Hybrid Attack Surface Analyst II — Seattle

Nordstrom

Seattle (WA)

Hybrid

USD 122,000 - 189,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical insurance
Vision insurance
Dental insurance
Retirement plan
Paid time off

Job summary

Nordstrom in Seattle, WA is seeking an Attack Surface Analyst II to identify, assess, and monitor vulnerabilities across cloud and on‑prem environments. The role involves collaboration with cybersecurity and technology teams to reduce attack surface and improve cyber hygiene.

Ideal candidates have 2+ years in security operations, familiarity with vulnerability management, CSPM/ASM tools, scripting, and knowledge of regulatory requirements such as PCI.

Qualifications

  • 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields.
  • Understanding of networking, system administration, cloud services, asset management and cyber security principles.
  • Working knowledge of cybersecurity tools including vulnerability identification, CSPM, attack surface / exposure management platforms, network security tools.
  • Understanding of processes and controls needed to satisfy relevant regulatory and compliance requirements (e.g. PCI) for vulnerability and attack surface management.
  • Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP).
  • Proficiency in scripting languages (Python, PowerShell) for process automation.
  • Familiarity with MITRE ATT&CK framework and cyber hygiene best practices.

Responsibilities

  • Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements.
  • Lead the triage of critical vulnerability findings alongside partner teams and stakeholders to analyze the risk of emergent vulnerabilities and patch releases, coordinating expedited remediation as needed.
  • Research solutions and mitigations for highest risk vulnerabilities and provide technical guidance to remediation teams.
  • Engage with cybersecurity community and threat intel sources to stay current on latest vulnerability publications, zero-day exploits, and threat actor activity trends.
  • Assist in mapping Nordstrom's attack surface by supporting reconnaissance activities with network and offensive security teams and monitoring dark web resources for emerging exposures.
  • Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation, and contribute to metrics that measure attack surface risk and remediation progress.
  • Identify and recommend opportunities to reduce attack surface through improved processes, tooling, or architectural changes.
  • Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities.
  • Support regulatory and compliance requirements including capturing evidence and artifacts related to vulnerability scanning and reporting for e.g. PCI.
  • Contribute to Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks.
  • Monitor, review, and escalation errors in automation of operational processes.
  • Increase cybersecurity domain depth and breadth by completing trainings, attending industry presentations, and cross-training with peers across Cybersecurity & Privacy and Technology teams.

Skills

Security operations
Vulnerability management
Networking concepts
Cloud security
Python scripting
PowerShell
Regulatory compliance
MITRE ATTACK
Threat intelligence

Education

Bachelor's degree
Master's degree
Equivalent experience

Tools

Vulnerability scanners
CSPM
ASM platforms
Network security tools
Threat intel sources

Job description

Nordstrom in Seattle, WA is seeking an Attack Surface Analyst II to identify, assess, and monitor vulnerabilities across cloud and on‑prem environments. The role involves collaboration with cybersecurity and technology teams to reduce attack surface and improve cyber hygiene.

Ideal candidates have 2+ years in security operations, familiarity with vulnerability management, CSPM/ASM tools, scripting, and knowledge of regulatory requirements such as PCI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Attack Surface Analyst - Secure Cloud & Apps
Senior Attack Surface Analyst - Secure Cloud & Apps

Nordstrom, Inc. • Seattle (WA), Northern (KY)

Hybrid
USD 166,000 - 258,000
Medical/Vision, Dental
Retirement and Paid Time Away
Life Insurance and Disability
+1
Attack Surface Analyst 2 (Hybrid - Seattle)
Attack Surface Analyst 2 (Hybrid - Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 122,000 - 189,000
Medical insurance
Vision insurance
Dental insurance
+2
Senior Attack Surface Engineer: ASM & Automation
Senior Attack Surface Engineer: ASM & Automation

Coupang • Seattle (WA)

On-site
USD 108,000 - 232,000
Annual bonus 0-20%
FSA/HSA
Disability insurance
+5
Senior 2 Cybersecurity Analyst - Attack Surface Management (Hybrid - Seattle)
Senior 2 Cybersecurity Analyst - Attack Surface Management (Hybrid - Seattle)

Nordstrom, Inc. • Seattle (WA), Northern (KY)

Hybrid
USD 166,000 - 258,000
Medical/Vision, Dental
Retirement and Paid Time Away
Life Insurance and Disability
+1
Senior Attack Surface Analyst - Remote & Automation Lead
Senior Attack Surface Analyst - Remote & Automation Lead

SailPoint Technologies Holdings, Inc. • United States

On-site
USD 92,000 - 155,000
Senior Attack Surface Engineer — Onsite NM
Senior Attack Surface Engineer — Onsite NM

ShorePoint • Albuquerque (NM)

On-site
USD 140,000 - 170,000
PTO 144 hours
11 holidays
Health insurance
+3
Senior Attack Surface Management Lead (Remote)
Senior Attack Surface Management Lead (Remote)

SailPoint Technologies Holdings, Inc. • Northern (KY)

Hybrid
USD 92,000 - 155,000
Health insurance
401(k) matching
Paid parental leave
+1
Senior Attack Surface & Breach Simulation Engineer
Senior Attack Surface & Breach Simulation Engineer

United States Digital Space LLC • United States

Hybrid
USD 87,000 - 161,000
Health insurance
401K & stock purchase
Tuition reimbursement
+2
Senior Security Analyst: Proactive App & Cloud Security
Senior Security Analyst: Proactive App & Cloud Security

BDA • Woodinville (WA)

On-site
USD 120,000 - 130,000
Senior Attack Surface Management Engineer
Senior Attack Surface Management Engineer

ShorePoint • Albuquerque (NM)

On-site
USD 140,000 - 170,000
PTO 144 hours
11 holidays
Health insurance
+3