Senior Principal Engineer - Cybersecurity (hybrid - Seattle)

Nordstrom Nordstrom · Retail · Seattle, WA

Senior Principal Engineer - Cybersecurity role at Nordstrom, focusing on defining and implementing enterprise-wide platform security strategy, including for emerging technologies like genAI. The role involves architecting security solutions, establishing governance frameworks, and mentoring technical leaders. While not directly building AI models, the role is critical for securing AI deployments and requires understanding of AI/ML platforms and responsible AI practices within a large enterprise context.

What you'd actually do

  1. Define and evangelize the long-term platform security vision aligned with enterprise technology strategy and business objectives
  2. Architect enterprise-wide security solutions for emerging and disruptive technologies (genAI, edge computing, decentralized systems)
  3. Develop comprehensive reference architectures and security patterns that become organizational standards across all technology domains
  4. Quantify and communicate platform security investments in terms of business risk reduction, revenue protection, and competitive advantage
  5. Mentor Principal Engineers, Architects, and senior technical leaders across cybersecurity and technology organizations

Skills

Required

  • 12+ years in cybersecurity with 5+ years leading enterprise-level security architecture initiatives
  • Demonstrated track record of defining security strategy that influenced organizational direction at Fortune 500 or equivalent scale
  • Proven ability to drive consensus and adoption of security standards across diverse technical and business stakeholders
  • History of mentoring senior technical talent and elevating organizational security capabilities
  • Enterprise security architecture frameworks (SABSA, O-ESA, TOGAF)
  • Advanced threat modeling and risk quantification methodologies
  • Zero Trust architecture at enterprise scale
  • Security for AI/ML
  • DevSecOps and platform engineering security patterns
  • Enterprise SIEM/SOAR/XDR platforms and custom security automation at scale
  • Multi-cloud security architecture (AWS, Azure, GCP) with hybrid considerations
  • Container orchestration security (Kubernetes, service mesh, serverless)
  • AI/ML platforms, LLMs, and emerging technology stacks
  • Infrastructure as Code security (Terraform, CloudFormation, security policy as code)
  • Python, Go, Java for security automation and tooling
  • Security domain-specific languages and frameworks

Nice to have

  • Published thought leadership (patents, peer-reviewed publications, industry presentations) in platform security
  • Experience advising C-suite or Board of Directors on technology security strategy
  • Track record of influencing industry standards or vendor security capabilities
  • Experience in regulated retail, financial services, or similarly complex enterprise environments
  • Bachelor's Degree in Information Technology, Computer Science, Cybersecurity or related field; Master's Degree strongly preferred

What the JD emphasized

  • Security for AI/ML
  • AI/ML platforms, LLMs, and emerging technology stacks
  • Organization-wide security frameworks for responsible AI deployment with integrated risk management