Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)

NordstromSeattle, WA
$191,000 - $297,000Hybrid

About The Position

This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position. We are seeking an accomplished Principal Security Engineer to serve within Nordstrom's Cybersecurity & Privacy Organization (CPO), focused on Identity & Access Management (IAM). This role will drive the architecture, strategy, and evolution of enterprise identity systems — including workforce identity, customer identity, privileged access, and the emerging discipline of agentic identity (machine-to-machine and AI agent credentials, authorization, and governance). The ideal candidate will be a seasoned identity practitioner with deep technical expertise, a passion for mentoring, and the ability to set IAM strategy at the highest levels of the organization. The goal is to make identity a foundational enabler of secure business innovation, operational resilience, and safe adoption of AI agents and automation.

Requirements

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field; Master's degree preferred.
  • 12+ years of experience in information security, with at least 5 years focused on identity & access management in a senior or principal technical leadership role.
  • Deep expertise in identity & access management domains: workforce and customer identity, privileged access management, identity governance, federation, directory services, and emerging agentic identity patterns.
  • Proven experience architecting and implementing IAM solutions in large-scale enterprise environments, including cloud-native identity services (AWS IAM, Azure Entra ID, GCP IAM).
  • Strong understanding of security frameworks and standards (NIST 800-63, OAuth 2.0, OpenID Connect, SAML, SCIM, SPIFFE/SPIRE, FIDO2/WebAuthn).
  • Demonstrated experience with IAM tools and technologies: IGA platforms, PAM solutions, CIAM, SSO/federation, identity orchestration, and identity threat detection and response (ITDR) tools.
  • Demonstrated experience designing identity solutions for non-human entities (service accounts, API keys, machine identities, AI agents) and a strong willingness to lead in the agentic identity space.
  • Exceptional communication and stakeholder management skills with ability to influence at all organizational levels.
  • Relevant certifications required (e.g., CISSP, GIAC, CCSP, OSCP, or equivalent advanced certifications).

Nice To Haves

  • Experience driving IAM transformations in retail, e-commerce, or other large-scale consumer-facing environments.
  • Deep knowledge of identity-as-code practices, infrastructure-as-code for IAM, and CI/CD identity integration.
  • Experience with identity orchestration platforms, identity fabric architectures, and AI-enhanced identity analytics solutions.
  • Familiarity with agentic AI identity challenges, including agent credential management, delegation chains, least-privilege scoping for autonomous systems, and non-human identity governance.
  • Experience evaluating IAM and agentic identity vendors and technologies.
  • Proven track record of mentoring and developing identity engineering professionals in complex, matrixed organizations.
  • Strong understanding of identity supply chain risks, third-party identity federation, and vendor IAM integration patterns.
  • Ability to translate complex technical security concepts into business risk language for executive and non-technical audiences.
  • Active participation in security community through speaking engagements, publications, or open-source contributions.

Responsibilities

  • Lead the design and architecture of enterprise IAM solutions across cloud, on-premises, and hybrid environments, including identity governance, authentication, authorization, and directory services.
  • Set technical direction and strategy for IAM initiatives, including zero trust identity, cloud IAM, agentic identity frameworks, and identity automation programs.
  • Serve as the principal technical advisor to security leadership, engineering teams, and business stakeholders on identity architecture, access risk management, and emerging identity threats.
  • Drive identity innovation through evaluation and integration of cutting-edge technologies, including AI/ML-based identity analytics, adaptive access controls, and identity orchestration platforms.
  • Define and lead Nordstrom's agentic identity strategy — establishing the standards, architecture, and governance for how AI agents, bots, and automated services are credentialed, authorized, scoped, and audited across the enterprise.
  • Partner with platform engineering, AI/ML, and application teams to operationalize agentic identity controls, ensuring AI agents operate under least-privilege, are attributable, and have auditable access lifecycles.
  • Maintain deep, current knowledge of the identity threat landscape — including credential-based attacks, identity supply chain risks, OAuth/token abuse, and emerging risks from agentic AI systems — and translate that intelligence into defensive priorities for Nordstrom.
  • Continuously assess Nordstrom's IAM posture, identifying capability gaps in identity governance, privileged access, and agentic identity and recommending new tools, vendors, or partnerships to close them.
  • Lead cross-functional identity architecture reviews and threat modeling exercises for critical business systems, with particular focus on access patterns, entitlement creep, and agentic access models.
  • Develop and maintain enterprise IAM standards, design patterns, and reference architectures aligned with industry best practices (NIST 800-63, OAuth 2.0/OIDC, SCIM, SPIFFE/SPIRE) and regulatory requirements.
  • Mentor and guide IAM engineers and analysts; foster a culture of technical excellence and continuous learning within the identity engineering organization.
  • Mentor the Cybersecurity Engineering team on identity-first security thinking and the emerging discipline of agentic identity — helping practitioners understand how to secure, govern, and audit non-human identities at scale.
  • Collaborate with enterprise architecture, infrastructure, application development, and DevSecOps teams to embed identity controls throughout the technology lifecycle.
  • Lead identity-related incident response efforts for critical events such as credential compromise, privilege escalation, and identity infrastructure attacks, providing technical expertise and strategic guidance.
  • Conduct advanced identity research and vulnerability analysis; develop proof-of-concepts for agentic identity governance, decentralized identity, and adaptive access models.
  • Partner with compliance, audit, and risk management teams to ensure IAM controls meet regulatory requirements (e.g., PCI-DSS, CCPA, SOX) and support auditability of both human and non-human access.
  • Track and communicate IAM program metrics, technical roadmaps, and identity risk posture to executive leadership and board-level stakeholders.
  • Drive automation and tooling initiatives to scale identity operations, reduce manual provisioning and access review workflows, and improve identity threat detection and response capabilities.

Benefits

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources
  • performance-based incentives/bonuses
  • 401k
  • medical/vision/dental/life/disability insurance options
  • PTO accruals
  • Holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service