MNC InsiderMNC Insider

Attack Surface Analyst 2 (Hybrid - Seattle)

Nordstrom

Attack Surface Analyst 2 (Hybrid - Seattle)

full-timePosted: Aug 13, 2026Updated: Aug 28, 2026WA, Seattle

Job Description

Job DescriptionThis role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position. Position Summary As an Attack Surface Analyst II, you will identify, assess, prioritize and monitor vulnerabilities that pose a risk to Nordstrom’s technologies and operations. This role will support the discovery and reduction of exposures across cloud, on-prem, and third-party environments and identifying opportunities to improve cyber hygiene processes to proactively reduce the attack surface. Key Responsibilities Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements. Lead the triage of critical vulnerability findings alongside partner teams and stakeholders to analyze the risk of emergent vulnerabilities and patch releases, coordinating expedited remediation as needed. Research solutions and mitigations for highest risk vulnerabilities and provide technical guidance to remediation teams. Engage with cybersecurity community and threat intel sources to stay current on latest vulnerability publications, zero-day exploits, and threat actor activity trends. Assist in mapping Nordstrom's attack surface by supporting reconnaissance activities with network and offensive security teams and monitoring dark web resources for emerging exposures. Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation, and contribute to metrics that measure attack surface risk and remediation progress. Identify and recommend opportunities to reduce attack surface through improved processes, tooling, or architectural changes. Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities. Support regulatory and compliance requirements including capturing evidence and artifacts related to vulnerability scanning and reporting for [e.g. PCI] Contribute to Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks. Monitor, review, and escalate errors in automation of operational processes. Increase cybersecurity domain depth and breadth by completing trainings, attending industry presentations, and cross-training with peers across Cybersecurity & Privacy and Technology teams. Qualifications 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields. Understanding of networking, system administration, cloud services, asset management and cyber security principles. Working knowledge of cybersecurity tools including vulnerability identification, cloud security posture management (CSPM), attack surface / exposure management platforms , network security tools Understanding of processes and controls needed to satisfy relevant regulatory and compliance requirements [e.g. PCI] for vulnerability and attack surface management. Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP), Cloud Asset Exposure: AWS S3 buckets, Azure Blob storage Proficiency in scripting languages (Python, PowerShell) for process automation Working knowledge of emerging AI technologies and how they can be applied within the ASM domain Familiarity with cybersecurity domains and concepts including the MITRE ATT&CK framework, common attack vectors, vulnerabilities and exposures, defense-in-depth principles, network security controls, and cloud and endpoint exposure risks Awareness of best practices for cyber hygiene including patch management, hardening, secure configuration management, and lifecycle management Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree. Pay Range DetailsThe pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.$121,500.00 - $188,500.00 Annual We’ve got you covered…Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:Medical/Vision, Dental, Retirement and Paid Time AwayLife Insurance and DisabilityMerchandise Discount and EAP Resources This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_16.pdf A few more important points...The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site. Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com. Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs. Nordstrom keeps job postings open for at least one day after the posting date. © 2026 Nordstrom, Inc

Locations

  • WA, Seattle

Skills Required

  • cybersecurity tools including vulnerability identificationintermediate
  • scripting languagesintermediate
  • emerging AI technologiesintermediate
  • cybersecurity domainsintermediate

