Senior 2 Cybersecurity Analyst - Attack Surface Management (Hybrid - Seattle)

Nordstrom, Inc.

Seattle, Northern (WA, KY)

Hybrid

USD 166,000 - 258,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical/Vision, Dental
Retirement and Paid Time Away
Life Insurance and Disability
Merchandise Discount and EAP Resources

Job summary

Qualifications

  • 6+ years in security operations, vulnerability management, or offensive security, including senior/lead capacity.
  • Deep knowledge of MITRE ATT&CK framework, TTPs, and attack vectors.
  • Experience implementing cloud security controls in a multi-cloud environment.
  • Proficiency in IT architecture principles and practices.
  • Knowledge of offensive security methodologies and ethical hacking.
  • Deep understanding of system landscape and data flow within the domain and across adjacent domains.
  • Expertise in scripting languages for automation (Python, PowerShell).
  • Advanced knowledge of networking, system administration, cloud services, asset management, and cybersecurity principles.
  • Understanding of PCI compliance requirements for vulnerability/attack surface management.
  • Strong leadership and communication skills.

Responsibilities

  • Lead the growth of the attack surface management program and improve visibility into exposures.
  • Develop and implement solutions to reduce exposures and automate where possible.
  • Maintain Cybersecurity Standards, SOPs, and runbooks for attack surface management.
  • Collaborate with AppSec, DevOps, and cloud teams to secure deployments and design secure-by-design systems.
  • Maintain Nordstrom’s attack surface map with network and offensive security teams.
  • Lead data-driven, risk-prioritized initiatives to reduce vulnerabilities across technologies.
  • Develop metrics to measure operational efficiency and attack surface risk.
  • Pursue domain expertise through training, conferences, and threat intelligence.
  • Mentor teammates and lead knowledge-sharing sessions.
  • Lead domain compliance activities including evidence validation and PCI assessments.

Skills

MITRE ATT&CK
Cloud security
IT architecture
Scripting (Python, PowerShell)
Networking basics
PCI compliance
Leadership & communication
Cybersecurity principles

Education

Bachelor’s or Master’s degree in IT/CS/Cybersecurity

Job description

## **Job Description**The Senior 2 Attack Surface Analyst champions reduction of Nordstrom’s attack surface through continuous identification, assessment, and escalation of the highest-risk exposures, along with the actions needed to manage that risk. As a senior leader on the Attack Surface Management team, this role collaborates closely with cybersecurity and technology partner teams to prioritize risk, execute remediation activities, and automate processes that secure the technology landscape.## Key Responsibilities* Lead the growth of the attack surface management program, develop and implement solutions to improve visibility into exposures, and contribute to the design and implementation of net-new capabilities.* Continuously drive improvements in attack surface management processes, methodologies, and security toolsets to enhance operational effectiveness, automating where possible.* Maintain Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks.* Collaborate with AppSec, DevOps, and cloud platform teams to secure deployments and integrate security best practices into the design of software and related systems, ensuring a secure-by-design approach.* Maintain a map of Nordstrom’s attack surface through collaboration with network and offensive security teams, conducting regular assessments and reconnaissance activities, and leveraging dark web monitoring resources.* Lead data-driven, risk-prioritized, enterprise-wide initiatives to reduce vulnerabilities and exposures across Nordstrom’s technologies; identify opportunities and champion architectural changes that reduce attack surface.* Develop and present metrics to measure operational efficiency and attack surface risk.* Maintain domain expertise by completing trainings, attending industry presentations, obtaining certifications, engaging with the cybersecurity community, and consuming threat intelligence sources.* Support the growth of teammates’ domain expertise through mentorship, presentations, and knowledge-sharing sessions.* Lead compliance activities for the domain, including evidence validation and submission, proactive control evaluation and mitigation of gaps, and assessments (e.g., PCI).## Qualifications**Required*** 6+ years in security operations, vulnerability management, or offensive security domains, including experience in a senior or lead capacity.* Deep knowledge of the MITRE ATT&CK framework, threat actor tactics, techniques, and procedures (TTPs), and common attack vectors.* Experience implementing cloud security controls in a multi-cloud environment.* Proficiency in enterprise information technology (IT) architecture principles and practices.* Knowledge of offensive security methodologies and ethical hacking principles and practices.* Deep understanding of system landscape and data flow within the domain and across adjacent domains.* Expertise in scripting languages (e.g., Python, PowerShell) for process automation.* Advanced knowledge of networking, system administration, cloud services, asset management, and cybersecurity principles.* Deep understanding of the processes and controls needed to satisfy relevant regulatory and compliance requirements (e.g., PCI) for vulnerability and attack surface management.* Strong leadership and communication skills.* Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree.**Preferred*** Experience developing attack surface management capabilities and coaching more junior analysts.* Expertise across cybersecurity domains including vulnerability management, cloud security, attack surface management, network security, and cyber hygiene.* Demonstrated thought leadership on the application of emerging AI technologies within cybersecurity domains.* Advanced certifications (e.g., OSCE, GREM, CISSP). **Pay Range Details**The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.$166,000.00 - $258,000.00 Annual**We’ve got you covered...**Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:* Medical/Vision, Dental, Retirement and Paid Time Away* Life Insurance and Disability* Merchandise Discount and EAP ResourcesThis position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben\\_Overview\\_17-19.pdf
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Network Security Engineer (Hybrid - Seattle, WA)
Sr. Network Security Engineer (Hybrid - Seattle, WA)

