Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Nordstrom

Attack Surface Analyst 2

Nordstrom

Attack Surface Analyst protecting Nordstrom’s fashion retail technology from cyber vulnerabilities. Managing exposure discovery, vulnerability triage, remediation, and attack surface reduction across cloud and on-premises environments.

Posted 8/13/2026full-timeSeattle • Washington • 🇺🇸 United StatesJuniorMid-Level💰 $121,500 - $188,500 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in vulnerability management, cybersecurity principles, and regulatory compliance, with a strong focus on cloud security across AWS, Azure, and GCP. Proficient in Python and PowerShell for automation, and skilled in analyzing and mitigating risks associated with vulnerabilities.

Highest-signal resume keywords
Vulnerability ManagementCloud Security (AWS, Azure, GCP)Python and PowerShell ProficiencyRegulatory Compliance (PCI)Attack Surface Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability IdentificationNetwork Security ToolsCSPMEmerging AI TechnologiesPatch ManagementSecure Configuration ManagementLifecycle ManagementAsset ManagementCyber Hygiene Best PracticesThreat Actor Activity Monitoring
Soft Skills
CollaborationTechnical GuidanceAnalytical ThinkingCommunicationProblem-Solving
Tools & Technologies
Attack Surface Management ToolsVulnerability Scanning ToolsReporting PlatformsAutomation ToolsDark Web Monitoring Tools
Industry Keywords
CybersecuritySecurity OperationsCompliance ProcessesEmergent VulnerabilitiesZero-Day Exploits

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud PlatformPython

About the role

Key responsibilities & impact
  • Identify, assess, prioritize, and monitor vulnerabilities posing risks to Nordstrom technologies and operations
  • Support discovery and reduction of exposures across cloud, on-premises, and third-party environments
  • Maintain and grow attack surface management tools and reporting platforms
  • Configure and troubleshoot vulnerability scans; develop alerts; review and tune false positives; build reporting templates
  • Lead triage of critical vulnerability findings with partner teams and stakeholders
  • Analyze risks from emergent vulnerabilities and patch releases and coordinate expedited remediation
  • Research solutions and mitigations for high-risk vulnerabilities and provide technical guidance to remediation teams
  • Monitor vulnerability publications, zero-day exploits, and threat actor activity trends
  • Support reconnaissance activities with network and offensive security teams and monitor dark web resources
  • Track attack surface reduction efforts and contribute to risk and remediation metrics
  • Recommend process, tooling, and architectural changes to reduce attack surface
  • Collaborate on asset identification and classification, vulnerability scanning, analysis, and prioritization
  • Support regulatory and compliance requirements by capturing vulnerability scanning and reporting evidence
  • Contribute to cybersecurity standards, standard operating procedures, and runbooks
  • Monitor, review, and escalate automation errors in operational processes
  • Complete training, attend industry presentations, and cross-train with Cybersecurity, Privacy, and Technology teams

Requirements

What you’ll need
  • 2+ years of experience in security operations, vulnerability management, cybersecurity, IT, or related fields
  • Understanding of networking, system administration, cloud services, asset management, and cybersecurity principles
  • Working knowledge of vulnerability identification, CSPM, attack surface/exposure management, and network security tools
  • Understanding of regulatory and compliance processes and controls for vulnerability and attack surface management, including PCI
  • Understanding of multi-cloud security concepts across AWS, Azure, and GCP
  • Experience with cloud asset exposure, including AWS S3 buckets and Azure Blob storage
  • Proficiency in Python and PowerShell for process automation
  • Working knowledge of emerging AI technologies and their application within attack surface management
  • Familiarity with MITRE ATT&CK, common attack vectors, vulnerabilities and exposures, defense-in-depth, network security controls, and cloud and endpoint exposure risks
  • Awareness of cyber hygiene best practices, including patch management, hardening, secure configuration management, and lifecycle management
  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience may be considered in lieu of a degree
  • Must be available to work in the Nordstrom corporate headquarters a minimum of 4 days/week

Benefits

Comp & perks
  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources
  • Performance-based incentives/bonuses may be available
  • 401k
  • PTO accruals
  • Holidays
  • Benefits support employees and their families
  • Training opportunities
  • Industry presentations and cross-training with peers