> Markdown version of [/jobs/ext/733534-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/733534-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Nordstrom, Inc. - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $141,000.0 - $258,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C Sharp (Programming Language), Cloud Engineering, Code Review, Cyber Security, Information Leak Prevention, DevOps, Github, Python (Programming Language), Software Engineering, Google Cloud, Large Language Models, Software Security, Kotlin, GWAPT, Kubernetes, Information Technology, Serverless Computing, Static Application Security Testing, Artifactory, Dynamic Application Security Testing - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=064d0f60e7b7f125 ## About the Role Do you have a Master's degree in cybersecurity?, * 4+ years in application security, secure software development, or a closely related field, with a bachelor's or master's in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent experience * A track record shipping security tooling, automation, or reusable patterns, not just operating off-the-shelf tools * Expert-level threat modeling, security design review, and manual code review, with deep knowledge of application and API vulnerability classes and how to design them out * Fluent enough to read and write code in languages like Java, Kotlin, C#, or Python * Hands-on fluency using AI to accelerate real security work, with judgment about where to trust it and where to verify * Working knowledge of how LLM and agent features fail, including prompt injection, unsafe tool and permission use, and data leakage through model outputs * Cloud-native, container, and serverless security (AWS, GCP, Azure, Kubernetes) Nice to Have * Hands-on with GitHub Advanced Security and JFrog Artifactory, or similar * Offensive security experience * Vulnerability disclosure or bug bounty program experience * Production software engineering background * Certifications such as CSSLP, CISSP, OSWA, OSWE, GWAPT, or GMOB ## Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn't have to choose between moving fast and shipping securely. As one of the first hires, you'll build the tooling and secure defaults that protect our web, mobile, and API ecosystem, do the deep work tooling can't, and help shape how we build with AI. You'll report to the Senior Manager of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack surface management, and platform. A Day in the Life * Build secure-by-default patterns and paved-road tooling so teams get security built into the pipelines and frameworks they already use * Own the AppSec tooling stack (SAST, SCA, secrets scanning, DAST), tune it for signal over noise, and route findings into where engineers already work * Automate the security work that doesn't need human judgment, and save manual review for the work that does * Partner with our security teams, mentor engineers and champions, and raise the application security bar across the org More About You * You'd rather build the guardrail than write the policy, and you've shipped tooling that changed how other engineers work * You go looking for the problems worth solving and own them end to end * You're the security person other teams want in the room, because you explain risk clearly, respect how teams work, and help them find a fix that fits * You think in risk, not severity scores. You know the difference between a finding that's exploitable in our context and one that just looks scary, and you prioritize accordingly ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Why Kotlin is the better Java and how you can start using it](https://www.wearedevelopers.com/videos/661-why-kotlin-is-the-better-java-and-how-you-can-start-using-it) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)