Target's leadership truly empowers personal and professional growth, fostering an environment where we care, grow and win together.
Job Id: R0000448693
The pay range is $132,000.00 - $238,000.00
Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.
About Us:
Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here. Target is one of the world's most recognized brands and one of America's leading retailers. But behind the brand our guests love, is a culture of continual innovation and right now, we are up to big things! Target's security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are too – that's why we work here. Join our team to improve Target's security and move the business forward.
As a Lead Engineer on the Cloud Security team, you'll be the senior software engineer building and owning the services that turn Target's cloud security signal into action. Cloud Security at Target is one team with two engineering disciplines — platform engineers who deploy, tune, and operate the cloud security controls (CSPM/CNAPP, IaC scanning, admission control, SSPM, workload protection), and software engineers who build the services that aggregate, attribute, enrich, and distribute the findings those controls produce, plus the broader backend that the team's capabilities depend on. You will lead the software engineering side of that partnership.
Beyond deep technical expertise, you have a strong bias for action and a builder's mindset. The team's software sits between the controls that produce findings and the product and platform engineers who have to act on them, and you are comfortable operating in that realm – translating security requirements into reliable, well-tested backend services; owning the day-to-day operation and continuous improvement of the findings pipeline and adjacent services; coordinating APIs, data contracts, and developer-experience tradeoffs with the platform engineers on your team and with the consumers of your services; and partnering with peers so cloud security findings flow into the enterprise remediation lifecycle. You have the engineering credibility to set technical direction for other software engineers on the team and the communication and partnership skills to make the services land well across Target.
Expect to:
• Serve as the senior software engineering lead and hands-on owner of the Cloud Security team's software portfolio — setting the technical direction, standards, and roadmap that other software engineers execute against.
• Lead the design, development, and operation of the findings pipeline: services that ingest cloud security signal from CSPM/CNAPP, IaC scanning, admission control, SSPM, and workload protection; deduplicate and normalize it; enrich it with ownership attribution and business context; and route it to Target's enterprise remediation dashboards with SLAs so product and platform teams can act.
• Design and build scalable backend services in Kotlin, Java, and Spring Boot — event-driven where it fits, request/response where it doesn't — with clean APIs, clear data contracts, and the observability needed to run them well in production.
• Own the ownership-attribution problem end-to-end: the data model, the sources of truth, the reconciliation logic, and the feedback loops that keep attribution accurate as Target's cloud footprint evolves.
• Own the noise-reduction problem end-to-end on the software side: deduplication, correlation across sources, suppression logic, and enrichment — so every finding that reaches an engineer is worth their time.
• Build the integrations that connect the team's services into Target's enterprise ecosystem: SIEM/SOAR, remediation and governance platforms, ticketing, source control, CI/CD, and internal developer platforms.
• Operate these services as production systems: own their availability, performance, observability, capacity, deploy cadence, and outage response, with clear SLOs and on-call participation.
• Peer closely with the platform engineers on the team who own CSPM/CNAPP, IaC scanning, admission control, and SSPM — you build the software that consumes and acts on what their controls produce, and the API and data contracts between you are a shared design problem.
• Partner with Detection & Response to turn high-signal posture and runtime findings into detections, and to build the software support that cloud incident response needs.
• Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation.
• Make pragmatic build-vs-buy calls on the software side, and own the technical side of the lifecycle of the libraries, frameworks, and third-party components the team's services depend on.
• Treat the team's software portfolio as a product: invest in automation, self-service, and platform thinking so coverage and remediation scale with Target's cloud footprint.
• Continuously reduce toil for both the team and Target's engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback for developers.
• Own the developer experience of the team's APIs and services: clean contracts, clear error messages, documented usage patterns, and a tight feedback loop with the engineers who consume them.
• Establish engineering patterns and standards for the team's software — APIs, event streams, data models, automated testing, observability, resiliency, secure service development, and CI/CD — and raise the bar on all of them.
• Guide database schema evolution, data migrations, cloud-based data warehouse design, API versioning, and backward-compatible platform changes so the team can move fast without breaking its consumers.
• Represent the team's software work clearly to senior leadership and to staff engineers alike: roadmap, risk reduction, operational health, and tradeoffs — in language tuned to the audience.
• Mentor other software engineers on the team on backend engineering, distributed systems, and cloud security software practices, and raise the bar for code quality, testing, code review, on-call hygiene, postmortems, and operational excellence.
