Target

Sr Engineering Manager – Operational Technology Security

Target Brooklyn Park, Minnesota, United States · $132K–$238K/yr

Retail · 10,001+ employees

19 h ago
engineering-manager Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Lead and develop a team of engineers to build, operate, and scale OT security platforms and data pipelines across Target's infrastructure. Manage end-to-end OT vulnerability, exposure, and secure-configuration assurance while partnering with cross-functional teams to ensure safe remediation.

What they look for

Operational Technology Security Engineering Management Vulnerability Management Asset Visibility Endpoint Security Data Engineering Automation ISA/IEC 62443 Python Go Terraform CI/CD Network Segmentation Incident Response Risk Prioritization Identity and Access Management

Requirements

Requires a 4-year degree or equivalent experience, with at least 8 years in technology and 3 years in engineering management. Candidates must possess deep expertise in OT security, platform operations, and the ability to drive multi-quarter roadmaps in complex environments.

Benefits

Medical Vision Dental Life insurance 401(k) Employee discount Short term disability Long term disability Paid sick leave Paid national holidays Paid vacation

Full description

The pay range is $132,000.00 - $238,000.00

Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.

About us:

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.

Target is one of the world's most recognized brands and one of America's leading retailers. But behind the brand our guests love, is a culture of continual innovation and right now, we are up to big things! Target's security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are too – that's why we work here. Join our team to improve Target's security and move the business forward.

As a Senior Engineering Manager on the Operational Technology (OT) Security team, you'll lead a team of Lead Engineers responsible for standing up, operating, integrating, automating, and scaling OT security capabilities across Target's OT infrastructure. Your team will own the platforms and pipelines that give Target visibility into OT assets, prioritize exposure, harden endpoints and configurations, and route the right findings to the right operational teams for safe, prioritized remediation.  You’ll partner with Infrastructure, Supply Chain, Architecture, and Network Security teams on OT network segmentation, backup and restore, and identity and access initiatives.

Beyond deep technical expertise, you have a strong bias for action and a builder's mindset. You are comfortable translating ISA/IEC 62443-aligned control requirements into implementable engineering patterns; owning the day-to-day operation and continuous improvement of the platforms that surface OT risk; coordinating exceptions, compensating controls, and change windows with partners; and providing white-glove engineering support for the highest-risk findings. You have the engineering credibility to lead a team that builds and operates this platform, and the communication and partnership skills to make the controls land safely in environments where availability, safety, and continuity of product movement matter as much as security.

Expect to:

  • Lead, build, and develop a team of Lead Engineers responsible for the day-to-day implementation and operation of Target's OT security capabilities.
  • Establish good stakeholder communication, work closely with partner teams, and help drive requirements while being a strong advocate of safe, efficient, and secure engineering practices in OT environments.
  • Build and manage a team of high performing engineers and provide leadership, coaching, motivation and recommend staffing levels, operating procedures, tools, and systems for the team.
  • Provide career development and performance management to a team of engineers.
  • Set the engineering culture and bar for the team — code quality, testing, review, on-call hygiene, postmortems, change safety, and operational excellence in environments where downtime has direct business impact.
  • Own the end-to-end engineering, deployment, configuration, and ongoing operation of Target's OT security platforms — including OT asset visibility and exposure platforms and the data pipelines that move OT signal into enterprise systems.
  • Operate these platforms as production systems: own their availability, performance, observability, coverage, data quality, upgrade cadence, and incident response, with clear service objectives and on-call coverage.
  • Own OT vulnerability and exposure management: intake, normalization, correlation, deduplication, enrichment, and risk prioritization of OT findings — using operational consequence, asset criticality, exploitability, exposure, compensating controls, vendor supportability, and maintenance windows rather than CVSS alone.
  • Own secure-configuration assurance for in-scope OT: develop hardening patterns, use OT security platforms and other available evidence to identify deviations, prioritize gaps, and validate remediation.
  • Own the endpoint security workstream for OT: eligibility, compatibility testing, pilots, deployment, health monitoring, rollback, exception handling, and compensating-control recommendations.
  • Provide white-glove engineering support for the highest-risk OT findings, while equipping OT Infrastructure, site teams, system owners, and vendors to execute most changes through their normal operational processes.
  • Own the OT security data pipeline: APIs, connectors, schemas, transformation, enrichment, reconciliation, routing, and monitoring that move OT Security platform data and related signal into the appropriate enterprise dashboards, ticketing systems, and remediation workflows with clear ownership attribution and SLAs.
  • Partner with Network Security on OT network segmentation and with IAM / Vendor Risk  on vendor-access controls.  Provide asset, traffic-flow, exposure, and operational-context data to inform engineering. 
  • Translate ISA/IEC 62443-aligned requirements into a prioritized engineering roadmap, and deliver against it predictably.
  • Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation.
  • Make pragmatic build-vs-buy decisions and own the lifecycle of the OT security tools the team operates: vendor relationship, evaluations/POCs, contract input, capability adoption, and sunsetting.
  • Drive adoption of the team's controls across in-scope OT environments, including onboarding, exception/governance workflows, and enablement of OT Infrastructure and site teams.
  • Treat the OT security control plane as a product: invest in automation, self-service, and platform thinking so controls scale with Target's OT footprint.
  • Continuously reduce toil for both your team and Target's OT engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback into the remediation lifecycle.
  • Provide security engineering consultation on new or materially changed in-scope OT solutions — including product/vendor evaluations, design reviews, endpoint compatibility assessments, hardening requirements, vulnerability-management expectations, telemetry requirements, and integration planning.
  • Represent the team's work clearly to senior leadership: roadmap, risk reduction, operational health, and tradeoffs — in language tuned to the audience.

