ForgeApply
Try it free

ForgeApply · Job listing

Principal Engineer - Cybersecurity Incident Response

Target

NCD-0375 Brooklyn Park, MN, US$168k – $303konsite

See all 379 open roles at Target

Tailor your resume for this Target job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Target's site. Free trial, no card required.

About this role

The pay range is $168,000.00 - $303,000.00 Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits .

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

As a Principal Engineer supporting Cybersecurity Incident Response, you set the technical strategy for the engineering platforms, services, integrations, and automations that enable Target to investigate and respond to cyber threats. You set direction for how these capabilities are designed, developed, tested, deployed, and operationalized across multiple portfolios and drive adoption across TTS. You lead and approve engineering efforts to meet functional and non-functional requirements, including security, reliability, scalability, availability, performance, and maintainability.

This role combines principal-level engineering leadership with deep incident response expertise. You are expected to contribute directly during active investigations with the judgment and hands-on capability of a principal incident response analyst, while translating investigative needs and lessons learned into durable technology and process improvements. You are a thought leader and mentor for engineers and incident responders and actively contribute to the broader cybersecurity and technical community.

Use your skills, experience and talents to be a part of groundbreaking thinking and visionary goals. As a Principal Engineer, Cybersecurity Incident Response, you will take the lead as you... • Set and communicate the technical vision, architecture, and roadmap for incident response engineering, aligning security operations needs with Target's business and technical environments. • Architect and lead the development of secure, reliable services, integrations, and automations using Python, APIs, event-driven patterns, and cloud-native technologies to accelerate triage, enrichment, evidence collection, analysis, containment, and recovery. • Establish and drive engineering standards for source control, peer review, automated testing, CI/CD, release management, observability, documentation, secrets management, access controls, and resilient operations. • Lead the design, development, and lifecycle management of security operations (SecOps) and security orchestration, automation, and response (SOAR) capabilities, including production-grade playbooks, integrations, case-management workflows, data enrichment, and analyst-facing tools. • Provide hands-on, principal analyst-level incident commander support by leading complex or high-severity cyber investigations. Guide triage, hypothesis development, data collection, scoping, evidence analysis, timeline reconstruction, containment decisions, eradication, recovery, and clear documentation of findings and risk. • Partner with incident responders, threat hunters, detection engineers, digital forensics, threat intelligence, Enterprise Architecture, and technology teams to convert investigative requirements and post-incident findings into scalable capabilities. • Assess the viability, applicability, security, maintainability, and cost implications of technical solutions through proofs of concept, prototypes, architecture reviews, vendor evaluations, and build-versus-buy decisions. • Define metrics and feedback loops that measure automation quality, platform reliability, investigative cycle time, analyst experience, and operational outcomes; use the results to drive continuous improvement. • Work with engineering and cybersecurity leaders to build a high-performing team, provide technical leadership and coaching, mentor engineers and analysts, and participate in the selection and development of technical talent. • Architect, engineer, and operationalize scalable live-response and forensic artifact collection solutions that enable secure, reliable acquisition of volatile and persistent evidence across endpoint, cloud, identity, network, and container environments, with built-in automation, evidence-integrity controls, observability, and integrations with investigative and SOAR workflows. • Design, develop, and operationalize agentic AI–powered analysis tooling that integrates with SecOps, SIEM, SOAR, and case-management platforms to correlate telemetry and forensic evidence, automate repetitive investigative tasks, generate defensible findings, and recommend next investigative actions with appropriate human oversight and security controls.

Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs.

About you: • 4-year degree or equivalent experience. Continuing education to maintain thorough knowledge of technical and cybersecurity domains while staying current with relevant technologies and threats. • 10+ years of experience in technology development, cybersecurity engineering, security operations, or related services. • 10+ years of hands-on cybersecurity incident response experience, including demonstrated ability to independently lead and support active enterprise investigations. • Advanced Python programming and software engineering skills, including AP

Salary insight

The midpoint of this range ($236k) is about 47% above the median disclosed salary for New York roles listed on ForgeApply ($160k across 10,208 jobs).

See full Security Engineer salary data for New York

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Target role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)