Summary
The Principal Security Engineer will lead the architecture, strategy, and evolution of enterprise identity and access management across cloud, on-premises, and hybrid environments. This role will also establish Nordstrom's approach to agentic identity, helping secure AI agents and other non-human identities while advising leaders and mentoring engineering teams.
Responsibilities
- Lead IAM architecture, strategy, standards, and reference designs, including identity governance, privileged access, zero trust, cloud IAM, and agentic identity.
- Advise security leaders and business stakeholders, assess IAM risks and capabilities, and guide technology evaluations and integrations.
- Partner with engineering and AI/ML teams to implement auditable, least-privilege controls for AI agents and automated services.
- Lead architecture reviews, threat modeling, incident response, research, and identity automation initiatives.
- Mentor engineers and communicate IAM roadmaps, metrics, and risk posture to executive stakeholders.
Requirements
- Bachelor's degree in computer science, information security, engineering, or a related field; a master's degree is preferred.
- At least 12 years of information security experience, including 5 or more years focused on IAM in a senior or principal technical leadership role.
- Deep expertise in enterprise IAM, including workforce and customer identity, privileged access, identity governance, federation, and directory services.
- Experience architecting enterprise IAM solutions, cloud identity services, and identity controls for service accounts, machine identities, and AI agents.
- Strong knowledge of security standards and protocols, IAM tools, and relevant certifications such as CISSP, GIAC, CCSP, or OSCP.
- Exceptional communication, stakeholder management, and mentoring skills.