Lead Security Assessment Engineer

Nordstrom, Inc.
Los Angeles, CA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$166,000.0 - $258,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Applications Architecture Cloud Engineering Software Engineering Software Vulnerability Management Software Security Information Technology

Job description

The Lead Security Assessment Engineer will play a critical role in evaluating the security posture of applications developed across all areas of the technology organization, including those sourced from external vendors. This role is designed for a seasoned security professional who can lead comprehensive assessments, identify risks, and recommend mitigation strategies. This role requires a forward-thinking approach to security assessments, incorporating AI to improve speed, accuracy, and scalability. The goal is to reduce manual effort and enhance the effectiveness of security evaluations across a diverse application landscape., * Conduct security assessments of internally developed and third-party applications across the enterprise.

  • Collaborate with engineering, product, and vendor teams to understand application architecture and identify potential security risks.
  • Develop and maintain standardized assessment frameworks and methodologies tailored to various application types and deployment models.
  • Develop AI tools and techniques to automate and streamline security assessments, including compliance and policy enforcement, threat modeling, and supply chain security evaluation.
  • Document findings and provide actionable recommendations to improve application security posture.
  • Track remediation efforts and validate fixes to ensure risk reduction.
  • Contribute to the development of secure design patterns and reusable security components.
  • Stay current with emerging threats, vulnerabilities, and AI-driven security innovations.

Requirements

  • Bachelor’s or master’s degree in computer science, cybersecurity, or a related field or equivalent experience required.
  • 8+ years of experience in cybersecurity, including hands-on assessment and remediation.
  • Strong understanding of secure software development practices, threat modeling, and vulnerability management.
  • Experience with security assessment tools and platforms, including AI-enhanced solutions.
  • Familiarity with cloud-native architectures, APIs, and modern development frameworks.
  • Excellent communication skills and ability to influence cross-functional teams.
  • Certifications such as CISSP, OSCP, or CSSLP are a plus.

Benefits & conditions

The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience. $166,000.00 - $258,000.00 Annual

We’ve got you covered…

Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources

This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: _Overview_17-19.pdf

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:23 min

Closing thoughts and educational resources for edge network engineering

Austin Gil · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

1:22 min

Understanding software engineering as more than just coding

Lilia Gargouri Lilia Gargouri · WWC Europe 2026

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:29 min

Recommended community resources for cloud engineers

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all