Job DescriptionThis role is offered ashybridin Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.
As an Attack Surface Analyst II, you will identify, assess, prioritize and monitor vulnerabilities that pose a risk to Nordstrom27s technologies and operations. This role will support the discovery and reduction of exposures across cloud, on-prem, and third-party environments andidentifyingopportunities to improve cyber hygiene processes to proactively reduce the attack surface.
Maintain and grow attack surface management tools and reporting platforms by configuring and troubleshooting vulnerability scans, developing alerts, reviewing and tuning false positives, and building reporting templates to meet customer requirements.
Identify and track the status of attack surface reduction efforts, by analyzing vulnerabilities and exposure, potential impact, and likelihood of exploitation, and contribute to metrics that measure attack surface risk and remediation progress.
Collaborate with cybersecurity peers, technology partner teams and other stakeholder groups to conduct asset identification and classification, vulnerability scanning, analysis, and prioritization activities.
2+ years in security operations, vulnerability management,cybersecurity, IT, or related fields.
Understanding of networking, system administration, cloud services, asset management and cyber security principles.
Working knowledge of cybersecurity tools including vulnerability identification, cloud security posture management (CSPM), attack surface / exposure managementplatforms,network security tools
Understanding of cloud security concepts for multi-cloud environments (AWS, Azure, GCP), Cloud Asset Exposure: AWS S3 buckets, Azure Blob storage
Familiarity with cybersecurity domains and concepts including the MITRE ATT&CK framework, common attack vectors, vulnerabilities and exposures, defense-in-depth principles, network security controls, and cloud and endpoint exposure risks
Awareness of best practices for cyber hygiene including patch management, hardening, secure configuration management, and lifecycle management
Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or a related field; equivalent experience will be considered in lieu of a degree.
Pay Range Details
The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations.
Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.
$121,500.00 - $188,500.00 Annual
We27ve got you covered
Our employees are our most important asset and that27s reflected in our benefits.Nordstrom is proud to offer a variety of benefits to support employees and their families, including:
- Medical/Vision, Dental, Retirement and Paid Time Away
- Life Insurance and Disability
- Merchandise Discount and EAP Resources
This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_16.pdf
A few more important points...
The job posting highlights the most critical responsibilities and requirements of the job. It27s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.