Director of Engineering - Cloud Security

Target · 7000 Target Pkwy N,NCD-0375 Brooklyn Park,MN 55445

The pay range is $168,000.00 - $303,000.00

Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.

About Us:

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here. Target is one of the world’s most recognized brands and one of America’s leading retailers. But behind the brand our guests love, is a culture of continual innovation and right now, we are up to big things! Target’s security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are too – that’s why we work here. Join our team to improve Target’s security and move the business forward. 

 

As an Engineering Director on the Cloud Security team, you'll lead a team of engineers responsible for deploying, operating, automating, and scaling cloud security capabilities across Target's public and private cloud environments. Your team is responsible for turning requirements into running, scaled, and continuously improving controls – including CSPM, IaC scanning, Kubernetes admission control, SSPM, secure configuration management, cloud workload protection, and the integration of cloud security findings into Target's enterprise remediation and governance processes. 

 

Beyond deep technical expertise, you have a strong bias for action and a builder's mindset Cloud Security sits between architecture and the engineering teams who consume it, and you are comfortable operating in that realm – translating security requirements into reliable, automated, developer-friendly controls; owning the day-to-day operation and continuous improvement of the platforms that enforce them; coordinating exceptions and developer-experience tradeoffs with BISO, Security Architecture, and product engineering; and partnering with Detection & Response, Vulnerability Management, and the broader Cloud Platform organization so that cloud security findings flow into the enterprise remediation lifecycle. You have the engineering credibility to lead engineers who build and operate this platform, and the communication and partnership skills to make the controls land well across Target. 

 

Expect to: 

 Lead, build, and develop a team of cloud security platform, automation, and governance engineers responsible for the day-to-day implementation and operation of Target's cloud security controls. 

 Establish good stakeholder communication, work closely with partner teams, and help drive requirements while being a strong advocate of efficient and secure engineering practices. 

 Build and manage a team of high performing engineers and provide leadership, coaching, motivation and recommend staffing levels, operating procedures, tools, and systems for the team. 

 Provide career development and performance management to a team of engineers. 

 Set the engineering culture and bar for the team — code quality, testing, code review, on-call hygiene, postmortems, and operational excellence. 

 Own the end-to-end engineering, deployment, configuration, and ongoing operation of Target's cloud security platforms — including CSPM, IaC scanning, Kubernetes admission control, SSPM, secure config management, and cloud workload protection — across Target's public and private cloud environments. 

 Operate these platforms as production systems: own their availability, performance, observability, capacity, upgrade cadence, and outage response, with clear SLOs and on-call coverage. 

 Own the implementation of IaC scanning policies in CI/CD pipelines, turning architectural requirements (e.g., Rego policy) into reliable, developer-friendly guardrails that fail fast and explain why. 

 Implement and operate Kubernetes admission controller policies across the private and public cloud fleet, and own the rollout strategy that gets to enforcement without breaking developers. 

 Build and operate the capabilities that support cloud incident response in partnership with Detection & Response. 

 Translate policy requirements into a prioritized engineering roadmap, and deliver against it predictably. 

 Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation. 

 Make pragmatic build-vs-buy decisions and own the lifecycle of the cloud security tools the team operates: vendor relationship, evaluations/POCs, contract input, capability adoption, and sunsetting. 

 Drive adoption of the team's controls across Target Tech, including onboarding, exception/governance workflows, and developer enablement. 

 Treat the cloud security control plane as a product: invest in automation, self-service, and platform thinking so controls scale with Target's cloud footprint. 

 Continuously reduce toil for both your team and Target's engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback in CI/CD. 

 Own the developer experience of the team's controls: clear error messages, documented escape hatches, fast and well-coordinated exception handling, and a tight feedback loop with product engineering. 

 Own the findings pipeline: aggregate signal from config hardening, CSPM, IaC and admission controller exceptions, and SSPM, and ship it into Target's enterprise remediation dashboards with SLAs so product and platform teams can act. 

 Partner with the broader Cloud Platform organization, Identity Security, Network Security, Data Security, Detection & Response, Vulnerability Management, BISO, and product engineering to align on requirements, rollout plans, and operational ownership. 

