Principal Security Engineer, Identity and Access Management

Nordstrom

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Seattle, WA
Salary
$191,000–$297,000 / yr
Posted
11 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $244k
$113k most similar roles pay here $317k

This role pays more than 91% of similar roles. Most pay $154,914–$212,000 — the shaded band above. At the midpoint, this role pays about $244k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About Nordstrom

Nordstrom is a leading American luxury department store chain offering a wide selection of clothing, shoes, accessories, and beauty products through its stores, Nordstrom Rack outlets, and online. Industry: Luxury Department Store Retail

Nordstrom currently has 30 open roles on FindRole.

Listed pay typically runs $142,000–$220,500 across 29 roles with salary data.

Most-posted roles

View all roles at Nordstrom

At a glance

TL;DR · Principal Security Engineer, Identity and Access Management

Principal Security Engineer - Identity and Access Management serves within the Cybersecurity & Privacy Organization to drive the architecture, strategy, and evolution of enterprise identity systems. This role focuses on workforce identity, customer identity, privileged access, and the emerging discipline of agentic identity for machine-to-machine and AI agent credentials. The engineer will design solutions across cloud, on-premises, and hybrid environments while establishing standards for authentication, authorization, and directory services. Key responsibilities include developing identity governance frameworks, performing threat modeling, and mentoring engineering teams on identity-first security. The role requires expertise in technologies such as AWS IAM, Azure Entra ID, GCP IAM, OAuth 2.0, OIDC, SAML, SCIM, SPIFFE/SPIRE, and FIDO2/WebAuthn. The position addresses the technical challenge of securing non-human entities and ensuring automated systems operate under least-privilege models within a complex enterprise infrastructure.

What does a Security Engineer earn?

Median $185250 from 84 postings across 39 companies.

See salary data

What you'll do

  • Design and architect enterprise IAM solutions across cloud, on-premises, and hybrid environments including governance, authentication, and directory services.
  • Establish the strategy and technical standards for agentic identity to secure AI agents, bots, and automated systems.
  • Serve as the principal technical advisor to leadership and engineering teams regarding access risk management and emerging threats.
  • Evaluate and integrate advanced technologies such as AI/ML-based analytics, adaptive access controls, and identity orchestration platforms.
  • Conduct threat modeling and architecture reviews for critical business systems to address entitlement creep and non-human access models.
  • Develop enterprise IAM standards and reference architectures aligned with industry protocols like NIST 800-63, OAuth, and OIDC.
  • Mentor engineering teams on identity-first security principles and the governance of machine-to-machine identities.
  • Lead identity-related incident response efforts for credential compromises, privilege escalations, and infrastructure attacks.

What we're looking for

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field is required; a Master's degree is preferred.
  • Candidates must have at least 12 years of experience in information security.
  • Candidates must have at least 5 years of experience in identity and access management (IAM) in a senior or principal technical leadership role.
  • Expertise is required in workforce/customer identity, privileged access management, identity governance, federation, and directory services.
  • Experience is required architecting IAM solutions for cloud-native environments including AWS, Azure Entra ID, and GCP.
  • Knowledge of security standards such as NIST 800-63, OAuth 2.0, OpenID Connect, SAML, SCIM, SPIFFE/SPIRE, and FIDO2/WebAuthn is required.
  • Experience is required with IAM tools including IGA platforms, PAM solutions, CIAM, SSO, and identity threat detection and response (ITDR).
  • Relevant advanced certifications such as CISSP, GIAC, CCSP, or OSCP are required.

More like this

Similar roles

Senior Cybersecurity Engineer, Identity Platform and Access Management

Nvidia

Santa Clara, CA 30 days ago $196,000$310,500
IAM OAuth 2.0 OIDC SAML Zero Trust Identity Governance Privileged Identity Management Conditional Access Directory Services Token Services SDKs Infrastructure Engineering Platform Engineering Security Architecture Federated Identity Device Attestation
10+ yrs exp

Cybersecurity Identity Architect

3M

Maplewood, MN +1 24 days ago $221,591$270,834
IAM SSO MFA Identity Federation IGA SAML OAuth OpenID Connect LDAP Kerberos Azure AD Entra Saviynt CyberArk AWS Azure GCP mTLS SPIFFE SPIRE Zero Trust NIST ISO GDPR HIPAA SOX PCI-DSS
10+ yrs exp

Senior Staff Software Engineer, Identity

eBay

San Jose, CA 7 days ago $217,600$290,500
IAM OAuth 2.0 OpenID Connect SAML 2.0 SCIM FIDO2 WebAuthn Passkeys JWT mTLS RBAC ABAC Zero Trust Distributed Systems Identity Federation SSO Multi-cloud
10+ yrs exp

Software Engineering SMTS, Enterprise IAM

Salesforce

Remote (Bellevue, WA) 46 days ago $148,500$223,900
IAM Identity Governance OAuth 2.0 OpenID Connect SAML SCIM LDAP REST JSON XML Java Go Python React Docker Kubernetes Terraform AWS Azure GCP CI/CD Git Jenkins Prompt Engineering
5+ yrs exp Remote