yoinka

Attack Surface Analyst 2 (Hybrid - Seattle)

Nordstrom

RemoteSeattle, WAMidH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Seattle, WA
Work model
Hybrid
Level
Mid
H-1B history
74 approvals (FY2023)
Posted
Aug 13, 2026

Skills

AWSAzureCybersecurityGCPPython

About this role

Job Description

This role is offered as  hybrid  in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.

Position

Summary     As an Attack Surface Analyst II, you will identify , assess, prioritize and monitor vulnerabilities that pose a risk to Nordstrom’s technologies and operations. This role will support the discovery and reduction of exposures across cloud, on-prem, and third-party environments and  identifying  opportunities to improve cyber hygiene processes to proactively reduce the attack surface.

Key Responsibilities

Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements.     Lead the triage of critical vulnerability findings alongside partner teams and stakeholders to analyze the risk of emergent vulnerabilities and patch releases, coordinating expedited remediation as needed.      Research solutions and mitigations for highest risk vulnerabilities and provide technical guidance to remediation teams.     Engage with cybersecurity community and threat intel sources to stay current on latest vulnerability publications, zero-day exploits, and threat actor activity trends.   Assist in mapping Nordstrom's attack surface by supporting reconnaissance activities with network and offensive security teams and monitoring dark web resources for emerging exposures.       Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation , and contribute to metrics that measure attack surface risk and remediation progress.   Identify and recommend opportunities to reduce attack surface through improved processes, tooling, or architectural changes .          Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities.   Support regulatory and compliance requirements including capturing evidence and artifacts related to vulnerability scanning and reporting for [ e.g. PCI]     Contribute to Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks.      Monitor, review, and escalate errors in automation of operational processes.      Increase cybersecurity domain depth and breadth by completing  trainings , attending industry presentations, and cross-training with peers across Cybersecurity & Privacy and Technology teams.

Qualifications

2+ years in security operations, vulnerability management,  cybersecurity, IT, or related fields.     Understanding of networking, system administration, cloud services, asset management and cyber security principles.     Working knowledge of cybersecurity tools including vulnerability identification, cloud security posture management (CSPM) , attack surface / exposure management  platforms ,  network security tools     Understanding of processes and controls needed to satisfy relevant regulatory and compliance requirements [ e.g. PCI] for vulnerability and attack surface management.      Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP), Cloud Asset Exposure: AWS S3 buckets, Azure Blob storage     Proficiency in scripting languages (Python, PowerShell) for process automation      Working knowledge of emerging AI technologies and how they can be applied within the ASM domain     Familiarity with cybersecurity domains and concepts including th e MITRE ATT&CK framework, common attack vectors, vulnerabilities and exposures, defense-in-depth

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Attack Surface Analyst 2 (Hybrid - Seattle) at Nordstrom, Seattle, WA | Yoinka