Required Qualifications

  • 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields. (experience, 2 years)
  • 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields. (experience, 2 years)
  • Understanding of networking, system administration, cloud services, asset management and cyber security principles. (experience)
  • Understanding of networking, system administration, cloud services, asset management and cyber security principles. (experience)
  • Working knowledge of cybersecurity tools including vulnerability identification, cloud security posture management (CSPM), attack surface / exposure management platforms , network security tools (experience)
  • Working knowledge of cybersecurity tools including vulnerability identification, cloud security posture management (CSPM), attack surface / exposure management platforms , network security tools (experience)
  • Understanding of processes and controls needed to satisfy relevant regulatory and compliance requirements [e.g. PCI] for vulnerability and attack surface management. (experience)
  • Understanding of processes and controls needed to satisfy relevant regulatory and compliance requirements [e.g. PCI] for vulnerability and attack surface management. (experience)
  • Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP), Cloud Asset Exposure: AWS S3 buckets, Azure Blob storage (experience)
  • Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP), Cloud Asset Exposure: AWS S3 buckets, Azure Blob storage (experience)
  • Proficiency in scripting languages (Python, PowerShell) for process automation (experience)
  • Proficiency in scripting languages (Python, PowerShell) for process automation (experience)
  • Working knowledge of emerging AI technologies and how they can be applied within the ASM domain (experience)
  • Working knowledge of emerging AI technologies and how they can be applied within the ASM domain (experience)
  • Familiarity with cybersecurity domains and concepts including the MITRE ATT&CK framework, common attack vectors, vulnerabilities and exposures, defense-in-depth principles, network security controls, and cloud and endpoint exposure risks (experience)
  • Familiarity with cybersecurity domains and concepts including the MITRE ATT&CK framework, common attack vectors, vulnerabilities and exposures, defense-in-depth principles, network security controls, and cloud and endpoint exposure risks (experience)
  • Awareness of best practices for cyber hygiene including patch management, hardening, secure configuration management, and lifecycle management (experience)
  • Awareness of best practices for cyber hygiene including patch management, hardening, secure configuration management, and lifecycle management (experience)
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree. (experience)
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree. (experience)

Responsibilities

  • Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements.
  • Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements.
  • Lead the triage of critical vulnerability findings alongside partner teams and stakeholders to analyze the risk of emergent vulnerabilities and patch releases, coordinating expedited remediation as needed.
  • Lead the triage of critical vulnerability findings alongside partner teams and stakeholders to analyze the risk of emergent vulnerabilities and patch releases, coordinating expedited remediation as needed.
  • Research solutions and mitigations for highest risk vulnerabilities and provide technical guidance to remediation teams.
  • Research solutions and mitigations for highest risk vulnerabilities and provide technical guidance to remediation teams.
  • Engage with cybersecurity community and threat intel sources to stay current on latest vulnerability publications, zero-day exploits, and threat actor activity trends.
  • Engage with cybersecurity community and threat intel sources to stay current on latest vulnerability publications, zero-day exploits, and threat actor activity trends.
  • Assist in mapping Nordstrom's attack surface by supporting reconnaissance activities with network and offensive security teams and monitoring dark web resources for emerging exposures.
  • Assist in mapping Nordstrom's attack surface by supporting reconnaissance activities with network and offensive security teams and monitoring dark web resources for emerging exposures.
  • Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation, and contribute to metrics that measure attack surface risk and remediation progress.
  • Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation, and contribute to metrics that measure attack surface risk and remediation progress.
  • Identify and recommend opportunities to reduce attack surface through improved processes, tooling, or architectural changes.
  • Identify and recommend opportunities to reduce attack surface through improved processes, tooling, or architectural changes.
  • Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities.
  • Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities.
  • Support regulatory and compliance requirements including capturing evidence and artifacts related to vulnerability scanning and reporting for [e.g. PCI]
  • Support regulatory and compliance requirements including capturing evidence and artifacts related to vulnerability scanning and reporting for [e.g. PCI]
  • Contribute to Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks.
  • Contribute to Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks.
  • Monitor, review, and escalate errors in automation of operational processes.
  • Monitor, review, and escalate errors in automation of operational processes.
  • Increase cybersecurity domain depth and breadth by completing trainings, attending industry presentations, and cross-training with peers across Cybersecurity & Privacy and Technology teams.
  • Increase cybersecurity domain depth and breadth by completing trainings, attending industry presentations, and cross-training with peers across Cybersecurity & Privacy and Technology teams.

Benefits

  • general: The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.

Target Your Resume for "Attack Surface Analyst 2 (Hybrid - Seattle)" , Nordstrom

Get personalized recommendations to optimize your resume specifically for Attack Surface Analyst 2 (Hybrid - Seattle). Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Attack Surface Analyst 2 (Hybrid - Seattle)" , Nordstrom

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

GeneralGeneral

Answer 10 quick questions to check your fit for Attack Surface Analyst 2 (Hybrid - Seattle) @ Nordstrom.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.