Business Relationship Support Associate – GPL National Service Group (NSG) CSO 3
CyberJobs.Com · Brooklyn Park, MN · 3 days ago
$132k–$238k/yrFull-time
About the role
Join our team to improve Target's security and move the business forward. As a Senior Engineering Manager on the Operational Technology (OT) Security team, you'll lead a team of Lead Engineers responsible for standing up, operating, integrating, automating, and scaling OT security capabilities across Target's OT infrastructure.
Responsibilities
- Lead a team of Lead Engineers responsible for the day-to-day implementation and operation of Target's OT security capabilities.
- Establish good stakeholder communication, work closely with partner teams, and help drive requirements while being a strong advocate of safe, efficient, and secure engineering practices in OT environments.
- Own the end-to-end engineering, deployment, configuration, and ongoing operation of Target's OT security platforms — including OT asset visibility and exposure platforms and the data pipelines that move OT signal into enterprise systems.
- Operate these platforms as production systems: own their availability, performance, observability, coverage, data quality, upgrade cadence, and incident response, with clear service objectives and on-call coverage.
- Own OT vulnerability and exposure management: intake, normalization, correlation, deduplication, enrichment, and risk prioritization of OT findings — using operational consequence, asset criticality, exploitability, exposure, compensating controls, vendor supportability, and maintenance windows rather than CVSS alone.
- Own secure-configuration assurance for in-scope OT: develop hardening patterns, use OT security platforms and other available evidence to identify deviations, prioritize gaps, and validate remediation.
- Own the endpoint security workstream for OT: eligibility, compatibility testing, pilots, deployment, health monitoring, rollback, exception handling, and compensating-control recommendations.
- Provide white-glove engineering support for the highest-risk OT findings, while equipping OT Infrastructure, site teams, system owners, and vendors to execute most changes through their normal operational processes.
- Partner with Network Security on OT network segmentation and with IAM / Vendor Risk on vendor-access controls.
- Translate ISA/IEC 62443-aligned requirements into a prioritized engineering roadmap, and deliver against it predictably.
- Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation.
- Make pragmatic build-vs-buy decisions and own the lifecycle of the OT security tools the team operates: vendor relationship, evaluations/POCs, contract input, capability adoption, and sunsetting.
- Drive adoption of the team's controls across in-scope OT environments, including onboarding, exception/governance workflows, and enablement of OT Infrastructure and site teams.
- Treat the OT security control plane as a product: invest in automation, self-service, and platform thinking so controls scale with Target's OT footprint.
- Continuously reduce toil for both your team and Target's OT engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback into the remediation lifecycle.
- Provide security engineering consultation on new or materially changed in-scope OT solutions — including product/vendor evaluations, design reviews, endpoint compatibility assessments, hardening requirements, vulnerability-management expectations, telemetry requirements, and integration planning.
- Represent the team's work clearly to senior leadership: roadmap, risk reduction, operational health, and tradeoffs — in language tuned to the audience.
Qualifications
- A 4-year degree OR equivalent work experience
- 8+ years of hands-on experience in technology, with deep experience in OT and security engineering and the adjacent disciplines that make OT security work — asset visibility, vulnerability and exposure management, endpoint security, data engineering/automation, and integration with enterprise remediation and governance workflows
- 3+ years managing engineering teams with a strong track record of delivery in a platform, infrastructure, software development, or security engineering in an OT context
- Experience hiring, growing, and retaining senior engineering talent, and building or evolving team operating models
- You lead engineers, not just programs: you've owned the full stack of engineering management — hiring, performance, career growth, on-call culture, code review standards, postmortems, and operational excellence
- Demonstrated track record of running production platforms with clear service objectives, on-call coverage, change management, and continuous-improvement loops in environments where availability, safety, and continuity of operations are non-negotiable
- Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation — and delivering predictably against them
- Comfortable making and defending pragmatic build-vs-buy decisions, owning vendor relationships and tool lifecycles, and knowing when to invest in custom engineering vs. lean on a platform
- Demonstrated experience leading teams that operate OT and/or ICS security platforms at scale — such as Claroty XDome, Nozomi, Dragos, Armis, Tenable OT, or comparable OT asset visibility and exposure platforms
- Hands-on familiarity with ISA/IEC 62443 (and adjacent frameworks such as NIST CSF, NIST SP 800-82) — enough to align the team's controls to them, without being the policy author
- Experience deploying and operating endpoint security agents on OT-adjacent or constrained endpoints (e.g. EDR agents), including eligibility, compatibility testing, health monitoring, and exception handling
- Experience building and operating findings pipelines that integrate security signal into enterprise remediation/governance platforms (e.g., shipping asset, vulnerability, secure-configuration, and endpoint findings to centralized dashboards with ownership attribution and SLAs)
- Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architecture's requirements
- Automation-first engineering mindset, with hands-on fluency in at least one general-purpose language (e.g., Python, Go) and a track record of building reusable platforms and paved roads instead of one-off scripts
- Working knowledge of infrastructure as code (Terraform and equivalent) and CI/CD, and comfort integrating security tooling with modern engineering workflows
- Strong understanding of distribution-center automation, industrial control systems, or vendor-managed OT environments
- Experience with, or exposure to, adjacent OT-relevant disciplines — including OT network segmentation, vendor-access controls, and OT backup and recovery
- Strong cross-functional partner: comfortable working closely with partners across Security Architecture, BISO, Network Security, OT infrastructure, and site teams to align requirements, rollout plans, and operational ownership
- Effective at representing your team's work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail
- Good understanding of security management workflows in large enterprise organizations and complex environments, and of the current OT threat landscape and the challenges most organizations are facing
- Excellent written and verbal communication skills with strong presentation abilities
- Demonstrated curiosity, bias for action, and a genuine builder's mindset — you want to ship the platform, not just describe it