Principal Threat Detection Operations Engineer

Roundel

Brooklyn Park, Northern (MN, KY)

Hybrid

USD 168,000 - 303,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health benefits
401(k)
Employee discount
Disability insurance
Paid holidays
Paid vacation

Job summary

Target is seeking a Principal Threat Detection Operations Engineer in Brooklyn Park, MN to lead the technical strategy for detection engineering across enterprise environments. You will design, develop, and operationalize scalable detection capabilities, guiding teams through CI/CD, threat intelligence integration, and secure production practices.

The role requires deep expertise in Python, SIEM, EDR, cloud security, and analytics, with a focus on reducing analyst workload while increasing

Qualifications

  • 10+ years of experience in cybersecurity engineering, detection engineering, threat hunting, security operations, or related services.
  • Advanced Python programming and software engineering skills, including APIs, data structures, testing, code review, source control.
  • Experience with CI/CD, detection-as-code, and DevSecOps practices.
  • Strong hands-on experience with SIEM and security analytics platforms and production-grade detection rules.
  • Familiarity with EDR, SOAR, threat intelligence, identity, cloud security, and network security.
  • Knowledge of telemetry, data strategy, and large-scale security data platforms.

Responsibilities

  • Set and communicate the technical vision, architecture, and roadmap for detection engineering.
  • Architect scalable detection capabilities across enterprise, cloud, identity, endpoint, network, and application environments.
  • Lead design, development, and lifecycle management of detection content and analytics pipelines.
  • Provide hands-on leadership for complex detection and visibility challenges.
  • Partner with incident responders, threat hunters, threat intelligence, enterprise architecture, and technology teams to translate threat intelligence into detections.
  • Define metrics and feedback loops to measure detection coverage, fidelity, and alert quality.
  • Influence telemetry and security data strategy to support detection capabilities.

Skills

Python
APIs
CI/CD
DevSecOps
SIEM
Security analytics
EDR
Threat intelligence
Cloud security
Kubernetes
Git
PowerShell/Bash
REST APIs
SQL/NoSQL
Security data platforms

Education

4-year degree or equivalent

Tools

Git
Kubernetes
PowerShell

Job description

## Principal Threat Detection Operations EngineerApply: 7000 Target Pkwy N,NCD-0375 Brooklyn Park,MN 55445: Full time: Posted Today: R0000453336The pay range is $168,000.00 - $303,000.00Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.About us:Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.As a **Principal Engineer supporting Threat Detection Operations,** you set the technical strategy for the detection engineering, platforms, services, integrations, and automations that enable Target to detect cyber threats. You set direction for how these capabilities are designed, developed, tested, deployed, and operationalized across multiple portfolios and drive adoption across Target. You lead and approve engineering efforts to meet functional and non-functional requirements, including security, reliability, scalability, availability, performance, and maintainability.This role combines principal-level engineering leadership with deep detection engineering expertise. You are expected to design, develop, and continuously improve scalable detection capabilities that identify sophisticated threats across complex environments, while applying strong investigative judgment to ensure detections are actionable, resilient, and aligned to evolving adversary behaviors. You translate threat intelligence, incident learnings, and emerging attack techniques into durable detection strategies, engineering solutions, and process improvements. You are a thought leader and mentor for detection engineers and partner teams and actively contribute to the broader cybersecurity team and tech organization.Use your skills, experience, and talents to be a part of groundbreaking thinking and visionary goals. As a Principal Engineer, Threat Detection Operations, you will take the lead as you...* Set and communicate the technical vision, architecture, and roadmap for detection engineering, aligning threat detection capabilities with Target's cybersecurity priorities, business risks, threat landscape, and technical environments.* Architect and lead the development of scalable, reliable detection capabilities, services, integrations, and automations using Python, APIs, detection-as-code practices, event-driven patterns, and cloud-native technologies to identify malicious and anomalous activity across enterprise, cloud, identity, endpoint, network, and application environments.* Establish and drive engineering standards for detection content, source control, peer review, automated testing, CI/CD, release management, observability, documentation, versioning, access controls, and resilient production operations.* Lead the design, development, and lifecycle management of enterprise detection capabilities, including detection rules, behavioral analytics, correlation logic, detection pipelines, enrichment, alerting workflows, and analyst-facing tooling.* Provide hands-on, principal-level leadership for complex detection and visibility challenges. Guide detection logic development, testing, tuning, validation, deployment, and continuous improvement to maximize detection effectiveness while reducing analyst workload.* Partner with incident responders, threat hunters, threat intelligence, enterprise architecture, and technology teams to translate threat intelligence, adversary behaviors, investigative findings, and emerging risks into scalable and durable detection capabilities.* Assess the viability, applicability, security, maintainability, and cost implications of detection technologies and technical solutions through proofs of concept, prototypes, architecture reviews, vendor evaluations, and build-versus-buy decisions.* Define metrics and feedback loops that measure detection coverage, fidelity, precision, reliability, time to detect, alert quality, operational performance, and analyst expertise; use the results to identify detection gaps and drive continuous improvement.* Influence telemetry and security data strategy by defining requirements for data quality, normalization, enrichment, retention, availability, and observability necessary to support effective and resilient detection capabilities.* Work with engineering and cybersecurity leaders to build a high-performing team, provide technical leadership and coaching, mentor engineers and analysts, and participate in the selection and development of technical talent.Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs.**About you:*** 4-year degree or equivalent experience. Continuing education to maintain thorough knowledge of technical and cybersecurity domains while staying current with relevant technologies and threats.* 10+ years of experience in cybersecurity engineering, detection engineering, threat hunting, security operations, security analytics, or related services, including demonstrated ability to independently design, develop, validate, and improve detection capabilities in complex enterprise environments.* Advanced Python programming and software engineering skills, including APIs, data structures, testing, code review, source control, packaging, error handling, and maintainable documentation.* Demonstrated experience designing, developing, testing, deploying, and operating detection content and supporting services through modern CI/CD, detection-as-code, and DevSecOps practices, including automated testing, secure deployment, monitoring, rollback, versioning, and change governance.* Strong hands-on experience SIEM and security analytics platforms and the development of production-grade detection rules, correlation logic, behavioral analytics, enrichment, and alerting workflows. Familiarity with adjacent technologies such as EDR, SOAR, threat intelligence, identity, cloud security, network security, case management, and malware analysis.* Deep knowledge of detection engineering principles and the ability to analyze endpoint, network, identity, cloud, application, and other security telemetry; understand adversary techniques and behaviors; identify detection opportunities and gaps; and develop high-fidelity detections that are effective, explainable, and operationally sustainable.* Strong understanding of secure systems design and operations, including authentication and authorization, secrets management, logging and telemetry, data handling, resilience, failure recovery, and reliable production operations.* Demonstrated success solving complex technical problems across more than one technical or functional area. Experience with REST APIs, SQL/NoSQL data stores, Git, PowerShell or Bash, containers/Kubernetes, cloud technologies, and large-scale security data platforms.* Understands business fundamentals and how technology can support business goals, translate business and cyber risk into technical strategy, and evaluate financial and operational implications.* Proven leadership capabilities, influence, interpersonal skills, sound judgment, and calm decision-making in time-sensitive situations. Excellent verbal, written, and presentation skills to communicate complex technical and investigative findings clearly to technical teams, cybersecurity leaders, and business stakeholders.* Strong team player with excellent planning and organizational skills and a demonstrated commitment to teamwork and team effectiveness.This position will operate as a **Hybrid**/Flex for Your Day work arrangement based on Target’s needs. A **Hybrid**/Flex for Your Day work arrangement means the team member’s core role will need to be performed both **onsite at the Target HQ MN location** the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Threat Detection Operations Engineer
Principal Threat Detection Operations Engineer

