ForgeApply · Job listing
Lead Engineer - Cloud Security (Cloud Security Platform & CSPM)
Target
See all 516 open roles at Target →
Tailor your resume for this Target job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Target's site. Free trial, no card required.
About this role
The pay range is $132,000.00 - $238,000.00 Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits .
About Us Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here . Target is one of the world's most recognized brands and one of America's leading retailers. But behind the brand our guests love, is a culture of continual innovation and right now, we are up to big things! Target's security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are too – that's why we work here. Join our team to improve Target's security and move the business forward.
As a Lead Engineer on the Cloud Security team, you'll be the senior technical owner of Target's Cloud Security Platform and CSPM capability across our public and private cloud environments. You'll be the person the team, our partners, and leadership look to for how CSPM and the broader CNAPP surface should be designed, deployed, operated, and evolved at Target scale — turning posture signal into action, and controls into paved roads that developers can actually use.
Beyond deep technical expertise, you have a strong bias for action and a builder's mindset. The Cloud Security Platform sits between architecture and the engineering teams who consume it, and you are comfortable operating in that realm – translating security requirements into reliable, automated, developer-friendly controls; owning the day-to-day operation and continuous improvement of the CSPM/CNAPP platform; coordinating exceptions and developer-experience tradeoffs and partnering with peers so that cloud security findings flow into the enterprise remediation lifecycle. You have the engineering credibility to set technical direction for a team of engineers as a hands-on IC, and the communication and partnership skills to make the controls land well across Target.
Expect to: • Serve as the senior technical lead and hands-on owner of Target's Cloud Security Platform and CSPM capability — setting the technical direction, standards, and roadmap that other engineers execute against. • Own the end-to-end engineering, deployment, configuration, tuning, and ongoing operation of the CSPM/CNAPP platform across Target's public and private cloud environments, including onboarding of new cloud accounts, projects, and workloads, leading the implementation and operation of core functional controls, and managing operations such as RBAC and SSO. • Operate the platform as a production system: own its availability, performance, observability, capacity, upgrade cadence, and outage response, with clear SLOs and on-call participation. • Own the CSPM policy set end-to-end: which rules are on, which are tuned, which are suppressed and why — grounded in Target's reference architecture, secure configuration benchmarks, and the realities of our environment. • Peer with Cloud Security software developers on design of the findings pipeline for CSPM and adjacent CNAPP signal. The pipeline will aggregate posture findings, deduplicate and enrich them with ownership attribution, and ship them into Target's enterprise remediation dashboards with SLAs so product and platform teams can act. • Drive continuous reduction of noise and false positives so every finding that reaches an engineer is worth their time. • Extend ownership into adjacent CNAPP capabilities delivered by the same platform — cloud workload posture, container/image posture, cloud identity/entitlement (CIEM) findings, and IaC posture signal — coordinating with the engineers who own the deeper IaC scanning, admission control, and SSPM controls. • Partner with Detection & Response to turn high-signal posture and runtime findings into detections, and to support cloud incident response with the context the platform can provide. • Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation. • Make pragmatic build-vs-buy calls within the platform's ecosystem, and own the technical side of the tool's lifecycle: evaluations/POCs, capability adoption, integration work, and input into vendor and contract discussions. • Treat the Cloud Security Platform as a product: invest in automation, self-service, and platform thinking so CSPM coverage and remediation scale with Target's cloud footprint rather than with headcount. • Continuously reduce toil for both the team and Target's engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback for developers. • Own the developer experience of the platform's findings and controls: clear explanations, documented escape hatches, fast and well-coordinated exception handling, and a tight feedback loop with product engineering. • Drive adoption of the platform's coverage across Target Tech, including onboarding, exception/governance workflows, and developer enablement. • Integrate cloud security telemetry from the platform into Target's enterprise SIEM/SOAR pipelines and remediation/governance systems. • Partn
Salary insight
The midpoint of this range ($185k) is about 13% above the median disclosed salary for New York roles listed on ForgeApply ($164k across 8,907 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Target role before you apply.
Tailor my resume for this jobSimilar jobs
- Lead Engineer - Cloud Security (Software Engineering) — Target · NCD-0375 Brooklyn Park, MN
- Senior Security Engineer (Cloud) — Chainguard · Remote
- Senior Cloud & Security Engineer — Armaninollp (Armanino) · Denver, Colorado | Salt Lake City, Utah | Chicago, Illinois
- Senior Cloud Security Engineer — Vanguard · Malvern, PA | Charlotte, NC | Dallas/Ft. Worth, TX
- Senior Cloud Security Engineer — Rescale · Remote
- Senior Cloud Security Engineer — Trueanomalyinc · Denver, CO or Long Beach, CA or SF Bay Area, CA
- Senior Cloud Security Engineer — Iterable · Remote
- Senior Cloud Security Engineer — Reltio · United States
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)