Senior Application Security Engineer

Nordstrom

Quick summary

Work type
On-site
Location
Seattle, WA
Salary
$141,000–$258,000 / yr
Posted
3 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $180k
This role $200k
$120k most similar roles pay here $273k

This role pays more than 69% of similar roles. Most pay $152,150–$206,900 — the shaded band above. At the midpoint, this role pays about $200k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About Nordstrom

Nordstrom is a leading American luxury department store chain offering a wide selection of clothing, shoes, accessories, and beauty products through its stores, Nordstrom Rack outlets, and online. Industry: Luxury Department Store Retail

Nordstrom currently has 37 open roles on FindRole.

Listed pay typically runs $142,000–$258,000 across 37 roles with salary data.

Most-posted roles

View all roles at Nordstrom

At a glance

TL;DR · Senior Application Security Engineer

As a Senior Application Security Engineer at Nordstrom, you will join the newly established Application Security team and work closely with product engineering and DevOps to build secure-by-default patterns and tooling for web, mobile, and API ecosystems. Your responsibilities include owning the AppSec tool stack (SAST, SCA, secrets scanning, DAST), automating security tasks, and partnering with other security teams to mentor engineers and raise the application security bar across the organization. Ideal candidates have 4+ years of experience in application security or a related field, expertise in threat modeling and manual code review, and hands-on fluency using AI for real security work. Proficiency in languages like Java, Kotlin, C#, or Python is required, along with knowledge of cloud-native, container, and serverless security practices.

What you'll do

  • Build secure-by-default patterns and tooling for teams to integrate into their pipelines.
  • Own and optimize the application security tool stack for minimal noise and maximum signal.
  • Automate routine security tasks, reserving manual review for complex issues requiring judgment.
  • Mentor engineers and collaborate with other security teams to enhance overall app security.
  • Use AI effectively in security work while maintaining critical judgment on verification needs.

What we're looking for

  • 4+ years of experience in application security or secure software development.
  • Expertise in threat modeling, security design review, and manual code review.
  • Proficiency in programming languages such as Java, Kotlin, C#, or Python.
  • Hands-on experience with cloud-native, container, and serverless security.
  • Fluency using AI for security work with judgment on trustworthiness.
  • Knowledge of how large language models (LLM) and agents can fail.

More like this

Similar roles

Application Security Engineer

Opendoor

Miami, FL 10 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes Apollo GraphQL GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF CI/CD GraphQL REST gRPC OAuth JWT Docker Linux JSON Web Tokens OAuth2 OAuth 2.0
Hybrid

Application Security Engineer

Opendoor

Miami, FL 10 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes Apollo GraphQL GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF CI/CD GraphQL REST gRPC OAuth JWT Docker Linux SQL PostgreSQL Redis MongoDB JSON Web Tokens OAuth 2.0 OpenID Connect Kerberos SAML LDAP ZAP OWASP Top Ten Threat Modeling Cloud Security Secrets Management Mobile Application Security AI Security
Hybrid

Application Security Engineer

Opendoor

Toronto, Canada 10 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes Apollo GraphQL GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI MCP CI/CD GraphQL REST gRPC
Hybrid

Senior Security Engineer

Chime

New York, NY +1 25 days ago
Python Go Ruby AWS GCP Terraform CI/CD APIs Cloud Infrastructure Penetration Testing Threat Modeling SDLC Automation Vulnerability Management Mobile Security(iOS/Android) AI GRC_tools_and_frameworks
Hybrid

Senior Application Security Engineer

Hippo

Austin, TX +1 68 days ago
Python Java OAuth2 OIDC SAML JWT MFA Kubernetes Terraform AWS CI/CD Docker PostgreSQL SAST DAST SCA Prometheus Grafana
Hybrid

Senior Application Security Engineer

Hippo

San Jose, CA +1 68 days ago $151,000$226,250
OAuth2 OIDC SAML JWT MFA CI/CD Kubernetes SAST DAST SCA Python PostgreSQL AWS Azure GitHub Swagger RESTful APIs JSON Web Tokens OWASP Top 10 DevSecOps
Hybrid