FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAssemblyAWSAzureCloudCyber SecurityGoogle Cloud PlatformPython
About the role
Key responsibilities & impact- Maintain and grow attack surface management tools and reporting platforms
- Configure and troubleshoot vulnerability scans
- Develop alerts, review and tune false positives, and build reporting templates
- Lead triage of critical vulnerability findings with partner teams and stakeholders
- Analyze risks from emergent vulnerabilities and patch releases and coordinate expedited remediation
- Research mitigations for high-risk vulnerabilities and provide technical guidance to remediation teams
- Monitor vulnerability publications, zero-day exploits, and threat actor activity trends
- Support reconnaissance activities with network and offensive security teams
- Monitor dark web resources for emerging exposures
- Track attack surface reduction efforts and contribute to risk and remediation metrics
- Recommend process, tooling, and architectural changes to reduce attack surface
- Collaborate on asset identification and classification, vulnerability scanning, analysis, and prioritization
- Support regulatory and compliance requirements by capturing evidence and artifacts
- Contribute to cybersecurity standards, operating procedures, and runbooks
- Monitor, review, and escalate automation errors
- Complete training, attend industry presentations, and cross-train with cybersecurity, privacy, and technology teams
Requirements
What you’ll need- 2+ years in security operations, vulnerability management, cybersecurity, IT, or related fields
- Understanding of networking, system administration, cloud services, asset management and cybersecurity principles
- Working knowledge of vulnerability identification, cloud security posture management (CSPM), attack surface/exposure management platforms, and network security tools
- Understanding of regulatory and compliance processes and controls for vulnerability and attack surface management, e.g. PCI
- Understanding of multi-cloud security concepts across AWS, Azure, and GCP
- Knowledge of AWS S3 buckets and Azure Blob storage exposure
- Proficiency in Python and PowerShell for process automation
- Working knowledge of emerging AI technologies and application within the ASM domain
- Familiarity with MITRE ATT&CK, common attack vectors, vulnerabilities and exposures, defense-in-depth, network security controls, and cloud and endpoint exposure risks
- Awareness of cyber hygiene best practices including patch management, hardening, secure configuration management, and lifecycle management
- Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree
- Candidates must be available to work in office at Nordstrom corporate headquarters a minimum of 4 days/week
Benefits
Comp & perks- Medical/Vision, Dental, Retirement and Paid Time Away
- Life Insurance and Disability
- Merchandise Discount and EAP Resources
- Performance-based incentives/bonuses may be available
- 401k
- PTO accruals
- Holidays
