Brooklyn Park, Minnesota, USA
5 days ago
Lead Engineer - Threat Hunting and Countermeasures (SOAR)(Remote Or Hybrid)
The pay range is $111,200.00 - $200,200.00

Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.

JOIN TARGET CYBERSECURITY AS A LEAD SOAR ENGINEER - THREAT HUNTING AND COUNTERMEASURES

About Us

Target is an iconic brand, a Fortune 50 company and one of America’s leading retailers.

Target as a tech company? Absolutely. We’re the behind-the-scenes powerhouse that fuels Target’s passion and commitment to cutting-edge innovation. We anchor every facet of one of the world’s best-loved retailers with a strong technology framework that relies on the latest tools and technologies—and the brightest people—to deliver incredible value to guests online and in stores. Target Technology Services is on a mission to offer the systems, tools and support that guests and team members need and deserve. Our high-performing teams balance independence with collaboration, and we pride ourselves on being versatile, agile and creative. We drive industry-leading technologies in support of every angle of the business, and help ensure that Target operates smoothly, securely, and reliably from the inside out.

As a Lead SOAR Engineer you will focus on assessing and improving current threat-hunting processes and developing countermeasures to proactively address potential threats within the Cyber Fusion Center (CFC) environment. Your role will involve designing automations that streamline hunting workflows, enhance threat visibility, and mitigate advanced cyber threats. You will leverage your expert-level knowledge of security tools and scripting languages to create, maintain, and manage a library of automation playbooks for threat-hunting and countermeasure deployment, ensuring these playbooks are continuously updated as the threat landscape evolves.

Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs.


About You

4-year degree or equivalent experience

5+ years of experience in cyber security, with a strong focus on security engineering, threat hunting, threat detection, or incident response

2+ years’ direct experience with security orchestration and automation tools

2+ years’ experience in building detection based off threat intelligence

A solid understanding of SIEM systems and the incident response process

3+ years' of experience in scripting with one or more of the following languages: JavaScript, Python, PowerShell, and various shell scripting, and a proven background in creating automation tools and automating web-based services.

Thorough understanding of REST API best practices and usage.

Strong analytical and problem-solving skills, with a focus on using SIEM to enhance threat hunting and proactive detection efforts

Ability to demonstrate expert-level analytical expertise, close attention to detail, excellent critical thinking, logic, and adaptive learning

Experience with Malware and File Analysis highly desired

Possession of or desire to obtain relevant certifications such as GREM, GCFA or similar is a plus

Strong communication skills with the ability to navigate ambiguity and collaborate across teams

This position may be considered for a Remote or Hybrid (known internally at Target as "Flex for Your Day") work arrangement based on Target's needs.  A Remote work arrangement means the team member works full-time from home or an alternate location that's not a Target location, does not have a desk at a Target location and may travel to HQ up to 4 times a year.  A Hybrid/Flex for Your Day work arrangement means the team member's core role may be performed either remote or onsite at a Target location depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target.

Americans with Disabilities Act (ADA)

In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com.

Application deadline is : 12/30/2024
Confirm your E-mail: Send Email