Lead Engineer Cloud Security (Cloud Security Platform & CSPM)
Brooklyn Park, MN - USA
Job Summary
Pay is based on several factors which vary based on include labor markets and in some instancesmay include education work experience and addition to your pay Target cares about and invests in you as a team member so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs which may include medical vision dental life insurance and more to help you and your family take care of your whole benefits for eligible team members include 401(k) employee discount short term disability long term disability paid sick leave paid national holidays and paid competitive benefits from financial and education to well-being and beyond at Us
Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here. Target is one of the worlds most recognized brands and one of Americas leading retailers. But behind the brand our guests love is a culture of continual innovation and right now we are up to big things! Targets security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning engineering excellence and stellar outcomes We are too thats why we work here. Join our team to improve Targets security and move the business forward.
As a Lead Engineer on the Cloud Security team youll be the senior technical owner of Targets Cloud Security Platform and CSPM capability across our public and private cloud environments. Youll be the person the team our partners and leadership look to for how CSPM and the broader CNAPP surface should be designed deployed operated and evolved at Target scale turning posture signal into action and controls into paved roads that developers can actually use.
Beyond deep technical expertise you have a strong bias for action and a builders mindset. The Cloud Security Platform sits between architecture and the engineering teams who consume it and you are comfortable operating in that realm translating security requirements into reliable automated developer-friendly controls; owning the day-to-day operation and continuous improvement of the CSPM/CNAPP platform; coordinating exceptions and developer-experience tradeoffs and partnering with peers so that cloud security findings flow into the enterprise remediation lifecycle. You have the engineering credibility to set technical direction for a team of engineers as a hands-on IC and the communication and partnership skills to make the controls land well across Target.
Expect to:
Serve as the senior technical lead and hands-on owner of Targets Cloud Security Platform and CSPM capability setting the technical direction standards and roadmap that other engineers execute against.
Own the end-to-end engineering deployment configuration tuning and ongoing operation of the CSPM/CNAPP platform across Targets public and private cloud environments including onboarding of new cloud accounts projects and workloads leading the implementation and operation of core functional controls and managing operations such as RBAC and SSO.
Operate the platform as a production system: own its availability performance observability capacity upgrade cadence and outage response with clear SLOs and on-call participation.
Own the CSPM policy set end-to-end: which rules are on which are tuned which are suppressed and why grounded in Targets reference architecture secure configuration benchmarks and the realities of our environment.
Peer with Cloud Security software developers on design of the findings pipeline for CSPM and adjacent CNAPP signal. The pipeline will aggregate posture findings deduplicate and enrich them with ownership attribution and ship them into Targets enterprise remediation dashboards with SLAs so product and platform teams can act.
Drive continuous reduction of noise and false positives so every finding that reaches an engineer is worth their time.
Extend ownership into adjacent CNAPP capabilities delivered by the same platform cloud workload posture container/image posture cloud identity/entitlement (CIEM) findings and IaC posture signal coordinating with the engineers who own the deeper IaC scanning admission control and SSPM controls.
Partner with Detection & Response to turn high-signal posture and runtime findings into detections and to support cloud incident response with the context the platform can provide.
Drive multi-quarter initiatives end-to-end: from problem framing and scoping through design build rollout adoption and steady-state operation.
Make pragmatic build-vs-buy calls within the platforms ecosystem and own the technical side of the tools lifecycle: evaluations/POCs capability adoption integration work and input into vendor and contract discussions.
Treat the Cloud Security Platform as a product: invest in automation self-service and platform thinking so CSPM coverage and remediation scale with Targets cloud footprint rather than with headcount.
Continuously reduce toil for both the team and Targets engineering organization fewer one-off tickets more paved roads better defaults faster feedback for developers.
Own the developer experience of the platforms findings and controls: clear explanations documented escape hatches fast and well-coordinated exception handling and a tight feedback loop with product engineering.
Drive adoption of the platforms coverage across Target Tech including onboarding exception/governance workflows and developer enablement.
Integrate cloud security telemetry from the platform into Targets enterprise SIEM/SOAR pipelines and remediation/governance systems.
