Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Nordstrom

Attack Surface Analyst 2

Nordstrom

. Maintain and grow attack surface management tools and reporting platforms .

Posted 10/7/2026full-timeSeattle • Washington • United StatesJuniorMid-Level💰 $121,500 - $188,500 per yearWebsite

Tech Stack

Tools & technologies
AssemblyAWSAzureCloudCyber SecurityGoogle Cloud PlatformPython

About the role

Key responsibilities & impact
  • Maintain and grow attack surface management tools and reporting platforms
  • Configure and troubleshoot vulnerability scans
  • Develop alerts, review and tune false positives, and build reporting templates
  • Lead triage of critical vulnerability findings with partner teams and stakeholders
  • Analyze risks from emergent vulnerabilities and patch releases and coordinate expedited remediation
  • Research mitigations for high-risk vulnerabilities and provide technical guidance to remediation teams
  • Monitor vulnerability publications, zero-day exploits, and threat actor activity trends
  • Support reconnaissance activities with network and offensive security teams
  • Monitor dark web resources for emerging exposures
  • Track attack surface reduction efforts and contribute to risk and remediation metrics
  • Recommend process, tooling, and architectural changes to reduce attack surface
  • Collaborate on asset identification and classification, vulnerability scanning, analysis, and prioritization
  • Support regulatory and compliance requirements by capturing evidence and artifacts
  • Contribute to cybersecurity standards, operating procedures, and runbooks
  • Monitor, review, and escalate automation errors
  • Complete training, attend industry presentations, and cross-train with cybersecurity, privacy, and technology teams

Requirements

What you’ll need
  • 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields
  • Understanding of networking, system administration, cloud services, asset management and cybersecurity principles
  • Working knowledge of vulnerability identification, cloud security posture management (CSPM), attack surface/exposure management platforms, and network security tools
  • Understanding of regulatory and compliance processes and controls for vulnerability and attack surface management, e.g. PCI
  • Understanding of multi-cloud security concepts across AWS, Azure, and GCP
  • Knowledge of AWS S3 buckets and Azure Blob storage exposure
  • Proficiency in Python and PowerShell for process automation
  • Working knowledge of emerging AI technologies and application within the ASM domain
  • Familiarity with MITRE ATT&CK, common attack vectors, vulnerabilities and exposures, defense-in-depth, network security controls, and cloud and endpoint exposure risks
  • Awareness of cyber hygiene best practices including patch management, hardening, secure configuration management, and lifecycle management
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree
  • Candidates must be available to work in office at Nordstrom corporate headquarters a minimum of 4 days/week

Benefits

Comp & perks
  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources
  • Performance-based incentives/bonuses may be available
  • 401k
  • PTO accruals
  • Holidays