Jobs and Careers
NO

Senior Manager, Application Security (Hybrid - Seattle)

Nordstrom
United StatesRemotefull_timeVerifiedPosted 17 Apr 2026
💰 $297,000/yr($191,000/yr$297,000/yr)

About the role

Job Description

We are seeking an experienced and strategic Senior Manager of Application Security to lead our application security team. This role is responsible for building and maturing our application security program, embedding security throughout the software development lifecycle (SDLC), and ensuring that Nordstrom’s applications and APIs are protected against evolving threats. The ideal candidate will drive technical strategy for application security tooling, scale secure-by-design practices, and lead initiatives to integrate security seamlessly into engineering workflows while building a high-performing AppSec team. You will partner closely with product engineering, platform, and DevOps teams to deliver security at the speed of development. The right leader will bring an AI-first mindset and a proven ability to enable their team to embrace and leverage AI in their day-to-day work.

Key Responsibilities:

Strategic Leadership & AppSec Program Vision

  • Develop and execute a strategic roadmap for application security across the SDLC, including secure code review, SAST/DAST/SCA tooling, API security, secrets management, and developer security enablement.
  • Champion an AI-first approach to application security, identifying opportunities to leverage AI for vulnerability detection, code analysis, threat modeling automation, and developer guidance.
  • Drive a shift-left security strategy, embedding security practices early in the development lifecycle and reducing time-to-remediation for application vulnerabilities.
  • Create multi-quarter implementation plans for maturing the AppSec program, including bug bounty expansion, penetration testing cadence, and security champions growth, aligned with enterprise security and engineering objectives.
  • Identify and prioritize application security investments based on threat intelligence, vulnerability trends, business risk, and the evolving attack surface of Nordstrom’s web, mobile, and API ecosystem.
  • Establish meaningful AppSec metrics that demonstrate program maturity and business value, such as mean time to remediate (MTTR), vulnerability density trends, security debt reduction, and developer security training completion.
  •  Partner with security leadership to translate organizational security strategy into actionable platform implementation plans.

Program Management & Technical Execution

  • Lead the design, implementation, and lifecycle management of application security tooling including SAST, DAST, SCA, IAST, secrets detection, API security testing, and developer security training platforms.
  • Oversee RFP processes and technical evaluations for AppSec tooling, ensuring selected solutions integrate into CI/CD pipelines and developer workflows with minimal friction.
  • Own the application penetration testing program, including scoping, vendor management, internal red team coordination, and ensuring findings are tracked to remediation.
  • Establish and maintain application security standards, secure coding guidelines, threat modeling practices, and architectural review processes across engineering teams.
  • Build and scale a Security Champions program that embeds security awareness and accountability within engineering squads, reducing reliance on centralized security reviews.
  • Partner with engineering, DevOps, and platform teams to integrate security gates into CI/CD pipelines, ensuring automated scanning and policy enforcement at every stage of the build and deploy process.
  • Lead application security incident response for vulnerabilities and exploits targeting Nordstrom’s applications, driving rapid triage, root cause analysis, and durable remediation in partnership with the SOC and engineering teams.

Team Leadership & Development

  • Build, lead, and mentor a diverse team of application security engineers spanning offensive security, secure code review, AppSec tooling, and developer enablement functions.
  • Establish team structure that balances proactive security engineering (tooling, automation, secure design) with reactive functions (vulnerability management, security reviews, and incident support).
  • Create individual development plans that align with team members’ career aspirations and organizational needs.
  • Implement performance management frameworks that recognize achievements and address development areas.
  • Foster a collaborative culture that encourages knowledge sharing, continuous learning, partnership, and innovation.
  • Identify and develop emerging leaders within the team to build succession pipelines.
  • Foster a culture of AI adoption by modeling an AI-first mindset, enabling experimentation, and integrating AI tools into team workflows.
  •  Promote inclusive team practices that value diverse perspectives and approaches

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Nordstrom

View company profile →