Senior Engineer – Security Visibility Infrastructure

Target Target · Retail · NCD-0375 Brooklyn Park, MN

Senior Engineer responsible for designing, building, and operating reliable log ingestion capabilities for cybersecurity at Target. This role focuses on improving end-to-end log ingestion into Google SecOps, including pipeline design, data validation, and integration with various security teams. Requires proficiency in Python, regular expressions, and experience with cloud environments and distributed systems.

What you'd actually do

  1. Own and improve end-to-end log ingestion into Google SecOps (formerly Chronicle)—from source onboarding through reliable shipment—so downstream teams can power search, alerting, enrichment, and investigations.
  2. Design and deliver scalable improvements to ingestion pipelines, integrations, and data validation, including feed health signals, shipment validations, and other meta-attributes that ensure end-to-end feed reliability.
  3. Partner with and build strong working relationships across Threat Management Engineering, Threat Detection & Operations, Cyber Threat Intelligence, and CSIRT to deliver high-quality, backward-compatible changes to large-volume, high-criticality data feeds and SecOps integrations.
  4. Lead troubleshooting and root-cause analysis across log pipelines and SIEM integrations (including other SIEM platforms) as part of a shared 24/7 on-call rotation; implement preventative mechanisms through monitoring, runbooks, and automation.
  5. Build and enhance ingestion integrations and operational tooling using Python and regular expressions for parsing, validation, transformations, and schema evolution across standard and non-standard formats (e.g., JSON, Syslog, CEF, CSV/TSV).

Skills

Required

  • Python
  • regular expressions
  • API integration
  • log/event data ingestion and transformation
  • troubleshooting and root-cause analysis
  • distributed systems fundamentals
  • cloud environment experience

Nice to have

  • Experience migrating services or data flows between provider platforms

What the JD emphasized

  • high-criticality data feeds
  • 24/7 on-call rotation
  • root-cause analysis
  • preventative mechanisms
  • high-quality code