Nordstrom • Seattle (WA)

On-site
USD 142,000 - 221,000
Medical/Vision, Dental
Retirement and Paid Time Away
Life Insurance and Disability
+1
Attack Surface Analyst 2 (Hybrid - Seattle)
Attack Surface Analyst 2 (Hybrid - Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 122,000 - 189,000
Medical insurance
Vision insurance
Dental insurance
+2
Senior Technical Program Manager - Security Platform Engineering (Hybrid - Seattle)
Senior Technical Program Manager - Security Platform Engineering (Hybrid - Seattle)

Nordstrom, Inc. • Seattle (WA)

Hybrid
USD 142,000 - 221,000
Senior Business Intelligence Analyst - Retail Foundation (Hybrid, Seattle)
Senior Business Intelligence Analyst - Retail Foundation (Hybrid, Seattle)

Nordstrom, Inc. • Seattle (WA)

Hybrid
USD 80,000 - 132,000
Sr. Software Engineer: Inventory Positioning (Hybrid - Seattle, WA)
Sr. Software Engineer: Inventory Positioning (Hybrid - Seattle, WA)

Nordstrom • Seattle (WA)

On-site
USD 142,000 - 221,000
Medical/Vision
Dental
Retirement
+5
Data Analyst 3 - Supply Chain Operations
Data Analyst 3 - Supply Chain Operations

Nordstrom, Inc. • Seattle (WA)

On-site
USD 102,000 - 171,000
Medical/Vision, Dental insurance
401k
Merchandise Discount
Senior Full Stack Software Engineer
Senior Full Stack Software Engineer

Nordstrom, Inc. • Seattle (WA)

On-site
USD 142,000 - 220,500
Medical/Vision, Dental Insurance
401k and Retirement Benefits
Merchandise Discount
+1
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 191,000 - 297,000
Medical/Vision, Dental, Retirement
Merchandise Discount
Director - Distribution Center Engineering
Director - Distribution Center Engineering

Nordstrom, Inc. • Seattle (WA), Northern (KY)

Hybrid
USD 175,000 - 275,000
Medical/Vision/Dental
Retirement program
Paid Time Away
+2
Senior Manager, Identity Security Operations
Senior Manager, Identity Security Operations

Nordstrom • Seattle (WA)

On-site
USD 191,000 - 297,000
Medical/Vision, Dental, Retirement and
Paid Time Away
Life Insurance and Disability