Core responsibilities are described within this job description. Job duties may change at any time due to business needs.

About you:

  • 4-year degree OR equivalent work experience
  • 8+ years of hands-on experience in technology, with deep experience in OT and security engineering and the adjacent disciplines that make OT security work — asset visibility, vulnerability and exposure management, endpoint security, data engineering/automation, and integration with enterprise remediation and governance workflows
  • 3+ years managing engineering teams with a strong track record of delivery in a platform, infrastructure, software development, or security engineering in an OT context
  • Experience hiring, growing, and retaining senior engineering talent, and building or evolving team operating models
  • You lead engineers, not just programs: you've owned the full stack of engineering management — hiring, performance, career growth, on-call culture, code review standards, postmortems, and operational excellence
  • Demonstrated track record of running production platforms with clear service objectives, on-call coverage, change management, and continuous-improvement loops in environments where availability, safety, and continuity of operations are non-negotiable
  • Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation — and delivering predictably against them
  • Comfortable making and defending pragmatic build-vs-buy decisions, owning vendor relationships and tool lifecycles, and knowing when to invest in custom engineering vs. lean on a platform
  • Demonstrated experience leading teams that operate OT and/or ICS security platforms at scale — such as Claroty XDome, Nozomi, Dragos, Armis, Tenable OT, or comparable OT asset visibility and exposure platforms
  • Hands-on familiarity with ISA/IEC 62443 (and adjacent frameworks such as NIST CSF, NIST SP 800-82) — enough to align the team's controls to them, without being the policy author
  • Experience deploying and operating endpoint security agents on OT-adjacent or constrained endpoints (e.g. EDR agents), including eligibility, compatibility testing, health monitoring, and exception handling
  • Experience building and operating findings pipelines that integrate security signal into enterprise remediation/governance platforms (e.g., shipping asset, vulnerability, secure-configuration, and endpoint findings to centralized dashboards with ownership attribution and SLAs)
  • Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architecture's requirements
  • Automation-first engineering mindset, with hands-on fluency in at least one general-purpose language (e.g., Python, Go) and a track record of building reusable platforms and paved roads instead of one-off scripts
  • Working knowledge of infrastructure as code (Terraform and equivalent) and CI/CD, and comfort integrating security tooling with modern engineering workflows
  • Strong understanding of distribution-center automation, industrial control systems, or vendor-managed OT environments
  • Experience with, or exposure to, adjacent OT-relevant disciplines — including OT network segmentation, vendor-access controls, and OT backup and recovery
  • Strong cross-functional partner: comfortable working closely with partners across Security Architecture, BISO, Network Security, OT infrastructure, and site teams to align requirements, rollout plans, and operational ownership
  • Effective at representing your team's work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail
  • Good understanding of security management workflows in large enterprise organizations and complex environments, and of the current OT threat landscape and the challenges most organizations are facing
  • Excellent written and verbal communication skills with strong presentation abilities
  • Demonstrated curiosity, bias for action, and a genuine builder's mindset — you want to ship the platform, not just describe it

This position will operate as a Hybrid/Flex for Your Day work arrangement based on Target's needs. A Hybrid/Flex for Your Day work arrangement means the team member's core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.

Benefits Eligibility

Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_E

Americans with Disabilities Act (ADA)

In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed through this channel.

Similar roles