Target • Brooklyn Park (MN)

Hybrid
USD 168,000 - 303,000
Senior Engineer: Threat Detection Engineering (Hybrid)
Senior Engineer: Threat Detection Engineering (Hybrid)

Roundel • Brooklyn Park (MN), Northern (KY)

Hybrid
USD 98,000 - 176,000
Health benefits
401(k)
Employee discounts
+1
Lead Engineer Cyber AI - AI Expert
Lead Engineer Cyber AI - AI Expert

Roundel • Brooklyn Park (MN)

On-site
USD 132,000 - 238,000
Comprehensive health benefits
401(k)
Employee discount
+2
Lead Engineer - AI Security (Hybrid)
Lead Engineer - AI Security (Hybrid)

Roundel • Brooklyn Park (MN), Northern (KY)

Hybrid
USD 132,000 - 238,000
Health benefits
401(k) matching
Paid time off
+1
Lead Security Engineer – Proactive Security
Lead Security Engineer – Proactive Security

Roundel • Brooklyn Park (MN)

On-site
USD 132,000 - 238,000
Comprehensive health benefits
401(k) plan
Employee discount
+1
Lead Engineer - Email and Data Protection (Cybersecurity)
Lead Engineer - Email and Data Protection (Cybersecurity)

Roundel • Brooklyn Park (MN)

Hybrid
USD 132,000 - 238,000
Health benefits
401(k)
Employee discount
+2
Engineer - Email and Data Protection (Cybersecurity)
Engineer - Email and Data Protection (Cybersecurity)

Roundel • Brooklyn Park (MN)

On-site
USD 75,000 - 136,000
Health benefits
401(k)
Paid time off
+1
Senior Engineer - Threat Detection Engineering
Senior Engineer - Threat Detection Engineering

Roundel • Brooklyn Park (MN)

On-site
USD 98,000 - 176,000
Comprehensive health benefits
401(k)
Employee discount
+2
Sr Engineer - Incident Response Engineering
Sr Engineer - Incident Response Engineering

Roundel • Brooklyn Park (MN)

Hybrid
USD 98,000 - 176,000
Comprehensive health benefits
Employee discount
401(k) plan
+1
Lead Engineer - Cloud Security (Cloud Security Platform & CSPM)
Lead Engineer - Cloud Security (Cloud Security Platform & CSPM)

Roundel • Brooklyn Park (MN)

Hybrid
USD 132,000 - 238,000
Health benefits
401(k)
Employee discount
+1