
Compliance Analyst 2 - PCI (Hybrid - Seattle)
Nordstrom
Job description
Job Description
This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.
Compliance doesn't have to mean dusty binders and once-a-year fire drills — on this team, it's about building programs that are sharp, current, and built to last. Nordstrom's Governance, Risk & Compliance (GRC) team is looking for a Compliance Analyst to help build out three of our most active programs: the Continuous Compliance Framework (CCF), Financial Control Audit, and PCI DSS. All three are actively maturing, and you'll be right there building alongside us — standing up RACIs, shaping the KPIs/KRIs that show program health, and helping put governance structures in place that actually hold. This isn't a "maintain what already exists" role; it's a "help us build the thing" role.
You'll also team up with the rest of the Compliance crew to find smarter, faster ways to get the work done — putting AI and automation to work so evidence collection and control testing stop feeling like a grind and start feeling like a well-oiled machine.
This is a great fit for someone who loves getting hands-on: technical control testing, evidence and documentation, RACI and governance design, program metrics — the whole toolkit. You'll work closely with senior analysts across both programs, and as things mature, you'll pick up direct ownership of specific pieces of CCF and/or PCI.
Come for the compliance, stay for the team that actually makes it fun.
A Day in the Life…
Continuous Compliance Framework (CCF) — Build & Support
-
Conduct hands-on testing of CCF controls using established methodologies, and document results clearly so control owners can act on them.
-
Help build out and maintain the CCF module in Nordstrom's GRC tool — control status, testing schedules, evidence records, and ownership assignments.
-
Build and maintain RACIs for CCF controls, working with stakeholders to document clear ownership and accountability.
-
Collect, organize, and validate evidence from control owners, following up on gaps or missing documentation.
-
Partner with the Compliance team to build and test AI-assisted and automated workflows that streamline evidence collection and control testing, validating them on real controls to distinguish genuine time-savers from tasks still needing a human eye.
-
Catch anomalies, exceptions, or gaps that automated evidence pulls or AI-assisted review surface, and loop in senior analysts for follow-up.
-
Support development of basic remediation recommendations for identified control gaps, in partnership with senior analysts.
-
Track remediation activities and status updates to keep the compliance posture current.
-
Support the design of KPIs and KRIs for the CCF program, helping translate testing and remediation data into metrics leadership can use.
-
As you grow in the role, take direct ownership of specific CCF modules or control domains.
PCI DSS and Financial Control Audit — Build & Support
-
Conduct hands-on technical control testing for PCI DSS v4.x and Financial Control Audit — firewall rule reviews, access reviews, patch compliance, SDLC, change management, and log configuration checks.
-
PCI DSS scoping, evidence collection, and control testing activities across the annual assessment cycle.
-
Help build and maintain the CDE asset inventory — network segmentation documentation, data flow diagrams, and system component registers.
-
Build and maintain RACIs and governance documentation for the PCI program and Financial Control Audit, clarifying ownership across control owners and stakeholders.
-
Assist with periodic control testing: scheduling, evidence requests, and tracking exceptions through to resolution.
-
Support QSA fieldwork by coordinating document requests and helping prepare evidence packages under senior analyst guidance.
-
Support the design of PCI program KPIs and KRIs and track outcomes over time (e.g., open findings age, control test pass rates, inventory coverage).
-
Apply PCI DSS requirements to routine technical assessment scenarios and escalate anything outside established procedures.
-
As you grow in the role, take direct ownership of specific PCI modules or control domains.
Information & Documentation Management
-
Organize and maintain evidence repositories and information records with clear structure and categorization.
-
Extract and compile information from multiple sources (control owners, tickets, prior assessments) into clear, useful summaries.
-
Put AI tools to work drafting and summarizing documentation from source material, reviewing the output for accuracy before it goes into final records — and sharing what you learn about where it shines and where it doesn't.
-
Create and update process documentation, translating technical detail into business-friendly language.
-
Coordinate review cycles for documentation to keep it current and applicable.
-
Develop basic reports on control status, testing progress, and remediation metrics.
Operational Execution
-
Execute recurring GRC activities — findings updates, assessment tickets, evidence tracking — with minimal supervision.
-
Apply established procedures to routine technical assessment work; recognize when a situation falls outside standard protocol and escalate to senior analysts or program owners.
-
Perform quality checks on your own deliverables before handoff.
-
Take on increasing ownership of specific CCF and/or PCI modules as your technical testing, RACI, and governance experience grows.
-
Support audit and assessment preparation for both CCF and PCI, and coordinate handoffs with other team members.
-
Monitor operational metrics for your area and flag opportunities for process improvement.
You Own This If You Have…
Required Qualifications
-
2+ years of hands-on professional experience running PCI DSS assessments, along with CCF and/or SOX experience or equivalent.
-
Working understanding of at least one relevant framework or standard (e.g., PCI DSS, NIST 800-30/CSF, ISO 27005, SOX, HIPAA) and the ability to apply it correctly to routine scenarios.
-
Experience with, or strong aptitude for, hands-on technical control testing (e.g., firewall rule reviews, access reviews, log configuration checks) and gap analysis.
-
Experience building or maintaining RACIs, or strong understanding of how to document control ownership and accountability.
-
Interest in and aptitude for metrics — comfortable helping design or track KPIs/KRIs that reflect program health.
-
Experience using AI and automation to make compliance work more effective — e.g., evidence pulls, LLM-assisted review — and the ability to evaluate what's actually a time-saver versus what still needs a human eye.
-
Strong organizational skills — able to juggle evidence collection, testing, and documentation across two programs without dropping things.
-
Clear written and verbal communication skills, including the ability to translate technical findings into business-friendly language.
-
Ability to work with minimal supervision on established processes, while knowing when to escalate.
Preferred Qualifications
-
Pursuing or holding an associate-level certification such as CISA, CRISC, ISO 27001 Implementer, CIPM, or CIPP.
-
Experience with a GRC platform (e.g., ServiceNow, OnSpring, AuditBoard, Archer or similar) for tracking findings and evidence.
-
Familiarity with cloud environments (AWS, Azure, or GCP) as they relate to compliance scope.
Pay Range Details
The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations.
Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.
$121,500.00 - $188,500.00 Annual
We’ve got you covered…
Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:
-
Medical/Vision, Dental, Retirement and Paid Time Away
-
Life Insurance and Disability
-
Merchandise Discount and EAP Resources
This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_16.pdf
A few more important points...
The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.
For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site.
Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com.
Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.
Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs.
Nordstrom keeps job postings open for at least one day after the posting date.
© 2026 Nordstrom, Inc