> Markdown version of [/jobs/ext/1972047-sr-network-security-engineer-hybrid-seattle](https://www.wearedevelopers.com/jobs/ext/1972047-sr-network-security-engineer-hybrid-seattle). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Network Security Engineer (Hybrid - Seattle,... - **Company:** Nordstrom, Inc. - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $142,000.0 - $220,500.0 - **Contract:** Permanent contract - **Skills:** IEEE 802.1X, Access Network, Amazon Web Services, User Authentication, Microsoft Azure, Border Gateway Protocol, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Networks, DDoS Mitigation, Domain Name System (DNS), Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), Network Security, Network Layer, Routing, OAuth, Public Key Infrastructure, Ansible, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, TCP/IP, Virtual Local Area Networks, Wide Area Networks, SSL Certificate Management, Identity Services Engine, Google Cloud, Cloud Platform System, Istio, Delivery Pipeline, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Juniper, Information Technology, Palo Alto Networks, Terraform, Oracle Cloud Infrastructure, Splunk, New Relic (SaaS), Data Pipelines - **Published:** August 7, 2026 - **Apply:** https://www.juju.com/job/00000000glylzq ## About the Role + You approach every problem with an automation-first mindset - if you're doing something twice, you're already writing the script + You understand the network well enough to implement security without needing a network engineer in the room - you can read a routing table, troubleshoot a VLAN, and reason about traffic flows + You've operated security in cloud environments and understand how AWS Security Groups, Azure NSGs, cloud NGFW, and service mesh fit into a layered defense model + Authentication and authorization are not just checkboxes to you - you have strong opinions about certificate lifecycles, EAP methods, and identity-aware policy enforcement + You communicate clearly with both engineers and executives, translating complex security posture into business risk + You thrive in ambiguity, work with urgency during incidents, and bring calm, structured thinking under pressure + Passionate about continuous improvement and raising the security bar across teams you work with Qualifications + Bachelor's or master's degree in Computer Science, Engineering, Cybersecurity, or equivalent education and experience + 7+ years of progressive enterprise security engineering experience with demonstrated depth in network security domains + Hands-on experience with cloud security architecture across two or more major cloud platforms (AWS, Azure, GCP, OCI) - including cloud NGFW, VPC security controls, and private connectivity patterns + Strong automation and IaC experience: Python, Terraform, Ansible, or equivalent - you write production-grade automation, not one-off scripts + Deep expertise in network security technologies: next-gen firewalls (Palo Alto), ZTNA/SWG (Zscaler), IDS/IPS, and DDoS mitigation + Strong working knowledge of authentication and authorization: 802.1X, EAP-TLS, RADIUS, ClearPass/ISE, SAML, OAuth, and PKI/certificate management + Solid foundational network knowledge: TCP/IP, BGP, SD-WAN concepts, VLAN segmentation, DNS, and routing protocols - enough to own security outcomes independently + Experience with security policy-as-code, CI/CD pipelines for network security changes, and GitOps workflows + Effective written and verbal communication; able to produce clear RCAs, architecture docs, and executive summaries Nice to Have + Experience with Versa SD-WAN security policy, Juniper Mist access policy, or Fastly/edge security controls + Familiarity with SIEM platforms, SOAR workflows, or security data pipelines (e.g., New Relic, Splunk) + Relevant certifications: PCNSE, CCNP Security, AWS/Azure Security Specialty, CISSP, or equivalent + Retail or high-velocity e-commerce security experience ## Description Are you passionate about securing the infrastructure that powers one of retail's most iconic brands? Nordstrom is on a journey to modernize and fortify the systems that connect our employees, partners, and customers across 400+ locations and multi-cloud environments. To support that mission, we are hiring a Senior Network Security Engineer to join our NIO organization. You will be part of a team of highly skilled security and infrastructure professionals responsible for designing, operating, and automating the network security controls that protect Nordstrom's enterprise. The ideal candidate thinks in automation first, understands how networks actually work, and brings deep expertise in cloud security, identity, and access. You will partner closely with engineers, architects, and platform teams to execute on both strategic and day-to-day security goals. A Day in the Life + Design, deploy, and operate network security controls across enterprise, cloud (AWS, Azure, GCP), and retail edge environments + Implement and maintain zero-trust network access (ZTNA) policies, microsegmentation, and perimeter security using tools like Zscaler, Palo Alto Networks, and cloud-native NGFWs + Build and maintain automation pipelines for security policy management, firewall rule lifecycle, and compliance validation - treating infrastructure as code + Collaborate with cloud, platform, and application teams to integrate security at the network layer without blocking delivery velocity + Serve as a subject matter expert for authentication and authorization frameworks: 802.1X, EAP-TLS, RADIUS/ClearPass, certificate management, and IAM integrations + Monitor, triage, and respond to network security events; drive root cause analysis and long-term remediation + Author engineering documentation, threat models, and security runbooks; contribute to architecture reviews + Mentor engineers across the NIO organization on security best practices and automation patterns ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)