Compliance Analyst 2 – PCI

Jobtailor

Seattle (WA)

On-site

USD 90,000 - 140,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Nordstrom is seeking a Compliance professional to conduct PCI DSS assessments and technical control testing within its GRC environment. You will build and maintain CCF and RACIs, coordinate evidence collection, and leverage AI to improve efficiency.

The role emphasizes translating technical findings into business language and driving remediation tracking across audit programs.

Qualifications

  • 2+ years of hands-on experience running PCI DSS assessments, and experience with CCF and/or SOX is preferred.
  • Familiar with frameworks such as PCI DSS, NIST CSF, ISO 27005, SOX, or HIPAA.
  • Hands-on testing and gap analysis of controls, with ability to document findings clearly.

Responsibilities

  • Conduct PCI DSS assessments and test controls; document results.
  • Build and maintain CCF module in Nordstrom's GRC tool including control status and evidence records.
  • Develop RACIs for CCF, PCI, and Financial Control Audit programs.

Skills

PCI DSS Assessment
Technical Control Testing
GRC Platform Experience
AI and Automation in Compliance
RACI Documentation

Education

CISA
CRISC
ISO 27001 Implementer
CIPM
CIPP

Tools

ServiceNow
OnSpring
AuditBoard
Archer
AWS
Azure
GCP

Job description

  • Conduct hands-on testing of Continuous Compliance Framework controls and document results
  • Build and maintain the CCF module in Nordstrom's GRC tool, including control status, testing schedules, evidence records, and ownership assignments
  • Build and maintain RACIs for CCF, PCI, and Financial Control Audit programs
  • Collect, organize, validate, and follow up on control evidence and documentation gaps
  • Build and test AI-assisted and automated workflows for evidence collection and control testing
  • Identify anomalies, exceptions, and gaps in automated evidence pulls or AI-assisted review
  • Support remediation recommendations and track remediation activities
  • Support design and tracking of KPIs and KRIs for compliance programs
  • Conduct technical control testing for PCI DSS v4.x and Financial Control Audit
  • Perform PCI DSS scoping, evidence collection, and testing across the annual assessment cycle
  • Maintain the CDE asset inventory, network segmentation documentation, data flow diagrams, and system component registers
  • Support QSA fieldwork by coordinating document requests and preparing evidence packages
  • Organize evidence repositories and information records
  • Compile information from multiple sources into clear summaries
  • Draft and summarize documentation using AI tools, reviewing outputs for accuracy
  • Create and update process documentation and translate technical details into business-friendly language
  • Develop reports on control status, testing progress, and remediation metrics
  • Execute recurring GRC activities with minimal supervision
  • Perform quality checks and coordinate audit and assessment preparation
  • Monitor operational metrics and flag process improvement opportunities
  • Take increasing ownership of CCF and/or PCI modules
Requirements
  • 2+ years of hands-on professional experience running PCI DSS assessments, along with CCF and/or SOX experience or equivalent
  • Working understanding of at least one relevant framework or standard, such as PCI DSS, NIST 800-30/CSF, ISO 27005, SOX, or HIPAA
  • Experience with or strong aptitude for hands-on technical control testing and gap analysis
  • Experience building or maintaining RACIs, or strong understanding of documenting control ownership and accountability
  • Interest in and aptitude for metrics, including KPIs/KRIs
  • Experience using AI and automation in compliance work and evaluating effectiveness
  • Strong organizational skills
  • Clear written and verbal communication skills, including translating technical findings into business-friendly language
  • Ability to work with minimal supervision and know when to elevate
  • Pursuing or holding an associate-level certification such as CISA, CRISC, ISO 27001 Implementer, CIPM, or CIPP (preferred)
  • Experience with a GRC platform such as ServiceNow, OnSpring, AuditBoard, or Archer (preferred)
  • Familiarity with cloud environments such as AWS, Azure, or GCP (preferred)
  • Must be available to work in the office at Nordstrom corporate headquarters a minimum of 4 days/week
  • Associate-level certification is preferred, not required
Core Competencies

Demonstrates expertise in conducting PCI DSS assessments and technical control testing while effectively utilizing AI and automation for compliance processes. Proficient in building and maintaining compliance frameworks, documenting control ownership, and translating technical findings into business-friendly language.

Highest-signal resume keywords
  • PCI DSS Assessment
  • Technical Control Testing
  • GRC Platform Experience
  • AI and Automation in Compliance
  • RACI Documentation
Hard Skills
  • Continuous Compliance Framework
  • Gap Analysis
  • KPI/KRI Tracking
  • Evidence Collection
  • Control Testing
  • Documentation Drafting
  • Quality Checks
  • Process Documentation
  • Metrics Evaluation
  • Anomaly Identification
Soft Skills
  • Organizational Skills
  • Clear Communication
  • Minimal Supervision
  • Escalation Awareness
Certifications & Qualifications
  • CISA
  • CRISC
  • ISO 27001 Implementer
  • CIPM
  • CIPP
Industry Keywords
  • PCI DSS
  • NIST 800-30
  • ISO 27005SOX
  • HIPAA
Tools & Technologies
  • ServiceNow
  • OnSpring
  • AuditBoard
  • Archer
  • AWS
  • Azure
  • GCP
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Compliance Analyst – Continuous Compliance Framework
Senior GRC Compliance Analyst – Continuous Compliance Framework

Jobtailor • Seattle (WA)

On-site
USD 150,000 - 190,000
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)

Relha LLC • Seattle (WA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Medical/Vision & Dental
Retirement plan
Paid time away
+1
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 142,000 - 221,000
Medical/Vision, Dental, Retirement
Paid Time Away
Life Insurance
+3
Senior Security GRC Analyst
Senior Security GRC Analyst

Jobtailor • California (MO)

On-site
USD 120,000 - 170,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
GRC Lead
GRC Lead

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
GRC Analyst – Public Sector
GRC Analyst – Public Sector

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior Security Compliance Analyst
Senior Security Compliance Analyst

Jobtailor • Burlington (MA)

On-site
USD 120,000 - 165,000
Cyber Compliance Analyst
Cyber Compliance Analyst

Jobtailor • Las Vegas (NV)

On-site
USD 90,000 - 130,000
Security & Compliance Analyst
Security & Compliance Analyst

OTG • New York (NY)

Remote
USD 90,000 - 110,000