Senior Security Engineer - Threat Intelligence & Detection (Hybrid - Seattle)

Nordstrom, Inc.

Seattle, Northern (WA, KY)

Hybrid

USD 142,000 - 221,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Merchandise Discount

Job summary

Nordstrom, Inc. is seeking a Senior Security Engineer to join the TIDE team in Seattle. This hybrid role requires in-office presence at least 4 days a week and hands-on work across detection engineering, threat intelligence, and threat hunting to protect retail and e‑commerce environments.

You will design detection rules, operationalize threat intelligence, and lead automation efforts, partnering with SOC, IAM, and cloud teams to strengthen telemetry and incident response.

Qualifications

  • 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation
  • Proficient in writing detection logic in at least one enterprise SIEM or XDR; CrowdStrike NG-SIEM experience preferred
  • Knowledge of MITRE ATT&CK technique/sub-technique mapping to telemetry and detection logic
  • Hands-on experience with EDR analysis, behavioral anomaly detection, and post-exploitation investigations
  • Experience with hypothesis-driven threat hunting and end-to-end hunt execution
  • Scripting in Python and/or PowerShell for automation and log parsing
  • Experience contributing to incident response for malware, identity-based attacks, or insider threats
  • Strong written communication and documentation skills
  • Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience

Responsibilities

  • Design, develop, and maintain high-fidelity detection rules across endpoint, email, identity, network, and cloud domains
  • Operationalize the full detection lifecycle from threat modeling to deployment and retirement
  • Translate threat intelligence findings and hunt results into durable detection logic
  • Collaborate with CSIRT and SOC to enrich investigations with adversary context
  • Build automation to accelerate detection deployment, alert triage, and intel processing
  • Mentor junior team members and partner with cross-functional teams to ensure telemetry quality and coverage

Skills

Detection engineering
Threat intelligence
Threat hunting
Security automation
Incident response
Investigation analysis

Education

Bachelor's degree in Computer Science or related field

Tools

CrowdStrike NG-SIEM (LogScale/CQL)
SIEM/XDR platforms
CrowdStrike Fusion
MISP
ThreatConnect
Recorded Future

Job description

Job Description This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.

The Senior Security Engineer on the TIDE team is a hybrid practitioner who writes detection rules, hunts adversary activity across the data lake, and builds the automation that ties it all together. This role requires functional depth in at least two of the following domains: detection engineering, threat intelligence, threat hunting, security automation, investigation analysis, and incident response.

This role reports to the Sr. Manager of Threat Intelligence & Detection Engineering and serves as a lead technical contributor on the TIDE team, with independent project horizons of up to 120 days.

Responsibilities
Detection Engineering
  • Design, develop, and maintain high-fidelity detection rules in CrowdStrike NG-SIEM (LogScale/CQL) across endpoint, email, identity, network, and cloud domains
  • Operationalize the full detection lifecycle: threat modeling, logic development, empirical testing, deployment, tuning, and retirement
  • Build detection content aligned to MITRE ATT&CK, threat actor TTPs, and internal threat model priorities
  • Translate threat intelligence findings, incident post-mortems, and hunt discoveries into durable detection logic
  • Enforce detection engineering standards including taxonomy, quality criteria, and review processes
Threat Intelligence
  • Collect, analyze, and operationalize tactical and technical threat intelligence from open-source, commercial, and internal sources
  • Produce actionable intelligence products including threat actor profiles, TTP summaries, and IOC packages that directly inform detection priorities and hunting hypotheses
  • Monitor threat actor campaigns targeting retail and e-commerce environments across email, endpoint, identity, supply chain, and insider risk vectors
  • Collaborate with CSIRT and SOC to enrich active investigations with adversary context
  • Apply AI-assisted tooling to accelerate intelligence processing, IOC enrichment, and adversary research
Threat Hunting
  • Design and execute hypothesis-driven threat hunts across endpoint, email, identity, network, and cloud telemetry
  • Apply structured hunting methodologies (MITRE ATT&CK-based, data-driven, indicator-based) to surface undetected adversary activity
  • Document hunt outcomes—including negative results—and feed confirmed patterns back into the detection library
  • Maintain visibility into coverage gaps and drive new hunt-to-detect cycles to close them
SOC & Incident Response Support
  • Provide technical escalation support for complex incidents involving identity compromise, endpoint intrusion, lateral movement, and data exfiltration
  • Conduct targeted forensic and log-based analysis during active investigations, contributing to root cause determination and containment decisions
  • Develop and maintain investigation runbooks and analyst guidance to improve SOC response fidelity
  • Translate post-incident lessons learned into detection and hunting improvements
Automation and Tooling
  • Build and maintain automation that accelerates detection deployment, alert triage, case enrichment, and threat intel processing
  • Develop integrations between SIEM, EDR, email security, SOAR, and threat intelligence platforms to reduce analyst toil
  • Apply scripting (Python, PowerShell) to operationalize repetitive workflows including IOC ingest, log parsing, and detection validation
  • Leverage AI and machine learning tools to improve detection quality, reduce false positive rates, and accelerate triage
Collaboration and Mentorship
  • Mentor less experienced team members through code review, knowledge transfer, and structured guidance
  • Partner with SOC, IAM, Platform Engineering, Email Security, and Cloud teams to ensure telemetry quality and detection coverage
  • Contribute to cross-functional initiatives including purple team exercises, tabletop scenarios, and platform migration readiness
Required Qualifications
  • 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation
  • Demonstrated proficiency writing detection logic in at least one enterprise SIEM or XDR platform; CrowdStrike NG-SIEM (LogScale/CQL) experience strongly preferred
  • Working knowledge of MITRE ATT&CK at the technique and sub-technique level; ability to map adversary behaviors to telemetry sources and detection logic
  • Hands-on experience with EDR analysis, behavioral anomaly detection, and investigation of post-exploitation activity
  • Hands-on experience with hypothesis-driven threat hunting; ability to document and execute an end-to-end hunt
  • Scripting proficiency in Python and/or PowerShell for automation, log parsing, or investigative tooling
  • Experience contributing to incident response for malware incidents, identity-based attacks, or insider threats
  • Strong written communication skills; ability to produce clear, actionable documentation, detection rationale, and intelligence products
  • Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience
Preferred Qualifications
  • Familiarity with identity attack patterns including AiTM, MFA fatigue, session hijacking, token replay, and adversarial abuse of SSO and federated identity platforms
  • Experience with enterprise email security platforms and email-based threat detection including phishing, BEC, and malicious delivery mechanisms
  • Exposure to SOAR platforms and workflow automation (CrowdStrike Fusion or equivalent)
  • Experience with threat intelligence platforms (MISP, ThreatConnect, Recorded Future) and structured intel formats (STIX/TAXII)
  • Knowledge of detection-as-code practices, version control (Git), and CI/CD integration for detection deployment
  • Experience with cloud security telemetry (Azure, AWS) and cloud-native attack detection
  • Demonstrated use of AI tools to accelerate detection development, security operations, or threat research
  • Intermediate or advanced certifications such as GIAC GCIA, GCIH, GCTI, GDAT, or equivalent
Pay Range Details

