Jobs Companies Nordstrom Compliance Analyst 2 - PCI (Hybrid - Seattle)

Über diese Compliance Analyst 2 - PCI (Hybrid - Seattle) Stelle bei Nordstrom

Nordstrom · Hybrid · Seattle, WA

Job Description

This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.

Compliance doesn't have to mean dusty binders and once-a-year fire drills — on this team, it's about building programs that are sharp, current, and built to last. Nordstrom's Governance, Risk & Compliance (GRC) team is looking for a Compliance Analyst to help build out three of our most active programs: the Continuous Compliance Framework (CCF), Financial Control Audit, and PCI DSS. All three are actively maturing, and you'll be right there building alongside us — standing up RACIs, shaping the KPIs/KRIs that show program health, and helping put governance structures in place that actually hold. This isn't a "maintain what already exists" role; it's a "help us build the thing" role.

You'll also team up with the rest of the Compliance crew to find smarter, faster ways to get the work done — putting AI and automation to work so evidence collection and control testing stop feeling like a grind and start feeling like a well-oiled machine.

This is a great fit for someone who loves getting hands-on: technical control testing, evidence and documentation, RACI and governance design, program metrics — the whole toolkit. You'll work closely with senior analysts across both programs, and as things mature, you'll pick up direct ownership of specific pieces of CCF and/or PCI.

Come for the compliance, stay for the team that actually makes it fun.

A Day in the Life…

Continuous Compliance Framework (CCF) — Build & Support

  • Conduct hands-on testing of CCF controls using established methodologies, and document results clearly so control owners can act on them.
  • Help build out and maintain the CCF module in Nordstrom's GRC tool — control status, testing schedules, evidence records, and ownership assignments.
  • Build and maintain RACIs for CCF controls, working with stakeholders to document clear ownership and accountability.
  • Collect, organize, and validate evidence from control owners, following up on gaps or missing documentation.
  • Partner with the Compliance team to build and test AI-assisted and automated workflows that streamline evidence collection and control testing, validating them on real controls to distinguish genuine time-savers from tasks still needing a human eye.
  • Catch anomalies, exceptions, or gaps that automated evidence pulls or AI-assisted review surface, and loop in senior analysts for follow-up.
  • Support development of basic remediation recommendations for identified control gaps, in partnership with senior analysts.
  • Track remediation activities and status updates to keep the compliance posture current.
  • Support the design of KPIs and KRIs for the CCF program, helping translate testing and remediation data into metrics leadership can use.
  • As you grow in the role, take direct ownership of specific CCF modules or control domains.

PCI DSS and Financial Control Audit — Build & Support

  • Conduct hands-on technical control testing for PCI DSS v4.x and Financial Control Audit — firewall rule reviews, access reviews, patch compliance, SDLC, change management, and log configuration checks.
  • PCI DSS scoping, evidence collection, and control testing activities across the annual assessment cycle.
  • Help build and maintain the CDE asset inventory — network segmentation documentation, data flow diagrams, and system component registers.
  • Build and maintain RACIs and governance documentation for the PCI program and Financial Control Audit, clarifying ownership across control owners and stakeholders.
  • Assist with periodic control testing: scheduling, evidence requests, and tracking exceptions through to resolution.
  • Support QSA fieldwork by coordinating document requests and helping prepare evidence packages under senior analyst guidance.
  • Support the design of PCI program KPIs and KRIs and track outcomes over time (e.g., open findings age, control test pass rates, inventory coverage).
  • Apply PCI DSS requirements to routine technical assessment scenarios and escalate anything outside established procedures.
  • As you grow in the role, take direct ownership of specific PCI modules or control domains.

Information & Documentation Management

  • Organize and maintain evidence repositories and information records with clear structure and categorization.
  • Extract and compile information from multiple sources (control owners, tickets, prior assessments) into clear, useful summaries.
  • Put AI tools to work drafting and summarizing documentation from source material, reviewing the output for accuracy before it goes into final records — and sharing what you learn about where it shines and where it doesn't.
  • Create and update process documentation, translating technical detail into business-friendly language.
  • Coordinate review cycles for documentation to keep it current and applicable.
  • Develop basic reports on control status, testing progress, and remediation metrics.

Operational Execution

  • Execute recurring GRC activities — findings updates, assessment tickets, evidence tracking — with minimal supervision.
  • Apply established procedures to routine technical assessment work; recognize when a situation falls outside standard protocol and escalate to senior analysts or program owners.
  • Perform quality checks on your own deliverables before handoff.
  • Take on increasing ownership of specific CCF and/or PCI modules as your technical testing, RACI, and governance experience grows.
  • Support audit and assessment preparation for both CCF and PCI, and coordinate handoffs with other team members.
  • Monitor operational metrics for your area and flag opportunities for process improvement.

