Senior Security Engineer - Threat Intelligence & Detection Engineering (hybrid - Seattle)

Nordstrom Nordstrom · Retail · Seattle, WA

Senior Security Engineer focused on Threat Intelligence & Detection Engineering. Responsibilities include writing detection rules, threat hunting, and building automation. The role leverages AI-assisted tooling for intelligence processing and detection development, but the core craft is security engineering, not AI model building.

What you'd actually do

  1. Design, develop, and maintain high-fidelity detection rules in CrowdStrike NG-SIEM (LogScale/CQL) across endpoint, email, identity, network, and cloud domains
  2. Collect, analyze, and operationalize tactical and technical threat intelligence from open-source, commercial, and internal sources
  3. Design and execute hypothesis-driven threat hunts across endpoint, email, identity, network, and cloud telemetry
  4. Build and maintain automation that accelerates detection deployment, alert triage, case enrichment, and threat intel processing

Skills

Required

  • 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation
  • Demonstrated proficiency writing detection logic in at least one enterprise SIEM or XDR platform
  • Working knowledge of MITRE ATT&CK at the technique and sub-technique level
  • Hands-on experience with EDR analysis, behavioral anomaly detection, and investigation of post-exploitation activity
  • Hands-on experience with hypothesis-driven threat hunting
  • Scripting proficiency in Python and/or PowerShell for automation, log parsing, or investigative tooling
  • Experience contributing to incident response for malware incidents, identity-based attacks, or insider threats
  • Strong written communication skills
  • Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience

Nice to have

  • Familiarity with identity attack patterns including AiTM, MFA fatigue, session hijacking, token replay, and adversarial abuse of SSO and federated identity platforms
  • Experience with enterprise email security platforms and email-based threat detection including phishing, BEC, and malicious delivery mechanisms
  • Exposure to SOAR platforms and workflow automation (CrowdStrike Fusion or equivalent)
  • Experience with threat intelligence platforms (MISP, ThreatConnect, Recorded Future) and structured intel formats (STIX/TAXII)
  • Knowledge of detection-as-code practices, version control (Git), and CI/CD integration for detection deployment
  • Experience with cloud security telemetry (Azure, AWS) and cloud-native attack detection
  • Demonstrated use of AI tools to accelerate detection development, security operations, or threat research

What the JD emphasized

  • functional depth in at least two of the following domains: detection engineering, threat intelligence, threat hunting, security automation, investigation analysis, and incident response
  • CrowdStrike NG-SIEM (LogScale/CQL) experience strongly preferred
  • Scripting proficiency in Python and/or PowerShell for automation, log parsing, or investigative tooling