$142,000.00 - $220,500.00 Annual

Benefits

Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away Life Insurance and Disability Merchandise Discount and EAP Resources
  • Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more
About Us

We’re a fast-moving fashion company that started as a shoe store in 1901. This heritage of service is the foundation we’re building on as we provide convenience and true connection for our customers. We empower our people to be innovative, creative and focused on providing the best service to our customers. Through it all, we remain committed to leaving the world better than we found it. Whether you’re a genius engineer, a phenomenal salesperson or a supply chain pro, we invite you to bring your unique talents and join our team. We reward great work, promote from within and celebrate diversity.

We strive to know our customers better than anyone else. We listen, anticipate, build trust and move with speed to deliver on their needs.

We treat every interaction as an opportunity to make an impact and deliver excellence.

We approach problems with curiosity and create solutions. We unlock potential to be bold, think big and inspire innovation.

We’re committed to delivering results, both today and tomorrow. We win as a team by supporting and challenging one another to be better every day.

We treat each other with respect and kindness. We do the small things that make a big difference. We create a welcoming environment, helping people feel connected, valued and part of one community. Come on! Join us!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Intel & Detection Engineer
Senior Threat Intel & Detection Engineer

Nordstrom, Inc. • Seattle (WA), Northern (KY)

Hybrid
USD 142,000 - 221,000
Merchandise Discount
Associate Security Engineer (Remote)
Associate Security Engineer (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)

Nordstrom, Inc. • Seattle (WA)

On-site
USD 191,000 - 297,000
Sr. Engineer, Exchange & Microsoft 365 Platforms (Hybrid - Seattle, WA)
Sr. Engineer, Exchange & Microsoft 365 Platforms (Hybrid - Seattle, WA)

Nordstrom, Inc. • Seattle (WA)

Hybrid
USD 150,000 - 190,000
Medical/Vision
Dental
Retirement
+8
Director of Engineering, PDLC Agents Platform (Hybrid - Seattle, WA)
Director of Engineering, PDLC Agents Platform (Hybrid - Seattle, WA)

Nordstrom, Inc. • Seattle (WA)

Hybrid
USD 299,000 - 365,000
Medical/Vision
Dental
401k
+3
Senior Security Engineer – Threat Intelligence, Detection
Senior Security Engineer – Threat Intelligence, Detection

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)

Relha LLC • Seattle (WA)

Hybrid
USD 191,000 - 297,000
Medical/Vision, Dental, Retirement and
Paid Time Away
Life Insurance and Disability
+2
Software Engineer 2 (Hybrid - Seattle, WA)
Software Engineer 2 (Hybrid - Seattle, WA)

Nordstrom, Inc. • Seattle (WA), Northern (KY)

Hybrid
USD 122,000 - 189,000
Medical/Vision/Dental
401k
Merchandise Discount
Sr. Director, Engineering - Next-Gen SIEM (Hybrid)
Sr. Director, Engineering - Next-Gen SIEM (Hybrid)

CrowdStrike • Sunnyvale (CA)

On-site
USD 235,000 - 350,000
Market leader compensation
Wellness programs
Vacation and holidays
+5
Senior Product Manager – Search and Discovery (Hybrid - Seattle)
Senior Product Manager – Search and Discovery (Hybrid - Seattle)

Nordstrom, Inc. • Seattle (WA), Northern (KY)

Hybrid
USD 142,000 - 221,000
Medical/Vision
Dental
Retirement
+5