You Own This If You Have…

Required Qualifications

  • 2+ years of hands-on professional experience running PCI DSS assessments, along with CCF and/or SOX experience or equivalent.
  • Working understanding of at least one relevant framework or standard (e.g., PCI DSS, NIST 800-30/CSF, ISO 27005, SOX, HIPAA) and the ability to apply it correctly to routine scenarios.
  • Experience with, or strong aptitude for, hands-on technical control testing (e.g., firewall rule reviews, access reviews, log configuration checks) and gap analysis.
  • Experience building or maintaining RACIs, or strong understanding of how to document control ownership and accountability.
  • Interest in and aptitude for metrics — comfortable helping design or track KPIs/KRIs that reflect program health.
  • Experience using AI and automation to make compliance work more effective — e.g., evidence pulls, LLM-assisted review — and the ability to evaluate what's actually a time-saver versus what still needs a human eye.
  • Strong organizational skills — able to juggle evidence collection, testing, and documentation across two programs without dropping things.
  • Clear written and verbal communication skills, including the ability to translate technical findings into business-friendly language.
  • Ability to work with minimal supervision on established processes, while knowing when to escalate.

Preferred Qualifications

  • Pursuing or holding an associate-level certification such as CISA, CRISC, ISO 27001 Implementer, CIPM, or CIPP.
  • Experience with a GRC platform (e.g., ServiceNow, OnSpring, AuditBoard, Archer or similar) for tracking findings and evidence.
  • Familiarity with cloud environments (AWS, Azure, or GCP) as they relate to compliance scope.


Pay Range Details

The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations. 
Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.

$121,500.00 - $188,500.00 Annual

 

 

We’ve got you covered…

Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources

   

This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_16.pdf

 

A few more important points...

The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.


For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site.


Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com


Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.

Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs.

 

Nordstrom keeps job postings open for at least one day after the posting date.

 

© 2026 Nordstrom, Inc
Bereit, sich bei Nordstrom zu bewerben?
Bei Nordstrom bewerben

Wie sich dieses Gehalt für Compliance vergleicht

Diese Stelle zahlt $155,000/yrunter der üblichen Spanne für Compliance Stellen.

$164,904 dem Median $200,450 $288,600

Übliche Spanne $179,769–$212,588/yr, aus 8 vergleichbaren Compliance Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Compliance ansehen →

Über Nordstrom

About Us We’re a fast-moving fashion company that started as a shoe store in 1901. This heritage of service is the foundation we’re building on as we provide convenience and true connection for our customers. We empower our people to be innovative, creative and focused on providing the best service to our customers. Through it all, we remain committed to leaving the world better than we found it. Whether you’re a genius engineer, a phenomenal salesperson or a supply chain pro, we invite you to bring your unique talents and join our team. We reward great work, promote from within and celebrate diversity. CUSTOMER OBSESSED We strive to know our customers better than anyone else. We listen, ant

Alle Jobs bei Nordstrom ansehen →

Ähnliche Jobs

Pinterest
Product Manager II, Content Compliance
Pinterest
⚡ Früh bewerben San Francisco, CA, US; Seattle... · standortgebunden $114,297–$235,319
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Nordstrom
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)
Nordstrom
⚡ Früh bewerben Seattle, WA Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 5 Tg.
PwC
Business Integrity Trade Compliance Senior Manager
PwC
⚡ Früh bewerben FL-Tampa Vor Ort $91,000–$321,500
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
Block
Staff Data Analyst, Block Compliance
Block
⚡ Früh bewerben Bay Area, CA, United States of... Vor Ort $171,800–$257,600
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
Block
Staff Data Analyst, Block Compliance
Block
⚡ Früh bewerben Denver, CO, United States of A... Vor Ort $171,800–$257,600
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
Block
Staff Data Analyst, Block Compliance
Block
⚡ Früh bewerben New York, NY, United States of... Vor Ort $171,800–$257,600
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
Anthropic
Engineering Manager, GRC Platform
Anthropic
⚡ Früh bewerben San Francisco, CA | New York C... Vor Ort $320,000–$405,000
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
Sonos
Principal Product Manager, Software: Identity, Security and Compliance
Sonos
⚡ Früh bewerben Boston, MA Hybrid $173,000–$216,300
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
Paytm
Regulatory Compliance- Manager
Paytm
⚡ Früh bewerben Noida, Uttar Pradesh Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Nordstrom

Alle Jobs bei Nordstrom ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos