Sr. Network Security Engineer (hybrid - Seattle, Wa)

Nordstrom Nordstrom · Retail · Seattle, WA

This role focuses on designing, deploying, and automating network security controls across enterprise, cloud, and retail edge environments. It involves implementing zero-trust network access, microsegmentation, and perimeter security, as well as building automation pipelines for security policy management and compliance validation. The role requires expertise in cloud security, identity, and access, with a strong emphasis on an automation-first mindset and treating infrastructure as code.

What you'd actually do

  1. Design, deploy, and operate network security controls across enterprise, cloud (AWS, Azure, GCP), and retail edge environments
  2. Implement and maintain zero-trust network access (ZTNA) policies, microsegmentation, and perimeter security using tools like Zscaler, Palo Alto Networks, and cloud-native NGFWs
  3. Build and maintain automation pipelines for security policy management, firewall rule lifecycle, and compliance validation — treating infrastructure as code
  4. Collaborate with cloud, platform, and application teams to integrate security at the network layer without blocking delivery velocity
  5. Serve as a subject matter expert for authentication and authorization frameworks: 802.1X, EAP-TLS, RADIUS/ClearPass, certificate management, and IAM integrations

Skills

Required

  • Bachelor's or master's degree in Computer Science, Engineering, Cybersecurity, or equivalent education and experience
  • 7+ years of progressive enterprise security engineering experience with demonstrated depth in network security domains
  • Hands-on experience with cloud security architecture across two or more major cloud platforms (AWS, Azure, GCP, OCI) — including cloud NGFW, VPC security controls, and private connectivity patterns
  • Strong automation and IaC experience: Python, Terraform, Ansible, or equivalent — you write production-grade automation, not one-off scripts
  • Deep expertise in network security technologies: next-gen firewalls (Palo Alto), ZTNA/SWG (Zscaler), IDS/IPS, and DDoS mitigation
  • Strong working knowledge of authentication and authorization: 802.1X, EAP-TLS, RADIUS, ClearPass/ISE, SAML, OAuth, and PKI/certificate management
  • Solid foundational network knowledge: TCP/IP, BGP, SD-WAN concepts, VLAN segmentation, DNS, and routing protocols — enough to own security outcomes independently
  • Experience with security policy-as-code, CI/CD pipelines for network security changes, and GitOps workflows
  • Effective written and verbal communication; able to produce clear RCAs, architecture docs, and executive summaries

Nice to have

  • Experience with Versa SD-WAN security policy, Juniper Mist access policy, or Fastly/edge security controls
  • Familiarity with SIEM platforms, SOAR workflows, or security data pipelines (e.g., New Relic, Splunk)
  • Relevant certifications: PCNSE, CCNP Security, AWS/Azure Security Specialty, CISSP, or equivalent
  • Retail or high-velocity e-commerce security experience

What the JD emphasized

  • automation first
  • automation pipelines
  • security policy management
  • firewall rule lifecycle
  • compliance validation
  • infrastructure as code
  • zero-trust network access (ZTNA)
  • microsegmentation
  • perimeter security
  • authentication and authorization frameworks
  • network security events
  • threat models
  • security runbooks
  • architecture reviews
  • security best practices
  • automation patterns
  • on-call rotation
  • automation-first mindset
  • security in cloud environments
  • AWS Security Groups
  • Azure NSGs
  • cloud NGFW
  • service mesh
  • layered defense model
  • authentication and authorization
  • certificate lifecycles
  • EAP methods
  • identity-aware policy enforcement
  • continuous improvement
  • raising the security bar