetration Tester jobs in Singapore