368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$191k – $297k per year
Location
In office (Seattle)
Seniority
Principal · 12+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Nordstrom is a retail enterprise specializing in upscale department store operations, luxury fashion, and digital commerce. Headquartered in Seattle, Washington, the company operates a network of full-line department stores, off-price retail locations (Nordstrom Rack), and integrated e-commerce platforms. The enterprise distributes high-end apparel, footwear, beauty products, jewelry, and home goods, offering a mix of international designer brands, exclusive labels, and in-house private merchandise.

Job Description

This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.

We are seeking an accomplished Principal Security Engineer to serve within Nordstrom's Cybersecurity & Privacy Organization (CPO), focused on Identity & Access Management (IAM). This role will drive the architecture, strategy, and evolution of enterprise identity systems - including workforce identity, customer identity, privileged access, and the emerging discipline of agentic identity (machine-to-machine and AI agent credentials, authorization, and governance). The ideal candidate will be a seasoned identity practitioner with deep technical expertise, a passion for mentoring, and the ability to set IAM strategy at the highest levels of the organization. The goal is to make identity a foundational enabler of secure business innovation, operational resilience, and safe adoption of AI agents and automation.

Key Responsibilities:

  • Lead the design and architecture of enterprise IAM solutions across cloud, on-premises, and hybrid environments, including identity governance, authentication, authorization, and directory services.
  • Set technical direction and strategy for IAM initiatives, including zero trust identity, cloud IAM, agentic identity frameworks, and identity automation programs.
  • Serve as the principal technical advisor to security leadership, engineering teams, and business stakeholders on identity architecture, access risk management, and emerging identity threats.
  • Drive identity innovation through evaluation and integration of cutting-edge technologies, including AI/ML-based identity analytics, adaptive access controls, and identity orchestration platforms.
  • Define and lead Nordstrom's agentic identity strategy - establishing the standards, architecture, and governance for how AI agents, bots, and automated services are credentialed, authorized, scoped, and audited across the enterprise.
  • Partner with platform engineering, AI/ML, and application teams to operationalize agentic identity controls, ensuring AI agents operate under least-privilege, are attributable, and have auditable access lifecycles.
  • Maintain deep, current knowledge of the identity threat landscape - including credential-based attacks, identity supply chain risks, OAuth/token abuse, and emerging risks from agentic AI systems - and translate that intelligence into defensive priorities for Nordstrom.
  • Continuously assess Nordstrom's IAM posture, identifying capability gaps in identity governance, privileged access, and agentic identity and recommending new tools, vendors, or partnerships to close them.
  • Lead cross-functional identity architecture reviews and threat modeling exercises for critical business systems, with particular focus on access patterns, entitlement creep, and agentic access models.
  • Develop and maintain enterprise IAM standards, design patterns, and reference architectures aligned with industry best practices (NIST 800-63, OAuth 2.0/OIDC, SCIM, SPIFFE/SPIRE) and regulatory requirements.
  • Mentor and guide IAM engineers and analysts; foster a culture of technical excellence and continuous learning within the identity engineering organization.
  • Mentor the Cybersecurity Engineering team on identity-first security thinking and the emerging discipline of agentic identity - helping practitioners understand how to secure, govern, and audit non-human identities at scale.
  • Collaborate with enterprise architecture, infrastructure, application development, and DevSecOps teams to embed identity controls throughout the technology lifecycle.
  • Lead identity-related incident response efforts for critical events such as credential compromise, privilege escalation, and identity infrastructure attacks, providing technical expertise and strategic guidance.
  • Conduct advanced identity research and vulnerability analysis; develop proof-of-concepts for agentic identity governance, decentralized identity, and adaptive access models.
  • Partner with compliance, audit, and risk management teams to ensure IAM controls meet regulatory requirements (e.g., PCI-DSS, CCPA, SOX) and support auditability of both human and non-human access.
  • Track and communicate IAM program metrics, technical roadmaps, and identity risk posture to executive leadership and board-level stakeholders.
  • Drive automation and tooling initiatives to scale identity operations, reduce manual provisioning and access review workflows, and improve identity threat detection and response capabilities.

Required Qualifications:

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field; Master's degree preferred.
  • 12+ years of experience in information security, with at least 5 years focused on identity & access management in a senior or principal technical leadership role.
  • Deep expertise in identity & access management domains: workforce and customer identity, privileged access management, identity governance, federation, directory services, and emerging agentic identity patterns.
  • Proven experience architecting and implementing IAM solutions in large-scale enterprise environments, including cloud-native identity services (AWS IAM, Azure Entra ID, GCP IAM).
  • Strong understanding of security frameworks and standards (NIST 800-63, OAuth 2.0, OpenID Connect, SAML, SCIM, SPIFFE/SPIRE, FIDO2/WebAuthn).
  • Demonstrated experience with IAM tools and technologies: IGA platforms, PAM solutions, CIAM, SSO/federation, identity orchestration, and identity threat detection and response (ITDR) tools.
  • Demonstrated experience designing identity solutions for non-human entities (service accounts, API keys, machine identities, AI agents) and a strong willingness to lead in the agentic identity space.
  • Exceptional communication and stakeholder management skills with ability to influence at all organizational levels.
  • Relevant certifications required (e.g., CISSP, GIAC, CCSP, OSCP, or equivalent advanced certifications).

Preferred Skills:

  • Experience driving IAM transformations in retail, e-commerce, or other large-scale consumer-facing environments.
  • Deep knowledge of identity-as-code practices, infrastructure-as-code for IAM, and CI/CD identity integration.
  • Experience with identity orchestration platforms, identity fabric architectures, and AI-enhanced identity analytics solutions.
  • Familiarity with agentic AI identity challenges, including agent credential management, delegation chains, least-privilege scoping for autonomous systems, and non-human identity governance.
  • Experience evaluating IAM and agentic identity vendors and technologies.
  • Proven track record of mentoring and developing identity engineering professionals in complex, matrixed organizations.
  • Strong understanding of identity supply chain risks, third-party identity federation, and vendor IAM integration patterns.
  • Ability to translate complex technical security concepts into business risk language for executive and non-technical audiences.
  • Active participation in security community through speaking engagements, publications, or open-source contributions.

Pay Range Details

The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations.

Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.

$191,000.00 - $297,000.00 Annual

We’ve got you covered…

Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources
This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_17-19.pdf

A few more important points...

The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.

For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site.

Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com.

Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.

Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs.

Nordstrom keeps job postings open for at least one day after the posting date.© 2026 Nordstrom, Inc
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Seattle
$169k – $253k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Boulder
JavaScript
TypeScript
AI/ML
AI Agents
Frontend
GraphQL
React.js
DevOps
AWS
Azure
GCP
Google GKE
Helm
Kubernetes
Apply
$60k – $108k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
PowerShell
Python
DevOps
AWS
Azure
IAM
Splunk
Cybersecurity
Crowdstrike
ISO 27001
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
NIST CSF
Qualys Cloud Platform
Apply
Network Manager 3 hours ago
$128k – $173k per year • In office • Full-Time • 5+ years exp • United States
DevOps
AWS
Azure
GCP
Apply
$66k – $123k per year • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Corvallis
Python
SQL
Databases
Snowflake
AI/ML
AI Agents
dbt
DevOps
AWS
GitHub
Analytics
Power BI
Tableau
Apply
$128k – $173k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • United States
JavaScript
Node JS
TypeScript
Frontend
React.js
DevOps
Amazon EC2
AWS
AWS CDK
AWS Lambda
CI/CD
GitHub Actions
Jenkins
Terraform
Amazon CloudWatch
Amazon S3
API Gateway
GitHub
GitLab
IAM
Apply
$88k – $146k per year • In office • Full-Time • 3+ years exp • Master's Degree • Seattle
Perl
Python
Ruby
SQL
Databases
MySQL
Teradata
DevOps
AWS
Analytics
Tableau
Apply
$166k – $258k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Seattle
DevOps
CI/CD
Apply
$69k – $111k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Seattle
Design
Adobe Photoshop
Figma
Apply
$201k – $332k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Seattle
AI/ML
Claude
Claude Code
Model Context Protocol
A2A
AI Agents
Context Engineering
LLM Guardrails
Apply
$142k – $221k per year • In office • Full-Time • 5+ years exp • Seattle
SQL
Databases
Google BigQuery
AI/ML
LLM
AI Agents
DevOps
GCP
Apply
$256k – $320k per year • Remote/Hybrid • Full-Time • Seattle
Go
Python
AI/ML
AI Agents
CrewAI
LangChain
LangGraph
DevOps
AWS
GCP
Kubernetes
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
Databases
Databricks
Google BigQuery
SAP HANA
Snowflake
AI/ML
Knowledge Graph
DevOps
Azure
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 5+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
DevOps
SLI/SLO/SLA
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$88k – $146k per year • In office • Full-Time • 3+ years exp • Master's Degree • Seattle
Perl
Python
Ruby
SQL
Databases
MySQL
Teradata
DevOps
AWS
Analytics
Tableau
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.