Partner with the broader Cloud Platform organization Identity Security Network Security Data Security Detection & Response Vulnerability Management BISO and product engineering to align on requirements rollout plans and operational ownership.
Represent the platforms work clearly to senior leadership and to staff engineers alike: roadmap risk reduction operational health and tradeoffs in language tuned to the audience.
Mentor other engineers on the team on cloud security CSPM/CNAPP and platform engineering practices and raise the bar for code quality testing code review on-call hygiene postmortems and operational excellence.
Core responsibilities are described within this job description. Job duties may change at any time due to business needs.
About You:
4-year degree OR equivalent work experience
7 years of hands-on experience in technology with deep experience in cloud security and the adjacent disciplines that make it work cloud platform engineering CSPM Kubernetes IaC/CI-CD automation identity and detection/response integration
Demonstrated experience as a senior IC or tech lead owning a security or platform capability end-to-end at enterprise scale including setting technical direction that other engineers execute against
Deep hands-on experience deploying operating and tuning a CSPM or CNAPP platform in a large multi-cloud environment including onboarding accounts authoring and tuning policies managing exceptions and driving findings to remediation
Strong opinions backed by experience on how to keep CSPM signal-to-noise high: policy tuning suppression discipline ownership attribution and SLA-based remediation
Track record of running production platforms with clear SLOs on-call coverage change management and continuous-improvement loops
Experience driving multi-quarter roadmaps end-to-end from problem framing through rollout adoption and steady-state operation and delivering predictably against them
Comfortable making and defending pragmatic build-vs-buy decisions and knowing when to invest in custom engineering vs. lean on a platform capability
Hands-on experience with public cloud (GCP preferred; AWS/Azure experience also valued) and private cloud / Kubernetes environments at enterprise scale
Working knowledge of Kubernetes and admission controller frameworks enough to partner effectively with the engineers who own those controls and to integrate posture signal across them
Strong working knowledge of infrastructure as code (Terraform and equivalent) and policy-as-code (e.g. Rego) and familiarity with integrating policy and posture signal into CI/CD
Experience building and operating findings pipelines that integrate cloud security signal into enterprise remediation/governance platforms (shipping CSPM and adjacent CNAPP findings to centralized dashboards with ownership attribution & SLAs)
Experience integrating cloud telemetry into enterprise SIEM/SOAR pipelines
Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architectures requirements
Hands-on experience integrating security tooling with developer workflows (CI/CD source control ticketing) in a way that scales with a large engineering organization
Strong understanding of secure software development practices network security fundamentals and modern cloud-native architectures
Solid understanding of AI/ML and the emerging security considerations associated with it including how to surface and enforce them through cloud security tooling
Automation-first engineering mindset with hands-on fluency in at least one general-purpose language (e.g. Python Go) and a track record of building reusable platforms and paved roads instead of one-off scripts
Strong cross-functional partner: comfortable working closely with a variety of security and product engineering teams to align requirements rollout plans and operational ownership
Effective at representing your work risks and tradeoffs to senior leadership and equally effective explaining the same content to staff engineers in detail
Good understanding of security management workflows in large enterprise organizations and complex environments and of the current threat landscape and the challenges most organizations are facing
Working knowledge of security frameworks standards the cloud threat landscape and best practices (e.g. NIST CIS Benchmarks ISO/IEC 27001) enough to align the platforms controls to them without being the policy author
Excellent written and verbal communication skills with strong presentation abilities
Demonstrated curiosity bias for action and a genuine builders mindset you want to ship the platform not just describe it
This position will operate as a Hybrid/Flex for Your Day work arrangement based on Targets needs. A Hybrid/Flex for Your Day work arrangement means the team members core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually depending upon what your role team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.
Benefits Eligibility
Please paste this url into your preferred browser to learn about benefits eligibility for this role: with Disabilities Act (ADA)In compliance with state and federal laws Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process please reach out to Non-accommodation-related requests such as application follow-ups or technical issues will not be addressed through this channel.
Required Experience:
Senior IC
About Company
1234 employees
Target Corporation is an American retail corporation. The eighth-largest retailer in the United States, it is a component of the S&P 500 Index.