Principal Engineer - Application Security; AI security, Pen Testing, DevSecOps
Listed on 2026-08-24
-
IT/Tech
Cybersecurity
The pay range is $ - $
Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves.
Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at
Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.
AboutThe Role
We are seeking a Principal Application Security Engineer to provide technical leadership for our enterprise Application Security program. This role is responsible for advancing secure development practices, integrating security into the software development lifecycle, and partnering with engineering teams to reduce application risk through scalable security solutions. The ideal candidate combines deep technical expertise with strategic thinking, enables developers, scales security through automation, and influences engineering organizations without direct authority.
ApplicationSecurity Expertise
- Provide technical leadership across Secure Software Development Lifecycle (SSDLC), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Threat Modeling, and Penetration Testing.
- Guide engineering teams in vulnerability remediation and secure coding best practices.
- Evaluate emerging application security technologies, emerging risks, and recommend pragmatic, risk-based improvements to application security capabilities.
- Partner with Security Architecture to ensure application security practices align with enterprise security standards and design principles.
- Design and build automation that integrates security seamlessly into CI/CD pipelines.
- Develop tooling, APIs, and automation to improve developer experience and reduce manual effort.
- Partner with platform engineering teams to implement security controls within modern development workflows.
- Identify and implement opportunities to leverage AI and generative AI technologies to improve application security processes, automate repetitive tasks, enhance developer enablement, and accelerate vulnerability detection and remediation while ensuring responsible and secure use of AI.
- Help define the technical roadmap for the Application Security program.
- Develop strategies that scale security across a large engineering organization through automation, standardization, and self-service capabilities.
- Champion developer enablement by creating security guidance, reusable frameworks, documentation, and training.
- Establish and track metrics that measure program effectiveness and continuously improve security maturity.
- Influence technical decisions through collaboration and technical leadership rather than organizational authority.
- Communicate security risks and recommendations effectively to technical and non-technical audiences.
- Mentor engineers and promote security best practices across the organization.
- Solve complex application security challenges involving modern software architectures and cloud-native platforms.
- Drive continuous improvement across security tooling, developer workflows, and vulnerability management processes.
- Provide technical leadership during the investigation and remediation of significant application security issues.
Core responsibilities of this job are described within this job description. Job…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).