 Represent the team's work clearly to senior leadership: roadmap, risk reduction, operational health, and tradeoffs — in language tuned to the audience. 

Core responsibilities are described within this job description. Job duties may change at any time due to business needs.

 

About You: 

 4-year degree OR equivalent work experience 

 10+ years of hands-on experience in technology, with deep experience in cloud security and the adjacent disciplines that make it work — cloud platform engineering, Kubernetes, IaC/CI-CD, automation, identity, and detection/response integration 

 4+ years managing engineering teams with a strong track record of delivery in a platform, infrastructure, software development, or security engineering context 

 Experience hiring, growing, and retaining senior engineering talent, and building team operating models from the ground up 

 You lead engineers, not just programs: you've owned the full stack of engineering management — hiring, performance, career growth, on-call culture, code review standards, postmortems, and operational excellence 

 Demonstrated track record of running production platforms with clear SLOs, on-call coverage, change management, and continuous-improvement loops 

 Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation — and delivering predictably against them 

 Comfortable making and defending pragmatic build-vs-buy decisions, owning vendor relationships and tool lifecycles, and knowing when to invest in custom engineering vs. lean on a platform 

 Demonstrated experience leading teams that operate cloud security platforms at scale — CSPM, IaC scanning, SSPM, Security Configuration Management, and cloud workload protection 

 Hands-on experience with public cloud (GCP preferred; AWS/Azure experience also valued) and private cloud / Kubernetes environments at enterprise scale 

 Expertise in Kubernetes and admission controller frameworks, including the rollout patterns required to move from detect to enforce without breaking developers 

 Strong working knowledge of infrastructure as code (Terraform and equivalent) and policy-as-code (e.g., Rego), and experience integrating policy enforcement into CI/CD 

 Experience building and operating findings pipelines that integrate cloud security signal into enterprise remediation/governance platforms (e.g., shipping CSPM, IaC, admission controller, and SSPM findings to a centralized dashboards with ownership attribution & SLAs) 

 Experience integrating cloud telemetry into enterprise SIEM/SOAR pipelines 

 Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architecture's requirements 

 Hands-on experience integrating security tooling with developer workflows (CI/CD, source control, ticketing, IDP/internal developer platforms) in a way that scales with a large engineering organization 

 Strong understanding of secure software development practices, network security fundamentals, and modern cloud-native architectures 

 Solid understanding of AI/ML and the emerging security considerations associated with it, including how to enforce them through cloud security tooling 

 Automation-first engineering mindset, with hands-on fluency in at least one general-purpose language (e.g., Python, Go) and a track record of building reusable platforms and paved roads instead of one-off scripts 

 Strong cross-functional partner: comfortable working closely with security architecture, cloud platform, identity, network, data security, detection & response, vulnerability management, BISO, and product engineering teams to align requirements, rollout plans, and operational ownership 

 Effective at representing your team's work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail 

 Good understanding of security management workflows in large enterprise organizations and complex environments, and of the current threat landscape and the challenges most organizations are facing 

 Working knowledge of security frameworks, standards, and best practices (e.g., NIST, CIS Benchmarks, ISO/IEC 27001) — enough to align the team's controls to them, without being the policy author 

 Excellent written and verbal communication skills with strong presentation abilities 

 Demonstrated curiosity, bias for action, and a genuine builder's mindset — you want to ship the platform, not just describe it 

This position will operate as a Hybrid/Flex for Your Day work arrangement based on Target’s needs. A Hybrid/Flex for Your Day work arrangement means the team member’s core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota. 

Benefits Eligibility

Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_F

Americans with Disabilities Act (ADA)

In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to [email protected]. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed through this channel.  

Eng Management pay context

Based on 734 disclosed Eng Management salaries on RoleSuite, the role pays a median of $216K/year, with most offers between $178K and $254K (10th–90th percentile: $157K–$314K).

This posting lists $168K–$303K, in line with the $216K market median.

See the full Eng Management salary breakdown →
Apply →