1

Cloud Security Lead Jobs (NOW HIRING)

Job Summary As a Lead Cloud Security Engineer within our telecommunications company, you will be responsible for ensuring the security of our cloud infrastructure, particularly withinpublic cloud ...

Lead Cloud Security Engineer

Chicago, IL · On-site

$67.50 - $89.75/hr

Lead Cloud Security Architect - Secret Clearance Required - Hybrid in San Antonio, TX IPSecure is seeking an experienced Lead Security Architect to lead the design, implementation, and continuous ...

New

Job Summary As a Lead Cloud Security Engineer within our telecommunications company, you will be responsible for ensuring the security of our cloud infrastructure, particularly within public cloud ...

Aretec seeks a Security Lead for a 100% remote opportunity with a minimum of 10 years of experience ... cloud automation capabilities * prioritizing and coordinating security remediation activities ...

Cloud Security Architect

Manhattan, NY · On-site

$72.25 - $96/hr

Lead risk assessments and compliance reviews (NIST, ISO, SOC2) * Develop reference architectures, frameworks, and security patterns * Provide technical leadership during client cloud migration ...

Cloud Security Architect

Irvine, CA · On-site

$69.50 - $92.25/hr

Responsibilities : • Lead cloud security architecture for the Data Center Exit migration to AWS EC2. • Design and implement AWS Landing Zone security including IAM guardrails, SCPs, and logging ...

Cloud Security Engineer

Washington, DC · On-site +1

$74.25 - $98.50/hr

Serve as the lead Cloud Security Architect, designing and implementing secure architectures for multi-cloud and hybrid environments supporting FAA systems. * Define and document cloud security ...

Cloud Security Architect

Bethesda, MD · On-site

$70.25 - $93.25/hr

We are seeking an experienced Senior Manager, Cloud Security Architect to lead the design and implementation of secure cloud infrastructure across our AWS-based environments. This role will focus on ...

Identify opportunities to reduce cloud security risk for WBD, to solution, and to lead implementations. * Create design artifacts to enable members of the Cloud Security team to implement solutions ...

Cloud Security Architect Lead

Mclean, VA · On-site

$150K - $224K/yr

Set vision, lead and coach security architecture and automation teams accountable for designing and architecting cloud solutions and cloud security controls. * Adopt and champion Agile methodologies ...

Cloud Security Engineer

Washington, DC · On-site

$74.25 - $98.50/hr

Serve as the lead Cloud Security Architect, designing and implementing secure architectures for multi-cloud and hybrid environments supporting FAA systems. * Define and document cloud security ...

Set vision, lead and coach security architecture and automation teams accountable for designing and architecting cloud solutions and cloud security controls. * Adopt and champion Agile methodologies ...

Cloud Security Architect

Princeton, NJ · On-site

$69.25 - $92/hr

Lead architecture and implementation of Palo Alto Strata Cloud Manager (SCM) * Design secure cloud network architectures across AWS/Azure/GCP * Define standards, best practices, and security ...

Showing results 41-60

Cloud Security Lead information

See salary details

$8

$30

$83

How much do cloud security lead jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for cloud security lead in the United States is $30.81, according to ZipRecruiter salary data. Most workers in this role earn between $17.31 and $36.06 per hour, depending on experience, location, and employer.

What does a Cloud Security Lead do?

A Cloud Security Lead is responsible for overseeing the security of an organization’s cloud computing environments. They design, implement, and manage security strategies, policies, and controls to protect cloud-based systems and data. This role involves assessing risks, responding to security incidents, ensuring compliance with relevant regulations, and working closely with IT and business teams to ensure secure cloud adoption. Cloud Security Leads also stay up-to-date with the latest security threats and technologies to proactively safeguard cloud infrastructure.

What are some of the main challenges a Cloud Security Lead faces when implementing security policies across multi-cloud environments?

A Cloud Security Lead often encounters challenges such as ensuring consistent security policy enforcement across different cloud providers, each with unique configurations and services. Coordinating with various development and operations teams to maintain compliance and manage access controls can be complex, especially in fast-paced or large-scale organizations. Additionally, keeping up with evolving cloud security threats requires continuous learning and proactive monitoring. Effective communication and collaboration with stakeholders are essential to address these challenges and ensure robust protection of cloud assets.

What are the key skills and qualifications needed to thrive as a Cloud Security Lead, and why are they important?

To thrive as a Cloud Security Lead, you need a deep understanding of cloud platforms (such as AWS, Azure, or Google Cloud), cybersecurity principles, risk assessment, and often a bachelor's degree in computer science or a related field. Familiarity with cloud security tools, identity and access management systems, and certifications like CISSP, CCSK, or AWS Certified Security are typically required. Strong leadership, analytical thinking, and effective communication are crucial soft skills for guiding teams and collaborating with stakeholders. These skills are vital to ensure robust cloud security posture, compliance, and protection of sensitive data in dynamic cloud environments.

