> Markdown version of [/jobs/ext/2695410-lead-engineer-insider-risk-remote-or-hybrid](https://www.wearedevelopers.com/jobs/ext/2695410-lead-engineer-insider-risk-remote-or-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Engineer - Insider Risk(Remote Or Hybrid) - **Company:** Target Brands, Inc. - **Location:** Minneapolis, MN, United States (Remote available) - **Experience:** Expert - **Salary:** $132,000.0 - $238,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Computer Programming, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Security Information and Event Management, EndPointSecurity, Symantec, Cyber Threat Analysis - **Published:** September 3, 2026 - **Apply:** https://www.minneapoliscareersite.com/job.asp?id=3375532331&tx=JP2721FFG&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * 4 year degree or equivalent experience * 7+ years in cybersecurity with a focus in Incident Response, DLP, and Insider Threat * Extensive experience with DLP tools (e.g. ZScaler, ForcePoint, Symantec) * Deep understanding of Insider Threat methodologies and behavioral analytics to differentiate between uncommon and malicious activity * Demonstrated programming experience in Python, PowerShell or equivalent * Experience with maintaining SIEM, UEBA, EDR, and cloud security platforms * Demonstrated ability to build strong cross-functional partnerships and influence enterprise security strategy * Experience working closely with cyber threat intelligence, incident response, or detection engineering teams * Strong problem-solving skills with the ability to navigate complex, ambiguous security challenges * Excellent communication skills, with the ability to present complex concepts clearly to technical and executive audiences * Commitment to operational excellence, safety, and continuous improvement * Self-directed learner who stays current with evolving cybersecurity threats, technologies and best practices This position may be considered for a Remote or Hybrid (known internally at Target as "Flex for Your Day") work arrangement based on Target's needs. A Remote work arrangement means the team member works full-time from home or an alternate location that's not a Target location, does not have a desk at a Target location and may travel to HQ up to 4 times a year. A Hybrid/Flex for Your Day work arrangement means the team member's core role may be performed either remote or onsite at a Target location depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. ## Description As a Lead Engineer - Insider Risk, you will be pivotal in the protection of Target's data, systems, and intellectual property by ensuring employees do not conduct malicious activities. In this role, you will play a critical part in safeguarding enterprise data, protecting customer trust in Target, and strengthening the organization's overall security posture against insider threats by improving detection visibility and fidelity within our UEBA, alerting functionality, and responding and mitigating all identified threats., * Help lead the design, implementation and continuous improvement of the Insider Threat and DLP programs. * Define metrics through which we can ensure our coverage is comprehensive, effective, and efficient in an ever-changing threat landscape. * Cross train with other teams within the Cyber Fusion Center such as Cyber Threat Intelligence, Incident Response, Security Architecture, and Enterprise Incident Management. * Assist in implementation of net new DLP capabilities and ITP UEBA engine. * Become proficient in workflow automation within our SOAR platform and automate previously manual processes., * Monitor, investigate and maintain DLP technologies across endpoints, network sensors, cloud platforms, and email systems. * Conduct root cause analysis, recommend remediation actions, and institute blocking procedures as needed to prevent similar risk moving forward. * Integrate DLP tools with SIEM, UEBA, CASB, and endpoint detection platforms. * Conduct continuous improvement of custom rules based on tradecraft knowledge, anomaly detection hunts, threat intelligence, and previous cases. * Work closely with Employee Relations, Human Resources, Security Architecture, and policy teams to improve Target's overall security posture and move from detection to prevention. Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Remote, Hybrid, or In-Office: What’s Really Best for Developers?](https://www.wearedevelopers.com/magazine/638-remote-hybrid-or-in-office-what-s-really-best-for-developers)