Nordstrom

Senior Security Engineer - Threat Intelligence & Detection Engineering (Hybrid - Seattle)

Nordstrom$142K — $220K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in detection engineering, threat intelligence, SOC/IR, or threat hunting
  • Proficient in writing detection logic for enterprise SIEM/XDR platforms, preferably CrowdStrike NG-SIEM
  • Working knowledge of MITRE ATT&CK techniques and mapping adversary behaviors
  • Hands-on experience in EDR analysis and post-exploitation investigations
  • Scripting proficiency in Python/PowerShell for automation and tooling
  • Experience with incident response for various attack vectors
  • Strong written communication skills for documentation and reporting

Responsibilities

  • Design and maintain detection rules in CrowdStrike NG-SIEM across multiple domains
  • Operationalize the detection lifecycle from threat modeling to retirement
  • Create detection content based on MITRE ATT&CK and internal threat priorities
  • Translate threat intel findings into actionable detection logic
  • Monitor campaigns targeting retail and e-commerce environments
  • Conduct hypothesis-driven threat hunts to uncover adversary activity
  • Provide technical support for complex security incidents

Benefits

  • Medical/Vision, Dental, Retirement, and Paid Time Off
  • Life Insurance and Disability coverage
  • Merchandise Discount and Employee Assistance Program resources
Full Job Description
Job Description

The Senior Security Engineer on the TIDE team is a hybrid practitioner who writes detection rules, hunts adversary activity across the data lake, and builds the automation that ties it all together. This role requires functional depth in at least two of the following domains: detection engineering, threat intelligence, threat hunting, security automation, investigation analysis, and incident response.

This role reports to the Sr. Manager of Threat Intelligence & Detection Engineering and serves as a lead technical contributor on the TIDE team, with independent project horizons of up to 120 days.

Responsibilities
Detection Engineering
  • Design, develop, and maintain high-fidelity detection rules in CrowdStrike NG-SIEM (LogScale/CQL) across endpoint, email, identity, network, and cloud domains
  • Operationalize the full detection lifecycle: threat modeling, logic development, empirical testing, deployment, tuning, and retirement
  • Build detection content aligned to MITRE ATT&CK, threat actor TTPs, and internal threat model priorities
  • Translate threat intelligence findings, incident post-mortems, and hunt discoveries into durable detection logic
  • Enforce detection engineering standards including taxonomy, quality criteria, and review processes

Threat Intelligence
  • Collect, analyze, and operationalize tactical and technical threat intelligence from open-source, commercial, and internal sources
  • Produce actionable intelligence products including threat actor profiles, TTP summaries, and IOC packages that directly inform detection priorities and hunting hypotheses
  • Monitor threat actor campaigns targeting retail and e-commerce environments across email, endpoint, identity, supply chain, and insider risk vectors
  • Collaborate with CSIRT and SOC to enrich active investigations with adversary context
  • Apply AI-assisted tooling to accelerate intelligence processing, IOC enrichment, and adversary research

Threat Hunting
  • Design and execute hypothesis-driven threat hunts across endpoint, email, identity, network, and cloud telemetry
  • Apply structured hunting methodologies (MITRE ATT&CK-based, data-driven, indicator-based) to surface undetected adversary activity
  • Document hunt outcomes—including negative results—and feed confirmed patterns back into the detection library
  • Maintain visibility into coverage gaps and drive new hunt-to-detect cycles to close them

SOC & Incident Response Support
  • Provide technical escalation support for complex incidents involving identity compromise, endpoint intrusion, lateral movement, and data exfiltration
  • Conduct targeted forensic and log-based analysis during active investigations, contributing to root cause determination and containment decisions
  • Develop and maintain investigation runbooks and analyst guidance to improve SOC response fidelity
  • Translate post-incident lessons learned into detection and hunting improvements

Automation and Tooling
  • Build and maintain automation that accelerates detection deployment, alert triage, case enrichment, and threat intel processing
  • Develop integrations between SIEM, EDR, email security, SOAR, and threat intelligence platforms to reduce analyst toil
  • Apply scripting (Python, PowerShell) to operationalize repetitive workflows including IOC ingest, log parsing, and detection validation
  • Leverage AI and machine learning tools to improve detection quality, reduce false positive rates, and accelerate triage

Collaboration and Mentorship
  • Mentor less experienced team members through code review, knowledge transfer, and structured guidance
  • Partner with SOC, IAM, Platform Engineering, Email Security, and Cloud teams to ensure telemetry quality and detection coverage
  • Contribute to cross-functional initiatives including purple team exercises, tabletop scenarios, and platform migration readiness

