> Markdown version of [/jobs/ext/562626-principal-engineer-cybersecurity-hybrid](https://www.wearedevelopers.com/jobs/ext/562626-principal-engineer-cybersecurity-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer - Cybersecurity (Hybrid - **Company:** Nordstrom, Inc. - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $200,500.0 - $332,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cyber Security, Python (Programming Language), Zero Trust Network Access, Azure Machine Learning, Sherwood Applied Business Security Architecture, Security Information and Event Management, Google Cloud, Cloud Platform System, Istio, Large Language Models, Multi-Cloud, Cloudformation, Togaf, Kubernetes, Information Technology, Terraform, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Golang - **Published:** June 15, 2026 - **Apply:** https://www.dice.com/job-detail/cfd2d7f0-e163-4821-9650-4344762ed3a2 ## About the Role * 12+ years in cybersecurity with 5+ years leading enterprise-level security architecture initiatives * Demonstrated track record of defining security strategy that influenced organizational direction at Fortune 500 or equivalent scale * Proven ability to drive consensus and adoption of security standards across diverse technical and business stakeholders * History of mentoring senior technical talent and elevating organizational security capabilities * Bachelor's Degree in Information Technology, Computer Science, Cybersecurity or related field; Master's Degree strongly preferred Preferred Qualifications * Published thought leadership (patents, peer-reviewed publications, industry presentations) in platform security * Experience advising C-suite or Board of Directors on technology security strategy * Track record of influencing industry standards or vendor security capabilities * Experience in regulated retail, financial services, or similarly complex enterprise environments Technical Expertise: Strategic Technologies * Enterprise security architecture frameworks (SABSA, O-ESA, TOGAF) * Advanced threat modeling and risk quantification methodologies * Zero Trust architecture at enterprise scale * Security for AI/ML * DevSecOps and platform engineering security patterns Platforms & Tools * Enterprise SIEM/SOAR/XDR platforms and custom security automation at scale * Multi-cloud security architecture (AWS, Azure, Google Cloud Platform) with hybrid considerations * Container orchestration security (Kubernetes, service mesh, serverless) * AI/ML platforms, LLMs, and emerging technology stacks * Infrastructure as Code security (Terraform, CloudFormation, security policy as code) Languages & Automation * Python, Go, Java for security automation and tooling * Security domain-specific languages and frameworks Leadership Competencies: Core Leadership Skills * Strategic Mindset - Defines multi-year vision with organizational impact * Drives Vision - Inspires adoption of security principles across the enterprise * Decision Quality - Makes high-stakes architectural decisions with incomplete information * Influences & Communicates - Shapes thinking of senior leadership and technical experts alike * Builds Trust - Establishes credibility as the organization's platform security authority Organizational Impact * Develops People - Elevates capability of senior technical staff and future leaders * Builds Teams - Fosters collaboration across organizational boundaries * Manages Complexity - Navigates ambiguous, cross-functional security challenges * Drives Results - Delivers transformational security outcomes with measurable business impact * Has Courage - Makes principled security recommendations even when facing organizational resistance ## Description Strategic Leadership & Vision * Define and evangelize the long-term platform security vision aligned with enterprise technology strategy and business objectives * Establish organization-wide platform security principles, standards, and governance frameworks that influence technology decisions at the highest levels * Drive Executive level platform security strategy discussions, translating complex technical security concepts into business risk and opportunity * Lead cross-functional security transformation initiatives that fundamentally reshape how Nordstrom approaches platform security Enterprise Architecture & Innovation * Architect enterprise-wide security solutions for emerging and disruptive technologies (genAI, edge computing, decentralized systems) * Develop comprehensive reference architectures and security patterns that become organizational standards across all technology domains * Pioneer innovative security approaches that position Nordstrom as an industry leader in platform security practices * Influence vendor roadmaps and industry standards through thought leadership and strategic partnerships Risk & Business Impact * Quantify and communicate platform security investments in terms of business risk reduction, revenue protection, and competitive advantage * Develop sophisticated security measurement frameworks that demonstrate clear ROI and business value to executive leadership * Lead security risk modeling for enterprise-critical platform decisions with multi-million dollar business implications * Balance security requirements with business velocity, establishing practical risk-based approaches for the organization Organization & Talent Development * Mentor Principal Engineers, Architects, and senior technical leaders across cybersecurity and technology organizations * Build and elevate platform security engineering capability across Nordstrom through advisory, coaching, and knowledge sharing * Represent Nordstrom externally through speaking engagements, publications, and industry collaboration * Influence hiring strategies and organizational design for platform security capabilities Example Projects or Deliverables * Enterprise security architecture strategy for quantum-ready cryptographic transitions across all platforms * Organization-wide security frameworks for responsible AI deployment with integrated risk management * Multi-year platform security roadmap with business case justification * Industry-recognized thought leadership (conference presentations, whitepapers, patents) on emerging platform security challenges * Cross-industry collaboration initiatives establishing platform security standards or best practices ## Related Videos - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)