• Evaluate emerging technologies, including AI-assisted and agentic engineering tools, and apply them responsibly to improve engineering quality and delivery.
Core responsibilities are described within this job description. Job duties may change at any time due to business needs.
About You:
• 4-year degree in Computer Science, Engineering, or a related field, OR equivalent work experience
• 7+ years of software engineering experience, with a strong track record of leading the design and delivery of complex, platform-oriented backend systems
• Deep hands-on experience with Kotlin, Java, and Spring Boot, and strong fluency in at least one additional modern language
• Demonstrated experience as a tech lead owning a software capability end-to-end at enterprise scale, including setting technical direction that other engineers execute against
• Deep experience designing, building, and operating distributed, event-driven, and data-intensive backend services in production
• Strong experience designing RESTful APIs, service-to-service integrations, and event streams that other teams depend on
• Experience building and operating findings, event, or telemetry pipelines that aggregate signal from multiple sources, deduplicate and enrich it, and route it to downstream systems with SLAs
• Strong opinions, backed by experience, on how to keep signal-to-noise high in a findings or alert pipeline: deduplication, correlation, suppression discipline, ownership attribution, and SLA-based remediation
• Track record of running production services with clear SLOs, on-call coverage, change management, and continuous-improvement loops
• Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation — and delivering predictably against them
• Comfortable making and defending pragmatic build-vs-buy decisions, and knowing when to invest in custom engineering vs. lean on an existing capability
• Strong experience with relational databases, cloud-based data warehouses, schema design, data migrations, and data lifecycle considerations; experience with event-streaming technologies such as Kafka or Pub/Sub
• Hands-on experience with public cloud (GCP preferred; AWS/Azure experience also valued) and with containers and orchestration (Docker, Kubernetes) at enterprise scale
• Strong understanding of automated testing — unit, integration, contract, regression, and end-to-end — and a demonstrated commitment to shipping code with tests, not around them
• Strong understanding of observability practices and tools for metrics, logging, tracing, alerting, and service-level objectives
• Hands-on experience integrating backend services with developer workflows (CI/CD, source control, ticketing) in a way that scales with a large engineering organization
• Strong understanding of secure software development practices and modern cloud-native architectures
• Solid understanding of AI/ML and the emerging engineering considerations associated with it, including the responsible use of AI-assisted and agentic engineering tools such as Claude Code, OpenCode, or Codex
• Strong cross-functional partner: comfortable working closely with a variety of security and product engineering teams to align requirements, rollout plans, and operational ownership
• Effective at representing your work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail
• Excellent written and verbal communication skills with strong presentation abilities
• Demonstrated curiosity, bias for action, and a genuine builder's mindset — you want to ship the services, not just describe them
Preferred Qualifications:
• Experience working in cybersecurity, cloud security, or another highly available and risk-sensitive production environment
• Familiarity with CSPM, CNAPP, IaC scanning, admission control, SSPM, or cloud workload protection tooling and the shape of the findings they produce
• Experience integrating with security analytics, SIEM, SOAR, detection, or response platforms
• Experience with policy-as-code (e.g., Rego) and infrastructure as code (Terraform and equivalent)
This position will operate as a Hybrid/Flex for Your Day work arrangement based on Target's needs. A Hybrid/Flex for Your Day work arrangement means the team member's core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.
Benefits Eligibility
Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_EAmericans with Disabilities Act (ADA)
In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed through this channel.
Target will never ask you to submit personal information via a text message for a position. Target will only ask you to apply for positions through corporate.target.com/careers, or Workday, our applicant tracking system.
We are proud to provide benefits that support you, your family and your future.
We bring out the best in each other every day.
We value diverse voices and approaches. We act with authenticity and respect. We create equitable experiences for all.
We build trusted relationships. We collaborate across business functions. We recognize and celebrate progress.
We do what is right for Target, our team and guests. We deliver results that matter. We continually learn by valuing progress over perfection.
We are fully invested in your personal and professional growth because our people are our power.
Target's leadership truly empowers personal and professional growth, fostering an environment where we care, grow and win together.
Stories of our Target team members in action.
Stay up-to-date with relevant Target opportunities sent right to your inbox.
*All fields required.
By submitting your information, you acknowledge that you have read our Career Privacy Notice and consent to receive email job alerts and other career-related communications from Target.