Principal Engineer - Application Security

Target

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Brooklyn Park, MN
Salary
$168,000–$303,000 / yr
Posted
21 days ago
Freshness
Confirmed live 2 days ago
Closes
Sep 25, 2026

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $190k
This role $236k
$124k most similar roles pay here $322k

This role pays more than 86% of similar roles. Most pay $161,965–$217,625 — the shaded band above. At the midpoint, this role pays about $236k versus about $190k for comparable roles.

Based on 240 similar postings.

Employer

About Target

Target Corporation is a large-format general merchandise and grocery retailer offering a wide assortment of everyday essentials, apparel, home goods, and electronics through stores and online. Industry: General Merchandise Retail

Target currently has 58 open roles on FindRole.

Listed pay typically runs $98,000–$176,000 across 58 roles with salary data.

Most-posted roles

View all roles at Target

At a glance

TL;DR · Principal Engineer - Application Security

As a Principal Engineer - Application Security (AI security, Pen Testing, DevSecOps), you will provide technical leadership for the enterprise Application Security program. You will be responsible for advancing secure development practices by integrating security into the software development lifecycle and partnering with engineering teams to reduce risk through scalable solutions. Your daily work involves managing SSDLC, SAST, DAST, SCA, Threat Modeling, and Penetration Testing while building automation for CI/CD pipelines and developing tools, APIs, and frameworks to improve developer experience. You will leverage AI and generative AI technologies to automate tasks and enhance vulnerability detection. The role requires expertise in modern programming languages, cloud-native platforms like AWS, Azure, or Google Cloud, Kubernetes, containers, and microservices. You will solve complex security challenges for modern architectures while influencing technical decisions across the organization through collaboration and leadership.

What does a Engineer earn?

Median $185000 from 249 postings across 48 companies.

See salary data

What you'll do

  • Provide technical leadership across the Secure Software Development Lifecycle including SAST, DAST, SCA, and Threat Modeling.
  • Integrate security controls into CI/CD pipelines and modern DevSecOps workflows to automate security processes.
  • Develop custom tooling, APIs, and automation to improve developer experience and reduce manual effort.
  • Identify and implement AI and generative AI technologies to accelerate vulnerability detection and remediation.
  • Define the technical roadmap for the Application Security program through standardization and self-service capabilities.
  • Guide engineering teams in vulnerability remediation and the adoption of secure coding best practices.
  • Solve complex security challenges involving cloud-native platforms, Kubernetes, containers, and microservices architectures.
  • Establish and track metrics to measure program effectiveness and improve overall security maturity.

What we're looking for

  • BS/MS in Computer Science, Information Security, Engineering, or equivalent industry experience.
  • 10+ years of experience in software engineering, application security, or related security engineering roles.
  • Demonstrated expertise in SSDLC, SAST, DAST, SCA, Threat Modeling, and Penetration Testing.
  • Strong software development experience in one or more modern programming languages.
  • Experience integrating security into modern CI/CD pipelines and DevSecOps workflows.
  • Proven experience building and scaling Application Security programs across large engineering organizations.
  • Experience securing cloud-native applications in AWS, Azure, or Google Cloud including Kubernetes, containers, APIs, and microservices.
  • Industry certifications such as CISSP, CSSLP, GIAC, OSCP, or cloud security certifications (preferred).

More like this

Similar roles

Application Security Engineer

State Street

Quincy, MA +4 14 days ago $120,000$202,500
AppSec DevSecOps SAST DAST SCA CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC API Security Container Scanning
6+ yrs exp

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 23 days ago $118,000$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Principal Security Engineer

Oracle

Switzerland 77 days ago $106,300$234,600
Hardware Security Firmware x86 ARM UEFI Root of Trust Secureboot Cryptography Intel SGX C C++ Java Python Ruby Go Rust Assembly CICD SPDM SmartNICs
8+ yrs exp

Principal Security Engineer

JPMorgan Chase

Seattle, WA 25 days ago
AI Security Engineering Kubernetes Container Security CI/CD Endpoint Protection anti‑virus Product Management Automation

Principal Security Engineer

Microsoft

16 days ago $142,800$274,800
Threat Modeling Security Architecture Automation Distributed Systems APIs Risk Management Cyber Security Anomaly Detection Security Assessment Reference Architecture
6+ yrs exp

Lead Security Engineer, DevSecOps

CME Group

Chicago, IL 44 days ago $132,100$220,100
DevSecOps AWS GCP Azure Python Java JavaScript Node.js .NET C# C++ Bash Terraform CloudFormation Ansible Chef Puppet Docker Kubernetes CI/CD Git Maven Splunk CloudWatch Jira Cryptography NIST 800 PCI HIPAA
8+ yrs exp