Senior Compliance Analyst – Continuous Compliance Framework

Jobtailor

Seattle (WA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nordstrom is seeking a regulatory compliance professional to lead the transformation and maturation of the Continuous Compliance Framework (CCF) within our GRC environment. You will collaborate with business and technology partners to define control language, testing cadence, and implementation guidance.

The role focuses on KPI and KRI design, RACI documentation, and integration with risk and governance programs.

Qualifications

  • 4-6 years of regulatory compliance experience.
  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs.
  • Hands-on experience configuring compliance programs within GRC tools and platforms.
  • Experience working with stakeholders to define control language, RACI, and testing cadence.
  • Demonstrated experience developing KPIs and KRIs for compliance programs.
  • Familiarity with PCI DSS sufficient to support assessments and control testing activities.
  • Experience partnering with engineering or security teams to implement automated or AI-assisted control testing.
  • Proven ability to align compliance operations with strategic business objectives.

Responsibilities

  • Lead the transformation and ongoing maturation of the CCF.
  • Configure and manage the CCF program module within Nordstrom's GRC tool.
  • Collaborate with stakeholders across business and technology teams to define control language, testing frequency, and implementation guidance.
  • Document RACI models for all controls within the CCF.
  • Design and implement KPIs and KRIs for the CCF.
  • Work closely with Governance and Risk teams to ensure the CCF, risk management program, and governance program are integrated.
  • Identify opportunities to harmonize compliance controls with risk appetite and governance structures.
  • Participate in cross-GRC planning sessions.
  • Support the development and communication of a unified GRC narrative for leadership.
  • Partner with Security Engineers to design AI-driven testing and automated evidence collection features.

Skills

Regulatory compliance experience
GRC tool configuration
Stakeholder engagement
AI-driven testing familiarity

Education

Bachelor's or Master's in IT / Cybersecurity or related field

Tools

GRC tools configuration
PCI DSS familiarity

Job description

  • Lead the transformation and ongoing maturation of the CCF
  • Configure and manage the CCF program module within Nordstrom's GRC tool
  • Collaborate with stakeholders across business and technology teams to define control language, testing frequency, and implementation guidance
  • Document RACI models for all controls within the CCF
  • Design and implement KPIs and KRIs for the CCF
  • Work closely with the Governance and Risk teams to ensure the CCF, risk management program, and governance program are integrated
  • Identify opportunities to harmonize compliance controls with risk appetite and governance structures
  • Participate in cross-GRC planning sessions
  • Support the development and communication of a unified GRC narrative for leadership
  • Partner with Security Engineers to design AI-driven testing and automated evidence collection features
Requirements
  • 4-6 years of regulatory compliance experience
  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs
  • Hands-on experience configuring compliance programs within GRC tools and platforms
  • Experience working with stakeholders to define control language, RACI, and testing cadence
  • Demonstrated experience developing KPIs and KRIs for compliance programs
  • Familiarity with PCI DSS sufficient to support assessments and control testing activities
  • Experience partnering with engineering or security teams to implement automated or AI-assisted control testing
  • Proven ability to align compliance operations with strategic business objectives
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent work experience
Core Competencies

Demonstrates expertise in managing and configuring Continuous Compliance Framework (CCF) programs within GRC tools, with a strong focus on developing KPIs and KRIs. Collaborates effectively with cross-functional teams to align compliance operations with strategic business objectives.

Highest-signal resume keywords
  • Continuous Compliance Framework (CCF) Management
  • GRC Tool Configuration
  • KPI and KRI Development
  • Regulatory Compliance Experience
  • Collaboration with Security Teams
ATS Optimization Keywords
Hard Skills
  • Regulatory Compliance
  • Continuous Compliance Framework (CCF)
  • GRC Tools
  • KPI Development
  • KRI Development
  • Control Language Definition
  • RACI Documentation
  • Automated Control Testing
  • AI-Driven Testing
  • PCI DSS Familiarity
Soft Skills
  • Collaboration
  • Communication
  • Stakeholder Engagement
  • Strategic Alignment
Industry Keywords
  • Governance
  • Risk Management
  • Compliance Controls
  • Control Testing
  • Risk Appetite
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Compliance Analyst — CCF & GRC Leader
Senior Compliance Analyst — CCF & GRC Leader

Jobtailor • Seattle (WA)

On-site
USD 120,000 - 160,000
Senior Technical Compliance Analyst
Senior Technical Compliance Analyst

Jobtailor • Kansas

On-site
USD 70,000 - 90,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Cyber GRC Specialist
Cyber GRC Specialist

Jobtailor • Washington

On-site
USD 90,000 - 130,000
Security GRC Specialist
Security GRC Specialist

Jobtailor • South San Francisco (CA)

On-site
USD 170,000 - 210,000
Senior Compliance Analyst – Continuous Compliance Framework (Hybrid - Seattle)
Senior Compliance Analyst – Continuous Compliance Framework (Hybrid - Seattle)

Nordstrom • Seattle (WA)

On-site
USD 142,000 - 221,000
Medical/Vision and Dental Insurance
Retirement Plan
Paid Time Off
Senior GRC Specialist
Senior GRC Specialist

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Enterprise Compliance and Operational Risk Manager
Enterprise Compliance and Operational Risk Manager

Jobtailor • Alabama

On-site
USD 120,000 - 180,000
Health insurance
Senior Associate, Cyber Strategy, Risk & Compliance
Senior Associate, Cyber Strategy, Risk & Compliance

Jobtailor • Washington

On-site
USD 75,000 - 110,000
Head of Security, GRC
Head of Security, GRC

Jobtailor • California (MO)

On-site
USD 200,000 - 280,000