Director of Engineering - Cloud Security

TargetBrooklyn Park, NC
Hybrid

About The Position

As an Engineering Director on the Cloud Security team, you'll lead a team of engineers responsible for deploying, operating, automating, and scaling cloud security capabilities across Target's public and private cloud environments. Your team is responsible for turning requirements into running, scaled, and continuously improving controls – including CSPM, IaC scanning, Kubernetes admission control, SSPM, secure configuration management, cloud workload protection, and the integration of cloud security findings into Target's enterprise remediation and governance processes. Beyond deep technical expertise, you have a strong bias for action and a builder's mindset. Cloud Security sits between architecture and the engineering teams who consume it, and you are comfortable operating in that realm – translating security requirements into reliable, automated, developer-friendly controls; owning the day-to-day operation and continuous improvement of the platforms that enforce them; coordinating exceptions and developer-experience tradeoffs with BISO, Security Architecture, and product engineering; and partnering with Detection & Response, Vulnerability Management, and the broader Cloud Platform organization so that cloud security findings flow into the enterprise remediation lifecycle. You have the engineering credibility to lead engineers who build and operate this platform, and the communication and partnership skills to make the controls land well across Target.

Requirements

  • 4-year degree OR equivalent work experience
  • 10+ years of hands-on experience in technology, with deep experience in cloud security and the adjacent disciplines that make it work — cloud platform engineering, Kubernetes, IaC /CI-CD, automation, identity, and detection/response integration
  • 4+ years managing engineering teams with a strong track record of delivery in a platform, infrastructure, software development, or security engineering context
  • Experience hiring, growing, and retaining senior engineering talent, and building team operating models from the ground up
  • You lead engineers, not just programs: you've owned the full stack of engineering management — hiring, performance, career growth, on-call culture, code review standards, postmortems, and operational excellence
  • Demonstrated track record of running production platforms with clear SLOs, on-call coverage, change management, and continuous-improvement loops
  • Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation — and delivering predictably against them
  • Comfortable making and defending pragmatic build-vs-buy decisions, owning vendor relationships and tool lifecycles, and knowing when to invest in custom engineering vs. lean on a platform
  • Demonstrated experience leading teams that operate cloud security platforms at scale — CSPM, IaC scanning, SSPM, Security Configuration Management, and cloud workload protection
  • Hands-on experience with public cloud (GCP preferred ; AWS/Azure experience also valued) and private cloud / Kubernetes environments at enterprise scale
  • Expertise in Kubernetes and admission controller frameworks, including the rollout patterns required to move from detect to enforce without breaking developers
  • Strong working knowledge of infrastructure as code (Terraform and equivalent) and policy-as-code (e.g., Rego), and experience integrating policy enforcement into CI/CD
  • Experience building and operating findings pipelines that integrate cloud security signal into enterprise remediation/governance platforms (e.g., shipping CSPM, IaC, admission controller, and SSPM findings to a centralized dashboards with ownership attribution & SLAs)
  • Experience integrating cloud telemetry into enterprise SIEM/SOAR pipelines
  • Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architecture's requirements
  • Hands-on experience integrating security tooling with developer workflows (CI/CD, source control, ticketing, IDP/internal developer platforms) in a way that scales with a large engineering organization
  • Strong understanding of secure software development practices, network security fundamentals, and modern cloud-native architectures
  • Solid understanding of AI/ML and the emerging security considerations associated with it, including how to enforce them through cloud security tooling
  • Automation-first engineering mindset, with hands-on fluency in at least one general-purpose language (e.g., Python, Go) and a track record of building reusable platforms and paved roads instead of one-off scripts
  • Strong cross-functional partner: comfortable working closely with security architecture, cloud platform, identity, network, data security, detection & response, vulnerability management, BISO, and product engineering teams to align requirements, rollout plans, and operational ownership
  • Effective at representing your team's work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail
  • Good understanding of security management workflows in large enterprise organizations and complex environments, and of the current threat landscape and the challenges most organizations are facing
  • Working knowledge of security frameworks, standards, and best practices (e.g., NIST, CIS Benchmarks, ISO/IEC 27001) — enough to align the team's controls to them, without being the policy author
  • Excellent written and verbal communication skills with strong presentation abilities
  • Demonstrated curiosity, bias for action, and a genuine builder's mindset — you want to ship the platform, not just describe it

Responsibilities

  • Lead, build, and develop a team of cloud security platform, automation, and governance engineers responsible for the day-to-day implementation and operation of Target's cloud security controls.
  • Establish good stakeholder communication, work closely with partner teams, and help drive requirements while being a strong advocate of efficient and secure engineering practices.
  • Build and manage a team of high performing engineers and provide leadership, coaching, motivation and recommend staffing levels, operating procedures, tools, and systems for the team.
  • Provide career development and performance management to a team of engineers.
  • Set the engineering culture and bar for the team — code quality, testing, code review, on-call hygiene, postmortems, and operational excellence.
  • Own the end-to-end engineering, deployment, configuration, and ongoing operation of Target's cloud security platforms — including CSPM, IaC scanning, Kubernetes admission control, SSPM, secure config management, and cloud workload protection — across Target's public and private cloud environments.
  • Operate these platforms as production systems: own their availability, performance, observability, capacity, upgrade cadence, and outage response, with clear SLOs and on-call coverage.
  • Own the implementation of IaC scanning policies in CI/CD pipelines, turning architectural requirements (e.g., Rego policy) into reliable, developer-friendly guardrails that fail fast and explain why.
  • Implement and operate Kubernetes admission controller policies across the private and public cloud fleet, and own the rollout strategy that gets to enforcement without breaking developers.
  • Build and operate the capabilities that support cloud incident response in partnership with Detection & Response.
  • Translate policy requirements into a prioritized engineering roadmap, and deliver against it predictably.
  • Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation.
  • Make pragmatic build-vs-buy decisions and own the lifecycle of the cloud security tools the team operates: vendor relationship, evaluations/POCs, contract input, capability adoption, and sunsetting.
  • Drive adoption of the team's controls across Target Tech, including onboarding, exception/governance workflows, and developer enablement.
  • Treat the cloud security control plane as a product: invest in automation, self-service, and platform thinking so controls scale with Target's cloud footprint.
  • Continuously reduce toil for both your team and Target's engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback in CI/CD.
  • Own the developer experience of the team's controls: clear error messages, documented escape hatches, fast and well-coordinated exception handling, and a tight feedback loop with product engineering.
  • Own the findings pipeline: aggregate signal from config hardening, CSPM, IaC and admission controller exceptions, and SSPM, and ship it into Target's enterprise remediation dashboards with SLAs so product and platform teams can act.
  • Partner with the broader Cloud Platform organization, Identity Security, Network Security, Data Security, Detection & Response, Vulnerability Management, BISO, and product engineering to align on requirements, rollout plans, and operational ownership.
  • Represent the team's work clearly to senior leadership: roadmap, risk reduction, operational health, and tradeoffs — in language tuned to the audience.

Benefits

  • comprehensive health benefits and programs
  • medical
  • vision
  • dental
  • life insurance
  • 401(k)
  • employee discount
  • short term disability
  • long term disability
  • paid sick leave
  • paid national holidays
  • paid vacation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service