Jobs · Minnesota

Lead Engineer - Cloud Security (Software Engineering)

Target · Brooklyn Park, MN · 2 wk ago
$132k–$238k/yrFull-time

Pay range: $132,000.00 - $238,000.00. Pay is based on several factors including labor markets, education, work experience, and certifications.

Benefits

  • Comprehensive health benefits and programs for eligible team members and their dependents, including medical, vision, dental, and life insurance
  • 401(k) retirement savings plan
  • Employee discount
  • Short-term and long-term disability coverage
  • Paid sick leave, national holidays, and vacation

Find competitive benefits from financial and education to well-being and beyond at Target's benefits page.

About Us

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Target is one of the world's most recognized brands and one of America's leading retailers, with a culture of continual innovation.

Target's security team is a place where innovation happens daily. We are building a culture that combines ongoing learning, engineering excellence, and stellar outcomes. Join our team to improve Target's security and move the business forward.

About the Role

As a Lead Engineer on the Cloud Security team, you'll be the senior software engineer building and owning the services that turn Target's cloud security signal into action. Cloud Security at Target is one team with two engineering disciplines:

  • Platform engineers who deploy, tune, and operate cloud security controls (CSPM/CNAPP, IaC scanning, admission control, SSPM, workload protection)
  • Software engineers who build the services that aggregate, attribute, enrich, and distribute the findings those controls produce, plus the broader backend the team's capabilities depend on

You will lead the software engineering side of this partnership. You have a strong bias for action and a builder's mindset, translating security requirements into reliable, well-tested backend services. You will own the day-to-day operation and continuous improvement of the findings pipeline and adjacent services, coordinating APIs, data contracts, and developer-experience tradeoffs.

Responsibilities

  • Serve as the senior software engineering lead and hands-on owner of the Cloud Security team's software portfolio, setting technical direction, standards, and roadmap
  • Lead the design, development, and operation of the findings pipeline: services that ingest cloud security signal from CSPM/CNAPP, IaC scanning, admission control, SSPM, and workload protection; deduplicate, normalize, enrich with ownership attribution and business context; and route to Target's enterprise remediation dashboards with SLAs
  • Design and build scalable backend services in Kotlin, Java, and Spring Boot — event-driven or request/response — with clean APIs, clear data contracts, and observability
  • Own the ownership-attribution problem end-to-end: data model, sources of truth, reconciliation logic, and feedback loops
  • Own the noise-reduction problem on the software side: deduplication, correlation, suppression logic, and enrichment to ensure every finding is actionable
  • Build integrations connecting the team's services into Target's enterprise ecosystem: SIEM/SOAR, remediation and governance platforms, ticketing, source control, CI/CD, and internal developer platforms
  • Operate these services as production systems: own availability, performance, observability, capacity, deploy cadence, and outage response with clear SLOs and on-call participation
  • Collaborate closely with platform engineers owning CSPM/CNAPP, IaC scanning, admission control, and SSPM to define shared API and data contracts
  • Partner with Detection & Response to turn high-signal posture and runtime findings into detections and build software support for cloud incident response
  • Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation
  • Make pragmatic build-vs-buy decisions and own the technical lifecycle of libraries, frameworks, and third-party components
  • Treat the software portfolio as a product: invest in automation, self-service, and platform thinking to scale coverage and remediation with Target's cloud footprint
  • Continuously reduce toil for the team and Target's engineering organization through paved roads, better defaults, and faster feedback
  • Own the developer experience of the team's APIs and services: clean contracts, clear error messages, documented usage patterns, and tight feedback loops
  • Establish engineering patterns and standards for APIs, event streams, data models, automated testing, observability, resiliency, secure service development, and CI/CD
  • Guide database schema evolution, data migrations, cloud-based data warehouse design, API versioning, and backward-compatible platform changes
  • Represent the team's software work to senior leadership and staff engineers, communicating roadmap, risk reduction, operational health, and tradeoffs
  • Mentor other software engineers on backend engineering, distributed systems, and cloud security software practices
  • Evaluate emerging technologies, including AI-assisted and agentic engineering tools, and apply them responsibly

Requirements

  • 4-year degree in Computer Science, Engineering, or a related field, OR equivalent work experience
  • 7+ years of software engineering experience, with a strong track record leading the design and delivery of complex, platform-oriented backend systems
  • Deep hands-on experience with Kotlin, Java, and Spring Boot, and strong fluency in at least one additional modern language
  • Demonstrated experience as a tech lead owning a software capability end-to-end at enterprise scale, including setting technical direction
  • Deep experience designing, building, and operating distributed, event-driven, and data-intensive backend services in production
  • Experience designing RESTful APIs, service-to-service integrations, and event streams that other teams depend on
  • Experience building and operating findings, event, or telemetry pipelines that aggregate signal from multiple sources, deduplicate, enrich, and route it with SLAs
  • Strong opinions on maintaining high signal-to-noise in findings or alert pipelines: deduplication, correlation, suppression, ownership attribution, and SLA-based remediation
  • Track record of running production services with clear SLOs, on-call coverage, change management, and continuous-improvement loops
  • Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation
  • Comfortable making and defending pragmatic build-vs-buy decisions
  • Strong experience with relational databases, cloud-based data warehouses, schema design, data migrations, and data lifecycle considerations; experience with event-streaming technologies such as Kafka or Pub/Sub
  • Hands-on experience with public cloud (GCP preferred; AWS/Azure experience also valued) and containers/orchestration (Docker, Kubernetes) at enterprise scale
  • Strong understanding of automated testing — unit, integration, contract, regression, and end-to-end — and a commitment to shipping code with tests
  • Strong understanding of observability practices and tools for metrics, logging, tracing, alerting, and service-level objectives
  • Hands-on experience integrating backend services with developer workflows (CI/CD, source control, ticketing) at scale
  • Strong understanding of secure software development practices and modern cloud-native architectures
  • Solid understanding of AI/ML and responsible use of AI-assisted and agentic engineering tools
  • Strong cross-functional partnership skills, working closely with security and product engineering teams
  • Effective communication skills for representing work, risks, and tradeoffs to senior leadership and staff engineers
  • Demonstrated curiosity, bias for action, and a builder's mindset

Preferred Qualifications

  • Experience working in cybersecurity, cloud security, or another highly available and risk-sensitive production environment
  • Familiarity with CSPM, CNAPP, IaC scanning, admission control, SSPM, or cloud workload protection tooling and their findings
  • Experience integrating with security analytics, SIEM, SOAR, detection, or response platforms
  • Experience with policy-as-code (e.g., Rego) and infrastructure as code (Terraform and equivalent)

Schedule

This position operates as a Hybrid/Flex for Your Day work arrangement based on Target's needs. The role requires onsite work at Target HQ in Minnesota and virtual work, depending on role, team, and task requirements.

Similar jobs