> Markdown version of [/jobs/ext/672772-lead-security-assessment-engineer](https://www.wearedevelopers.com/jobs/ext/672772-lead-security-assessment-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Assessment Engineer - **Company:** Nordstrom, Inc. - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $166,000.0 - $258,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Applications Architecture, Cloud Engineering, Software Engineering, Software Vulnerability Management, Software Security, Information Technology - **Published:** June 27, 2026 - **Apply:** https://www.dice.com/job-detail/07638a24-0dad-4a24-a404-cdd70c42bb04 ## About the Role * Bachelor's or master's degree in computer science, cybersecurity, or a related field or equivalent experience required. * 8+ years of experience in cybersecurity, including hands-on assessment and remediation. * Strong understanding of secure software development practices, threat modeling, and vulnerability management. * Experience with security assessment tools and platforms, including AI-enhanced solutions. * Familiarity with cloud-native architectures, APIs, and modern development frameworks. * Excellent communication skills and ability to influence cross-functional teams. * Certifications such as CISSP, OSCP, or CSSLP are a plus. ## Description The Lead Security Assessment Engineer will play a critical role in evaluating the security posture of applications developed across all areas of the technology organization, including those sourced from external vendors. This role is designed for a seasoned security professional who can lead comprehensive assessments, identify risks, and recommend mitigation strategies. This role requires a forward-thinking approach to security assessments, incorporating AI to improve speed, accuracy, and scalability. The goal is to reduce manual effort and enhance the effectiveness of security evaluations across a diverse application landscape., * Conduct security assessments of internally developed and third-party applications across the enterprise. * Collaborate with engineering, product, and vendor teams to understand application architecture and identify potential security risks. * Develop and maintain standardized assessment frameworks and methodologies tailored to various application types and deployment models. * Develop AI tools and techniques to automate and streamline security assessments, including compliance and policy enforcement, threat modeling, and supply chain security evaluation. * Document findings and provide actionable recommendations to improve application security posture. * Track remediation efforts and validate fixes to ensure risk reduction. * Contribute to the development of secure design patterns and reusable security components. * Stay current with emerging threats, vulnerabilities, and AI-driven security innovations. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)