What cities are hiring for Cloud Security Lead jobs?

Cities with the most Cloud Security Lead job openings:

What states have the most Cloud Security Lead jobs?

States with the most job openings for Cloud Security Lead jobs include:

What are popular job titles related to Cloud Security Lead jobs?

For Cloud Security Lead jobs, the most frequently searched job titles are:

Infographic showing various Cloud Security Lead job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 10% Part Time, and 3% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $64,082 per year, or $30.8 per hour.

Lead Engineer - Cloud Security (Cloud Security Platform & CSPM)

Minneapolis, MN

Target
Retail • 10K+ employees

$132K - $238K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 7 days ago


Key responsibilities

  • Serve as the senior technical lead and hands-on owner of Target's Cloud Security Platform and CSPM capability, setting the technical direction, standards, and roadmap.

  • Own the end-to-end engineering, deployment, configuration, tuning, and ongoing operation of the CSPM/CNAPP platform across Target's cloud environments, including onboarding, core controls, and operational management.

  • Operate the platform as a production system, ensuring its availability, performance, observability, capacity, and managing outages with clear SLOs and on-call participation.


Target rating

6.6

Company rating: 6.6 out of 10

Based on 7,060 frontline employees who took The Breakroom Quiz


Job description

The pay range is $132,000.00 - $238,000.00

Pay is based on several factors which vary based on position.These include labor markets and in some instancesmay include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves.Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation.Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.

About Us

Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here. Target is one of the world's most recognized brands and one of America's leading retailers. But behind the brand our guests love, is a culture of continual innovation and right now, we are up to big things! Target's security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are too - that's why we work here. Join our team to improve Target's security and move the business forward.

As a Lead Engineer on the Cloud Security team, you'll be the senior technical owner of Target's Cloud Security Platform and CSPM capability across our public and private cloud environments. You'll be the person the team, our partners, and leadership look to for how CSPM and the broader CNAPP surface should be designed, deployed, operated, and evolved at Target scale - turning posture signal into action, and controls into paved roads that developers can actually use.

Beyond deep technical expertise, you have a strong bias for action and a builder's mindset. The Cloud Security Platform sits between architecture and the engineering teams who consume it, and you are comfortable operating in that realm - translating security requirements into reliable, automated, developer-friendly controls; owning the day-to-day operation and continuous improvement of the CSPM/CNAPP platform; coordinating exceptions and developer-experience tradeoffs and partnering with peers so that cloud security findings flow into the enterprise remediation lifecycle. You have the engineering credibility to set technical direction for a team of engineers as a hands-on IC, and the communication and partnership skills to make the controls land well across Target.

Expect to:

Serve as the senior technical lead and hands-on owner of Target's Cloud Security Platform and CSPM capability - setting the technical direction, standards, and roadmap that other engineers execute against.

Own the end-to-end engineering, deployment, configuration, tuning, and ongoing operation of the CSPM/CNAPP platform across Target's public and private cloud environments, including onboarding of new cloud accounts, projects, and workloads, leading the implementation and operation of core functional controls, and managing operations such as RBAC and SSO.

Operate the platform as a production system: own its availability, performance, observability, capacity, upgrade cadence, and outage response, with clear SLOs and on-call participation.

Own the CSPM policy set end-to-end: which rules are on, which are tuned, which are suppressed and why - grounded in Target's reference architecture, secure configuration benchmarks, and the realities of our environment.

Peer with Cloud Security software developers on design of the findings pipeline for CSPM and adjacent CNAPP signal. The pipeline will aggregate posture findings, deduplicate and enrich them with ownership attribution, and ship them into Target's enterprise remediation dashboards with SLAs so product and platform teams can act.

Drive continuous reduction of noise and false positives so every finding that reaches an engineer is worth their time.

Extend ownership into adjacent CNAPP capabilities delivered by the same platform - cloud workload posture, container/image posture, cloud identity/entitlement (CIEM) findings, and IaC posture signal - coordinating with the engineers who own the deeper IaC scanning, admission control, and SSPM controls.

Partner with Detection & Response to turn high-signal posture and runtime findings into detections, and to support cloud incident response with the context the platform can provide.

Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation.

Make pragmatic build-vs-buy calls within the platform's ecosystem, and own the technical side of the tool's lifecycle: evaluations/POCs, capability adoption, integration work, and input into vendor and contract discussions.

Treat the Cloud Security Platform as a product: invest in automation, self-service, and platform thinking so CSPM coverage and remediation scale with Target's cloud footprint rather than with headcount.

Continuously reduce toil for both the team and Target's engineering organization - fewer one-off tickets, more paved roads, better defaults, faster feedback for developers.

Own the developer experience of the platform's findings and controls: clear explanations, documented escape hatches, fast and well-coordinated exception handling, and a tight feedback loop with product engineering.

Drive adoption of the platform's coverage across Target Tech, including onboarding, exception/governance workflows, and developer enablement.

Integrate cloud security telemetry from the platform into Target's enterprise SIEM/SOAR pipelines and remediation/governance systems.

Partner with the broader Cloud Platform organization, Identity Security, Network Security, Data Security, Detection & Response, Vulnerability Management, BISO, and product engineering to align on requirements, rollout plans, and operational ownership.

Represent the platform's work clearly to senior leadership and to staff engineers alike: roadmap, risk reduction, operational health, and tradeoffs - in language tuned to the audience.

Mentor other engineers on the team on cloud security, CSPM/CNAPP, and platform engineering practices, and raise the bar for code quality, testing, code review, on-call hygiene, postmortems, and operational excellence.

Core responsibilities are described within this job description. Job duties may change at any time due to business needs.

About You:

4-year degree OR equivalent work experience

7+ years of hands-on experience in technology, with deep experience in cloud security and the adjacent disciplines that make it work - cloud platform engineering, CSPM, Kubernetes, IaC/CI-CD, automation, identity, and detection/response integration

Demonstrated experience as a senior IC or tech lead owning a security or platform capability end-to-end at enterprise scale, including setting technical direction that other engineers execute against

Deep hands-on experience deploying, operating, and tuning a CSPM or CNAPP platform in a large multi-cloud environment - including onboarding accounts, authoring and tuning policies, managing exceptions, and driving findings to remediation

Strong opinions, backed by experience, on how to keep CSPM signal-to-noise high: policy tuning, suppression discipline, ownership attribution, and SLA-based remediation

Track record of running production platforms with clear SLOs, on-call coverage, change management, and continuous-improvement loops

Experience driving multi-quarter roadmaps end-to-end - from problem framing through rollout, adoption, and steady-state operation - and delivering predictably against them

Comfortable making and defending pragmatic build-vs-buy decisions, and knowing when to invest in custom engineering vs. lean on a platform capability

Hands-on experience with public cloud (GCP preferred; AWS/Azure experience also valued) and private cloud / Kubernetes environments at enterprise scale

Working knowledge of Kubernetes and admission controller frameworks - enough to partner effectively with the engineers who own those controls and to integrate posture signal across them

Strong working knowledge of infrastructure as code (Terraform and equivalent) and policy-as-code (e.g., Rego), and familiarity with integrating policy and posture signal into CI/CD

Experience building and operating findings pipelines that integrate cloud security signal into enterprise remediation/governance platforms (shipping CSPM and adjacent CNAPP findings to centralized dashboards with ownership attribution & SLAs)

Experience integrating cloud telemetry into enterprise SIEM/SOAR pipelines

Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architecture's requirements

Hands-on experience integrating security tooling with developer workflows (CI/CD, source control, ticketing) in a way that scales with a large engineering organization

Strong understanding of secure software development practices, network security fundamentals, and modern cloud-native architectures

Solid understanding of AI/ML and the emerging security considerations associated with it, including how to surface and enforce them through cloud security tooling

Automation-first engineering mindset, with hands-on fluency in at least one general-purpose language (e.g., Python, Go) and a track record of building reusable platforms and paved roads instead of one-off scripts

Strong cross-functional partner: comfortable working closely with a variety of security and product engineering teams to align requirements, rollout plans, and operational ownership

Effective at representing your work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail

Good understanding of security management workflows in large enterprise organizations and complex environments, and of the current threat landscape and the challenges most organizations are facing

Working knowledge of security frameworks, standards, the cloud threat landscape, and best practices (e.g., NIST, CIS Benchmarks, ISO/IEC 27001) - enough to align the platform's controls to them, without being the policy author

Excellent written and verbal communication skills with strong presentation abilities

Demonstrated curiosity, bias for action, and a genuine builder's mindset - you want to ship the platform, not just describe it

This position will operate as a Hybrid/Flex for Your Day work arrangement based on Target's needs. A Hybrid/Flex for Your Day work arrangement means the team member's core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.

Benefits Eligibility

Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_E

Americans with Disabilities Act (ADA)

In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed through this channel.


What Target employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Target logo

About Target

Sourced by ZipRecruiter

We're here to help all families discover the joy of everyday life. Target is a general merchandise retailer with stores in all 50 U.S. states and the District of Columbia. 75% of the U.S. population lives within 10 miles of a Target store. We employ 400,000+ Our tagline is "Expect More. Pay Less." We've been using it since 1994! The Target Corporation also owns Shipt and Roundel. More to love! Target is headquartered in Minneapolis, Minnesota, its hometown since the first Target store opened in 1962 under The Dayton Company.

Industry

Retail and scientific research and development services

Company size

10,000+ Employees

Headquarters location

Minneapolis, MN, US