Principal Security Engineer - Identity and Access Management; Hybrid - Seattle
Listed on 2026-09-14
-
IT/Tech
Cybersecurity
Job Description
This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.
We are seeking an accomplished Principal Security Engineer to serve within Nordstrom's Cybersecurity & Privacy Organization (CPO), focused on Identity & Access Management (IAM). This role will drive the architecture, strategy, and evolution of enterprise identity systems — including workforce identity, customer identity, privileged access, and the emerging discipline of agentic identity (machine-to-machine and AI agent credentials, authorization, and governance). The ideal candidate will be a seasoned identity practitioner with deep technical expertise, a passion for mentoring, and the ability to set IAM strategy at the highest levels of the organization.
The goal is to make identity a foundational enabler of secure business innovation, operational resilience, and safe adoption of AI agents and automation.
- Lead the design and architecture of enterprise IAM solutions across cloud, on-premises, and hybrid environments, including identity governance, authentication, authorization, and directory services.
- Set technical direction and strategy for IAM initiatives, including zero trust identity, cloud IAM, agentic identity frameworks, and identity automation programs.
- Serve as the principal technical advisor to security leadership, engineering teams, and business stakeholders on identity architecture, access risk management, and emerging identity threats.
- Drive identity innovation through evaluation and integration of cutting‑edge technologies, including AI/ML‑based identity analytics, adaptive access controls, and identity orchestration platforms.
- Define and lead Nordstrom's agentic identity strategy — establishing the standards, architecture, and governance for how AI agents, bots, and automated services are credentialed, authorized, scoped, and audited across the enterprise.
- Partner with platform engineering, AI/ML, and application teams to operationalize agentic identity controls, ensuring AI agents operate under least‑privilege, are attributable, and have auditable access life cycles.
- Maintain deep, current knowledge of the identity threat landscape — including credential‑based attacks, identity supply chain risks, OAuth/token abuse, and emerging risks from agentic AI systems — and translate that intelligence into defensive priorities for Nordstrom.
- Continuously assess Nordstrom's IAM posture, identifying capability gaps in identity governance, privileged access, and agentic identity and recommending new tools, vendors, or partnerships to close them.
- Lead cross‑functional identity architecture reviews and threat modeling exercises for critical business systems, with particular focus on access patterns, entitlement creep, and agentic access models.
- Develop and maintain enterprise IAM standards, design patterns, and reference architectures aligned with industry best practices (NIST 800-63, OAuth 2.0/OIDC, SCIM, SPIFFE/SPIRE) and regulatory requirements.
- Mentor and guide IAM engineers and analysts; foster a culture of technical excellence and continuous learning within the identity engineering organization.
- Mentor the Cybersecurity Engineering team on identity‑first security thinking and the emerging discipline of agentic identity — helping practitioners understand how to secure, govern, and audit non‑human identities at scale.
- Collaborate with enterprise architecture, infrastructure, application development, and Dev Sec Ops teams to embed identity controls throughout the technology lifecycle.
- Lead identity‑related incident response efforts for critical events such as…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).