> Markdown version of [/jobs/ext/1928717-cybersecurity-analyst-attack-surface-management](https://www.wearedevelopers.com/jobs/ext/1928717-cybersecurity-analyst-attack-surface-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - Attack Surface Management - **Company:** Nordstrom, Inc. - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $166,000.0 - $258,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, DevOps, Python (Programming Language), Network Security, Windows PowerShell, Cloud Services, Data Streaming, Software Vulnerability Management, Scripting, Cloud Platform System, Software Security, Mitre Att&ck, Multi-Cloud, Information Technology, Data Analytics, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.dice.com/job-detail/bef9a9ee-c25a-416b-affb-432acd9e43e7 ## About the Role Required * 6+ years in security operations, vulnerability management, or offensive security domains, including experience in a senior or lead capacity. * Deep knowledge of the MITRE ATT&CK framework, threat actor tactics, techniques, and procedures (TTPs), and common attack vectors. * Experience implementing cloud security controls in a multi-cloud environment. * Proficiency in enterprise information technology (IT) architecture principles and practices. * Knowledge of offensive security methodologies and ethical hacking principles and practices. * Deep understanding of system landscape and data flow within the domain and across adjacent domains. * Expertise in scripting languages (e.g., Python, PowerShell) for process automation. * Advanced knowledge of networking, system administration, cloud services, asset management, and cybersecurity principles. * Deep understanding of the processes and controls needed to satisfy relevant regulatory and compliance requirements (e.g., PCI) for vulnerability and attack surface management. * Strong leadership and communication skills. * Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree. Preferred * Experience developing attack surface management capabilities and coaching more junior analysts. * Expertise across cybersecurity domains including vulnerability management, cloud security, attack surface management, network security, and cyber hygiene. * Demonstrated thought leadership on the application of emerging AI technologies within cybersecurity domains. * Advanced certifications (e.g., OSCE, GREM, CISSP). ## Description The Senior Attack Surface Analyst champions reduction of Nordstrom's attack surface through continuous identification, assessment, and escalation of the highest-risk exposures, along with the actions needed to manage that risk. As a senior leader on the Attack Surface Management team, this role collaborates closely with cybersecurity and technology partner teams to prioritize risk, execute remediation activities, and automate processes that secure the technology landscape., * Lead the growth of the attack surface management program, develop and implement solutions to improve visibility into exposures, and contribute to the design and implementation of net-new capabilities. * Continuously drive improvements in attack surface management processes, methodologies, and security toolsets to enhance operational effectiveness, automating where possible. * Maintain Cybersecurity Standards, Attack Surface Management standard operating procedures, and runbooks. * Collaborate with AppSec, DevOps, and cloud platform teams to secure deployments and integrate security best practices into the design of software and related systems, ensuring a secure-by-design approach. * Maintain a map of Nordstrom's attack surface through collaboration with network and offensive security teams, conducting regular assessments and reconnaissance activities, and leveraging dark web monitoring resources. * Lead data-driven, risk-prioritized, enterprise-wide initiatives to reduce vulnerabilities and exposures across Nordstrom's technologies; identify opportunities and champion architectural changes that reduce attack surface. * Develop and present metrics to measure operational efficiency and attack surface risk. * Maintain domain expertise by completing trainings, attending industry presentations, obtaining certifications, engaging with the cybersecurity community, and consuming threat intelligence sources. * Support the growth of teammates' domain expertise through mentorship, presentations, and knowledge-sharing sessions. * Lead compliance activities for the domain, including evidence validation and submission, proactive control evaluation and mitigation of gaps, and assessments (e.g., PCI). ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)