Senior Cybersecurity Analyst, Attack Surface Management

Nordstrom

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Seattle, WA
Salary
$166,000–$258,000 / yr
Posted
10 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $153k
This role $212k
$101k most similar roles pay here $275k

This role pays more than 89% of similar roles. Most pay $123,787–$181,250 — the shaded band above. At the midpoint, this role pays about $212k versus about $153k for comparable roles.

Based on 240 similar postings.

Employer

About Nordstrom

Nordstrom is a leading American luxury department store chain offering a wide selection of clothing, shoes, accessories, and beauty products through its stores, Nordstrom Rack outlets, and online. Industry: Luxury Department Store Retail

Nordstrom currently has 33 open roles on FindRole.

Listed pay typically runs $142,000–$220,500 across 32 roles with salary data.

Most-posted roles

View all roles at Nordstrom

At a glance

TL;DR · Senior Cybersecurity Analyst, Attack Surface Management

Senior 2 Cybersecurity Analyst - Attack Surface Management serves as a senior leader on the Attack Surface Management team focused on reducing risk by identifying and assessing high-risk exposures. The role involves developing new capabilities, automating processes, maintaining standard operating procedures, and collaborating with AppSec, DevOps, and cloud platform teams to ensure secure-by-design systems. You will manage an attack surface map through reconnaissance, dark web monitoring, and regular assessments while leading data-driven initiatives to mitigate vulnerabilities. Required skills include expertise in Python and PowerShell for automation, deep knowledge of the MITRE ATT&CK framework, and experience with multi-cloud security controls. The role addresses the technical challenge of securing a complex technology landscape by managing infrastructure risks, ensuring PCI compliance, and implementing advanced cybersecurity principles across various enterprise systems to proactively defend against common attack vectors.

What you'll do

  • Identify, assess, and escalate high-risk exposures to reduce the organization's attack surface.
  • Develop and implement solutions to improve visibility into security vulnerabilities and infrastructure risks.
  • Automate manual processes and tools to enhance operational efficiency in attack surface management.
  • Maintain comprehensive maps of the attack surface using reconnaissance, network data, and dark web monitoring.
  • Lead data-driven initiatives to prioritize and remediate vulnerabilities across enterprise technologies.
  • Collaborate with engineering teams to integrate security best practices into software and cloud deployments.
  • Manage compliance activities including evidence validation and mitigation of gaps for standards like PCI.
  • Develop metrics to measure the effectiveness of attack surface management programs and risk reduction.

What we're looking for

  • 6+ years in security operations, vulnerability management, or offensive security domains, including experience in a senior or lead capacity.
  • Deep knowledge of the MITRE ATT&CK framework, threat actor TTPs, and common attack vectors.
  • Experience implementing cloud security controls in a multi-cloud environment.
  • Proficiency in scripting languages like Python or PowerShell for process automation.
  • Advanced knowledge of networking, system administration, cloud services, asset management, and cybersecurity principles.
  • Deep understanding of processes and controls to satisfy regulatory requirements such as PCI.
  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or a related field (equivalent experience accepted).
  • Experience developing attack surface management capabilities, coaching junior analysts, and advanced certifications like OSCE, GREM, or CISSP (preferred); AI thought leadership (preferred).

More like this

Similar roles

Attack Surface Analyst II

Nordstrom

Seattle, WA 39 days ago $121,500$188,500
Vulnerability Management Attack Surface Management CSPM Python PowerShell AWS Azure GCP PCI Network Security Patch Management Cloud Security Scripting Cyber Hygiene
2+ yrs exp Hybrid

Senior Cybersecurity Analyst, OT Compliance

Marathon Petroleum

Findlay, OH +2 12 days ago $106,900$184,300
OT Cybersecurity Risk Management SIEM Vulnerability Management Penetration Testing Identity Access Management Security Governance Threat Hunting Forensics Web Application Scanning Asset Inventory Information Technology Operational Technology
5+ yrs exp

AI Attack Surface and Threat Exposure Management Consulting Director

CNA Financial

Chicago, IL 49 days ago $97,000$189,000
AI GenAI LLM Agentic AI Application Security Vulnerability Management Ethical Hacking Attack Surface Management Cloud Security Threat Modeling Red Teaming Penetration Testing Scripting Automation Risk Management
10+ yrs exp Hybrid

Threat Exposure Management Analyst

Fiserv

Berkeley Heights, NJ +2 6 days ago $110,000$186,000
Attack Surface Management Vulnerability Management MITRE ATT&CK CVSS EPSS CISA KEV breach-and-attack simulation Offensive Security Penetration Testing Threat Intelligence SaaS CTEM
8+ yrs exp

Senior Technical Program Manager, Security Platform Engineering

Nordstrom

Seattle, WA 49 days ago $142,000$220,500
Endpoint Detection Email Security Data Encryption Network Security Compliance Engineering Security Assessment OKRs KPIs Jira Confluence Sprint Cadence Roadmap Tracking Program Management Infrastructure Platform Engineering
6+ yrs exp Hybrid

Senior Cybersecurity Analyst

Visa

Ashburn, VA 7 days ago $131,600$210,300
Incident Response Threat Hunting Malware Analysis Web Application Security SIEM WAF IDS Netflow Packet Analysis TCP/IP Windows Linux SQL Injection Cross-Site Scripting Cross-Site Request Forgery
5+ yrs exp Hybrid