Required Qualifications
  • 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation
  • Demonstrated proficiency writing detection logic in at least one enterprise SIEM or XDR platform; CrowdStrike NG-SIEM (LogScale/CQL) experience strongly preferred
  • Working knowledge of MITRE ATT&CK at the technique and sub-technique level; ability to map adversary behaviors to telemetry sources and detection logic
  • Hands-on experience with EDR analysis, behavioral anomaly detection, and investigation of post-exploitation activity
  • Hands-on experience with hypothesis-driven threat hunting; ability to document and execute an end-to-end hunt
  • Scripting proficiency in Python and/or PowerShell for automation, log parsing, or investigative tooling
  • Experience contributing to incident response for malware incidents, identity-based attacks, or insider threats
  • Strong written communication skills; ability to produce clear, actionable documentation, detection rationale, and intelligence products
  • Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience

Preferred Qualifications
  • Familiarity with identity attack patterns including AiTM, MFA fatigue, session hijacking, token replay, and adversarial abuse of SSO and federated identity platforms
  • Experience with enterprise email security platforms and email-based threat detection including phishing, BEC, and malicious delivery mechanisms
  • Exposure to SOAR platforms and workflow automation (CrowdStrike Fusion or equivalent)
  • Experience with threat intelligence platforms (MISP, ThreatConnect, Recorded Future) and structured intel formats (STIX/TAXII)
  • Knowledge of detection-as-code practices, version control (Git), and CI/CD integration for detection deployment
  • Experience with cloud security telemetry (Azure, AWS) and cloud-native attack detection
  • Demonstrated use of AI tools to accelerate detection development, security operations, or threat research
  • Intermediate or advanced certifications such as GIAC GCIA, GCIH, GCTI, GDAT, or equivalent

Pay Range Details


The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. 
Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.

$142,000.00 - $220,500.00 Annual

 

We’ve got you covered…


Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources

   

This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_17-19.pdf

 

A few more important points...


The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.

About Nordstrom

Acquired by Nordstrom in March 2011, HauteLook is a place where you'll discover thousands of the top fashion and lifestyle brands at amazing savings. Each day at 8 AM Pacific, shop new sale events featuring the best names in women's and men's fashion, beauty, and home décor at up to 75% off. Membership is free and everyone is welcome. HauteLook launched in 2007 and is headquartered in Los Angeles. See what the buzz is all about! Register now to become a HauteLook member. www.hautelook.com

Nordstrom Careers

Join the vibrant team at Nordstrom, a leader in the retail industry, where your career growth and development are prioritized. At Nordstrom, we offer a wide array of job opportunities that allow professionals to thrive in an innovative and supportive environment. Work You’ll Do At Nordstrom, we are committed to driving success not only for our company but for each individual who joins our team. Whether you are looking for a position in sales, management, or corporate roles, Nordstrom provides a platform for professional growth through hands-on experience and high-quality leadership training. Our commitment to diversity and inclusion ensures a workplace where everyone can truly belong and excel. Nordstrom’s market-leading team is at the forefront of retail innovation and customer service excellence. By joining us, you will collaborate with skilled professionals dedicated to reshaping the future of retail through cutting-edge technology and exceptional service strategies. Internship Programs Kickstart your career with a Nordstrom internship. Our programs offer invaluable industry insights and hands-on experience, making them a perfect starting point for students and recent graduates eager to make their mark in the retail sector. Interns at Nordstrom gain practical skills and are often considered for full-time positions, reflecting our commitment to nurturing talent from within. Employee Benefits and Culture Nordstrom’s reputation is built not only on our commitment to customers but also on our dedication to our team members. We offer a comprehensive benefits package that supports the health, well-being, and financial security of our employees and their families. Benefits at Nordstrom include health insurance, employee discounts, and access to wellness programs. Our culture at Nordstrom is one of collaboration, innovation, and respect. We believe in the power of working together as a team, where each member’s contribution is valued. Networking within the company is encouraged, fostering a community of support and continuous learning. Career Advancement Opportunities Nordstrom believes in the growth of our employees. With a variety of training and development programs, employees are equipped with the knowledge and skills needed to advance their careers within the company. Leadership development and succession planning are integral parts of our commitment to employee advancement. Join Our Team Explore the exciting career and employment opportunities available at Nordstrom today. We are actively hiring and looking for ambitious, creative, and driven individuals to join our team. Search open positions that match your skills and interests on our Jobs page. Stay Connected Keep up to date with the latest career tips, insider perspectives, and industry-leading insights—all from the people who work at Nordstrom. Subscribe to our Careers Blog and personalize your subscription to receive job alerts and the latest news tailored to your preferences. Discover the rewarding career opportunities waiting for you at Nordstrom, where we turn jobs into pathways for professional growth and personal achievement. Join us and be part of a company that values innovation, leadership, and a diverse and inclusive workplace.
Learn more about Nordstrom
Size
60,000 employees
Market Cap
$2.5 billion
Industry
Net Income
-$531 million
Founded
1901
5 Year Trend
-5.8%
Revenue
$10.7 billion
NASDAQ

Similar Jobs

More Jobs at Nordstrom

More Information Technology Jobs

Find similar Senior Security Engineer - Threat Intelligence & Detection Engineering (Hybrid - Seattle) jobs: