Cloud Operations Engineer Jobs in USA with Visa Sponsorship
Cloud Operations Engineers are strong H-1B visa candidates because the role consistently meets USCIS specialty occupation standards, a computer science or engineering degree is typically required. Employers across cloud infrastructure, fintech, and enterprise SaaS routinely sponsor this position. For detailed occupation requirements, see the O*NET profile.
Find Cloud Operations Engineer JobsOverview
Showing 5 of 8,079+ Cloud Operations Engineer jobs










See all 8,079+ Cloud Operations Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cloud Operations Engineer roles.
Get Access To All Jobs
COMPENSATION
- The pay range is $132,000.00 - $238,000.00
Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves. Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at https://corporate.target.com/careers/benefits.
About us
Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here. Target is one of the world's most recognized brands and one of America's leading retailers. But behind the brand our guests love, is a culture of continual innovation and right now, we are up to big things! Target's security team is a place where innovation happens daily. Interested in a culture that combines ongoing learning, engineering excellence, and stellar outcomes? We are too – that's why we work here. Join our team to improve Target's security and move the business forward.
ROLE AND RESPONSIBILITIES
As a Lead Engineer on the Cloud Security team, you'll be the senior technical owner of Target's Cloud Security Platform and CSPM capability across our public and private cloud environments. You'll be the person the team, our partners, and leadership look to for how CSPM and the broader CNAPP surface should be designed, deployed, operated, and evolved at Target scale — turning posture signal into action, and controls into paved roads that developers can actually use.
Expect to:
- Serve as the senior technical lead and hands-on owner of Target's Cloud Security Platform and CSPM capability — setting the technical direction, standards, and roadmap that other engineers execute against.
- Own the end-to-end engineering, deployment, configuration, tuning, and ongoing operation of the CSPM/CNAPP platform across Target's public and private cloud environments, including onboarding of new cloud accounts, projects, and workloads, leading the implementation and operation of core functional controls, and managing operations such as RBAC and SSO.
- Operate the platform as a production system: own its availability, performance, observability, capacity, upgrade cadence, and outage response, with clear SLOs and on-call participation.
- Own the CSPM policy set end-to-end: which rules are on, which are tuned, which are suppressed and why — grounded in Target's reference architecture, secure configuration benchmarks, and the realities of our environment.
- Peer with Cloud Security software developers on design of the findings pipeline for CSPM and adjacent CNAPP signal. The pipeline will aggregate posture findings, deduplicate and enrich them with ownership attribution, and ship them into Target's enterprise remediation dashboards with SLAs so product and platform teams can act.
- Drive continuous reduction of noise and false positives so every finding that reaches an engineer is worth their time.
- Extend ownership into adjacent CNAPP capabilities delivered by the same platform — cloud workload posture, container/image posture, cloud identity/entitlement (CIEM) findings, and IaC posture signal — coordinating with the engineers who own the deeper IaC scanning, admission control, and SSPM controls.
- Partner with Detection & Response to turn high-signal posture and runtime findings into detections, and to support cloud incident response with the context the platform can provide.
- Drive multi-quarter initiatives end-to-end: from problem framing and scoping, through design, build, rollout, adoption, and steady-state operation.
- Make pragmatic build-vs-buy calls within the platform's ecosystem, and own the technical side of the tool's lifecycle: evaluations/POCs, capability adoption, integration work, and input into vendor and contract discussions.
- Treat the Cloud Security Platform as a product: invest in automation, self-service, and platform thinking so CSPM coverage and remediation scale with Target's cloud footprint rather than with headcount.
- Continuously reduce toil for both the team and Target's engineering organization — fewer one-off tickets, more paved roads, better defaults, faster feedback for developers.
- Own the developer experience of the platform's findings and controls: clear explanations, documented escape hatches, fast and well-coordinated exception handling, and a tight feedback loop with product engineering.
- Drive adoption of the platform's coverage across Target Tech, including onboarding, exception/governance workflows, and developer enablement.
- Integrate cloud security telemetry from the platform into Target's enterprise SIEM/SOAR pipelines and remediation/governance systems.
- Partner with the broader Cloud Platform organization, Identity Security, Network Security, Data Security, Detection & Response, Vulnerability Management, BISO, and product engineering to align on requirements, rollout plans, and operational ownership.
- Represent the platform's work clearly to senior leadership and to staff engineers alike: roadmap, risk reduction, operational health, and tradeoffs — in language tuned to the audience.
- Mentor other engineers on the team on cloud security, CSPM/CNAPP, and platform engineering practices, and raise the bar for code quality, testing, code review, on-call hygiene, postmortems, and operational excellence.
Core responsibilities are described within this job description. Job duties may change at any time due to business needs.
BASIC QUALIFICATIONS
- 4-year degree OR equivalent work experience
- 7+ years of hands-on experience in technology, with deep experience in cloud security and the adjacent disciplines that make it work — cloud platform engineering, CSPM, Kubernetes, IaC/CI-CD, automation, identity, and detection/response integration
- Demonstrated experience as a senior IC or tech lead owning a security or platform capability end-to-end at enterprise scale, including setting technical direction that other engineers execute against
- Deep hands-on experience deploying, operating, and tuning a CSPM or CNAPP platform in a large multi-cloud environment — including onboarding accounts, authoring and tuning policies, managing exceptions, and driving findings to remediation
- Strong opinions, backed by experience, on how to keep CSPM signal-to-noise high: policy tuning, suppression discipline, ownership attribution, and SLA-based remediation
- Track record of running production platforms with clear SLOs, on-call coverage, change management, and continuous-improvement loops
- Experience driving multi-quarter roadmaps end-to-end — from problem framing through rollout, adoption, and steady-state operation — and delivering predictably against them
- Comfortable making and defending pragmatic build-vs-buy decisions, and knowing when to invest in custom engineering vs. lean on a platform capability
- Hands-on experience with public cloud (GCP preferred; AWS/Azure experience also valued) and private cloud / Kubernetes environments at enterprise scale
- Working knowledge of Kubernetes and admission controller frameworks — enough to partner effectively with the engineers who own those controls and to integrate posture signal across them
- Strong working knowledge of infrastructure as code (Terraform and equivalent) and policy-as-code (e.g., Rego), and familiarity with integrating policy and posture signal into CI/CD
- Experience building and operating findings pipelines that integrate cloud security signal into enterprise remediation/governance platforms (shipping CSPM and adjacent CNAPP findings to centralized dashboards with ownership attribution & SLAs)
- Experience integrating cloud telemetry into enterprise SIEM/SOAR pipelines
- Proven history of effectively utilizing a variety of security tools and technologies across diverse environments. The ideal candidate will not be limited to specific vendors or solutions but will possess the technical depth to comprehend and implement end-to-end solutions that align with the reference security architecture's requirements
- Hands-on experience integrating security tooling with developer workflows (CI/CD, source control, ticketing) in a way that scales with a large engineering organization
- Strong understanding of secure software development practices, network security fundamentals, and modern cloud-native architectures
- Solid understanding of AI/ML and the emerging security considerations associated with it, including how to surface and enforce them through cloud security tooling
- Automation-first engineering mindset, with hands-on fluency in at least one general-purpose language (e.g., Python, Go) and a track record of building reusable platforms and paved roads instead of one-off scripts
- Strong cross-functional partner: comfortable working closely with a variety of security and product engineering teams to align requirements, rollout plans, and operational ownership
- Effective at representing your work, risks, and tradeoffs to senior leadership, and equally effective explaining the same content to staff engineers in detail
- Good understanding of security management workflows in large enterprise organizations and complex environments, and of the current threat landscape and the challenges most organizations are facing
- Working knowledge of security frameworks, standards, the cloud threat landscape, and best practices (e.g., NIST, CIS Benchmarks, ISO/IEC 27001) — enough to align the platform's controls to them, without being the policy author
- Excellent written and verbal communication skills with strong presentation abilities
- Demonstrated curiosity, bias for action, and a genuine builder's mindset — you want to ship the platform, not just describe it
This position will operate as a Hybrid/Flex for Your Day work arrangement based on Target's needs. A Hybrid/Flex for Your Day work arrangement means the team member's core role will need to be performed both onsite at the Target HQ MN location the role is assigned to and virtually, depending upon what your role, team and tasks require for that day. Work duties cannot be performed outside of the country of the primary work location, unless otherwise prescribed by Target. Click here if you are curious to learn more about Minnesota.
Benefits Eligibility
Please paste this url into your preferred browser to learn about benefits eligibility for this role: https://tgt.biz/BenefitsForYou_E
Americans with Disabilities Act (ADA)
In compliance with state and federal laws, Target will make reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please reach out to candidate.accommodations@HRHelp.Target.com. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed through this channel.
See all 8,079+ Cloud Operations Engineer Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Cloud Operations Engineer roles.
Get Access To All JobsTips for Finding Visa Sponsorship as a Cloud Operations Engineer
Target cloud-native employers first
Companies running AWS, Azure, or GCP at scale hire Cloud Operations Engineers regularly and have established sponsorship pipelines. These employers file H-1B petitions routinely and are less likely to treat sponsorship as an obstacle during hiring.
Certifications strengthen your petition
AWS Certified SysOps Administrator, Google Cloud Professional, or Azure Administrator certifications signal specialized knowledge. USCIS looks favorably on credentials that demonstrate the role requires more than a generalist degree, these certifications support that case directly.
Frame your degree match carefully
Computer science, information systems, and electrical engineering degrees align cleanly with this role. If your degree is in a related but non-obvious field, document how your coursework maps to cloud infrastructure, degree mismatches are a common RFE trigger.
Start the LCA process early
Your employer must file a Labor Condition Application with the Department of Labor before submitting your H-1B petition. The LCA certifies prevailing wage compliance and typically takes one to two weeks, delays here push back your entire timeline.
Understand cap-exempt employer options
Universities, nonprofit research institutions, and certain government entities are exempt from the H-1B annual cap and lottery. Cloud operations roles exist at these organizations, and a cap-exempt petition can be filed any time of year without waiting for the April lottery.
Use Migrate Mate to find sponsoring employers
Not every company willing to hire Cloud Operations Engineers will sponsor visas. Migrate Mate filters job listings specifically for sponsorship-eligible roles, saving you from applying to positions where visa support was never on the table.
Frequently Asked Questions
Does a Cloud Operations Engineer role qualify as a specialty occupation for H-1B purposes?
Yes, in most cases. USCIS considers a position a specialty occupation when it normally requires at least a bachelor's degree in a specific technical field. Cloud Operations Engineer roles routinely require computer science, information systems, or engineering degrees, which meets that standard. Roles with vague requirements like 'any bachelor's degree accepted' can face RFEs, so job descriptions that specify a technical field hold up better under scrutiny.
What degree do I need to get H-1B sponsorship as a Cloud Operations Engineer?
A bachelor's degree or higher in computer science, information technology, electrical engineering, or a closely related field is the standard. Degrees in unrelated disciplines supported by IT certifications can sometimes qualify, but USCIS applies stricter scrutiny. If your degree is in a field that isn't an obvious match, a detailed credentials evaluation from a recognized evaluator strengthens your petition considerably.
How competitive is the H-1B lottery for Cloud Operations Engineers?
Cloud Operations Engineers fall under the regular cap, which in recent years has seen selection rates around 25%. Premium processing ($2,805 as of 2025) doesn't improve lottery odds, it only speeds up USCIS adjudication after selection. If you're subject to the cap, the April lottery is your one annual window. Working for a cap-exempt employer is the only way to bypass it entirely.
Can I find Cloud Operations Engineer jobs that sponsor visas on Migrate Mate?
Yes. Migrate Mate is built specifically for visa-requiring candidates and filters listings to employers actively open to sponsorship. You can browse Cloud Operations Engineer roles without wading through postings from companies that won't support an H-1B visa or E-3 visa petition. It's the most direct way to identify sponsoring employers in this field without burning time on applications that will stall at the visa question.
Are there visa options besides H-1B for Cloud Operations Engineers?
Yes. Australian citizens can use the E-3 visa, which has a separate 10,500-person annual cap that has never been exhausted, no lottery required. Canadian and Mexican citizens may qualify under the TN visa for certain technology roles. Candidates with extraordinary ability in cloud infrastructure can pursue the O-1A. L-1B transfers are another route for those already employed by a multinational with a U.S. presence.
What is the prevailing wage requirement for sponsored Cloud Operations Engineer jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.