Senior Compliance Analyst – Continuous Compliance Framework (Hybrid - Seattle)

Nordstrom

Seattle (WA)

On-site

USD 142,000 - 220,500

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical/Vision and Dental Insurance
Retirement Plan
Paid Time Off

Job summary

Nordstrom is looking for a Senior Analyst to join the Governance, Risk, and Compliance (GRC) team. This role involves leading the transformation of our Continuous Compliance Framework and fostering collaboration across various business units.

The ideal candidate will have 4-6 years of regulatory compliance experience, a strong background in compliance program management, and excellent stakeholder engagement skills. The position offers a compensation range of $142,000 - $220,500 annually and includes a comprehensive benefits package.

Qualifications

  • 4–6 years of regulatory compliance experience with demonstrated ownership of cross-functional compliance initiatives.
  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs.
  • Hands-on experience configuring compliance programs within GRC tools and platforms.

Responsibilities

  • Lead the transformation and ongoing maturation of the CCF.
  • Collaborate with stakeholders across teams to define control language and testing frequency.
  • Engage cross-functional stakeholders to gather input on control design and testing.

Skills

Regulatory compliance experience
Stakeholder engagement
Control framework design
Excellent communication skills
Project management

Education

Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or related field

Tools

GRC tools

Job description

Job Description

If you’re a compliance pro who thrives on building scalable, tech-enabled frameworks and wants to be at the forefront of AI-assisted testing and automation, we want to meet you. We are evolving our compliance program to move at the speed of our business, and we need a strategic lead to take the wheel. Forget the traditional "box-checking" mentality. This role is for a compliance professional who thrives on building scalable, tech-enabled frameworks and wants to be at the forefront of AI-assisted testing and automation. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team. In this role, you will lead the transformation and maturation of our existing Continuous Compliance Framework (CCF)—tailoring controls to our organization, acting as the functional lead for the CCF module in our GRC tool, and collaborating across the business to define the parameters that keep us secure. A critical aspect of this role is cross-functional collaboration with the Governance and Risk teams to ensure the CCF, risk management, and governance programs are integrated and mutually reinforcing. You will also support our audits and assessments such as PCI, contributing to the team’s broader compliance posture.


A Day in the Life

Continuous Compliance Framework (CCF) Transformation


  • Lead the transformation and ongoing maturation of the CCF, including updating and tailoring controls to reflect the current organizational environment, risk profile, and regulatory landscape.

  • Configure and manage the CCF program module within Nordstrom’s GRC tool, ensuring accurate representation of controls, testing schedules, evidence requirements, and ownership assignments.

  • Collaborate with stakeholders across business and technology teams to define control language, testing frequency, and implementation guidance that is practical and aligned with operational realities.

  • Document RACI models for all controls within the CCF, establishing clear ownership and accountability across teams.

  • Design and implement KPIs and KRIs for the CCF and broader compliance program, enabling data-driven reporting on compliance health and risk exposure.


GRC Program Integration


  • Work closely with the Governance and Risk teams to ensure the CCF, risk management program, and governance program are integrated, with aligned control sets, shared evidence, and coordinated reporting.

  • Identify opportunities to harmonize compliance controls with risk appetite and governance structures, reducing duplication and improving program efficiency.

  • Participate in cross-GRC planning sessions to align timelines, control mappings, and stakeholder engagement strategies across all three programs.

  • Support the development and communication of a unified GRC narrative for leadership, translating program health across risk, governance, and compliance into cohesive insights.


Compliance Assessment & Methodology


  • Partner with Security Engineers to design AI-driven testing and automated evidence collection features within the GRC tool; the Senior Analyst provides functional requirements while Engineers lead technical builds.

  • Serve as a subject matter partner to the PCI program owner to ensure CCF controls satisfy PCI DSS requirements and support the annual PCI assessment process.

  • Design and implement enterprise compliance assessment methodologies that integrate multiple regulatory domains (e.g., NIST, CIS, SOX, HIPAA, CCPA).

  • Develop operational standards and quality criteria for compliance processes, ensuring consistency and effectiveness across the organization.

  • Serve as a subject matter resource for control testing approaches, evidence collection, and documentation quality.


Stakeholder Engagement


  • Engage cross-functional stakeholders to gather input on control design, testing feasibility, and ownership, building lasting partnerships that embed compliance into the technology ecosystem.

  • Lead workshops and working sessions with stakeholders to define control requirements, discuss testing approaches, and align on program direction.

  • Serve as a liaison with internal and external auditors as needed, representing the organization’s compliance posture and program maturity.


Strategic Alignment & Program Leadership


  • Align CCF activities with strategic business and security objectives by participating in medium-term planning (6–18 months) and ensuring compliance initiatives support organizational goals.

  • Contribute to the strategic vision and roadmap for the Compliance Assessment team, developing reusable, scalable solutions that enhance program efficiency and support organizational growth.

  • Coordinate cross-functional compliance initiatives to ensure comprehensive regulatory coverage and consistent execution.


You Own This If You Have…

Experience

Required Qualifications



  • 4–6 years of regulatory compliance experience with demonstrated ownership of cross-functional compliance initiatives.

  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs.

  • Hands‑on experience configuring compliance programs within GRC tools and platforms.

  • Experience working with stakeholders to define control language, RACI, and testing cadence.

  • Demonstrated experience developing KPIs and KRIs for compliance programs.

  • Familiarity with PCI DSS sufficient to support assessments and control testing activities.

  • Experience partnering with engineering or security teams to implement automated or AI‑assisted control testing.

  • Proven ability to align compliance operations with strategic business objectives.


Education


  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent work experience.


Technical Knowledge


  • Deep knowledge about multiple regulatory frameworks (CIS, NIST, SOX, HIPAA, CCPA, PCI DSS v4.x) and their control implications.

  • Experience testing technical controls and documenting evidence to support audits.

  • Understanding of enterprise compliance architecture and integrated control frameworks.

  • Familiarity with GRC tool configuration and workflow design.

  • Knowledge of AI/automation tools applicable to compliance testing and evidence collection.


Skills


  • Strong control framework design and documentation capabilities.

  • Excellent stakeholder engagement and facilitation skills; able to drive consensus across technical and non-technical audiences.

  • Ability to develop and communicate KPIs/KRIs and compliance metrics to leadership.

  • Strong written and verbal communication skills, including experience presenting to senior leadership.

  • Self‑directed and results‑oriented; able to operate with autonomy, manage competing priorities, and drive programs to completion.

  • Collaborative mindset with the ability to work effectively across the GRC triad (risk, governance, compliance).


Certifications

Preferred Qualifications



  • Professional certifications preferred: CISA, CRISC, CIPP, CIPM, or equivalent.

  • PCI ISA, QSA, or other PCI-related certifications a plus.


Additional Experience


  • Experience with GRC platform implementation and administration.

  • Background in regulatory consulting or internal/external audit.

  • Experience leading enterprise-wide compliance transformation initiatives.

  • Proficiency in compliance automation, scripting, or security tooling.

  • Familiarity with AI/ML‑assisted compliance or security monitoring tools.


Pay Range Details

$142,000.00 - $220,500.00 Annual


Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.


The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations.


Benefits


  • Medical/Vision, Dental, Retirement and Paid Time Away

  • Life Insurance and Disability

  • Merchandise Discount and EAP Resources


This position may be eligible for performance-based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_17-19.pdf


Legal Notices

For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site.


Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com.


Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.


Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs.


Nordstrom keeps job postings open for at least one day after the posting date.


© 2026 Nordstrom, Inc

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Identity Security Operations
Senior Manager, Identity Security Operations

Relha LLC • Seattle (WA), Northern (KY)

Hybrid
USD 191,000 - 297,000
Medical/Vision
Dental
Retirement
+5
Engineer 2 - Supply Chain
Engineer 2 - Supply Chain

Relha LLC • Seattle (WA), Northern (KY)

Hybrid
USD 122,000 - 189,000
Medical/Vision, Dental
Retirement Plan
Paid Time Off
+2
Senior Program Manager, Human Resource Compliance (Hybrid, Seattle)
Senior Program Manager, Human Resource Compliance (Hybrid, Seattle)

Nordstrom • Seattle (WA)

On-site
USD 103,000 - 175,000
Medical/Vision and Dental Insurance
Retirement Plans
Paid Time Away
+1
Data Analyst 3, Supply Chain Intelligence - (Hybrid - Seattle, WA)
Data Analyst 3, Supply Chain Intelligence - (Hybrid - Seattle, WA)

Nordstrom • Seattle (WA)

On-site
USD 103,000 - 171,000
Merchandise Discount
Benefits Package
Engineer 2 - Inventory
Engineer 2 - Inventory

Nordstrom • Seattle (WA)

On-site
USD 121,000 - 189,000
Medical/Vision insurance
Dental insurance
401k plan
+1
Senior Technical Program Manager - Security Platform Engineering (Hybrid - Seattle)
Senior Technical Program Manager - Security Platform Engineering (Hybrid - Seattle)

Nordstrom, Inc. • Seattle (WA)

Hybrid
USD 142,000 - 221,000
Data Engineer 1, Insights Delivery Finance (Hybrid - Seattle, WA)
Data Engineer 1, Insights Delivery Finance (Hybrid - Seattle, WA)

Relha LLC • Seattle (WA), Northern (KY)

Hybrid
USD 105,000 - 163,000
Senior Engineer 2, Merchandise Order Management - (Hybrid, Seattle)
Senior Engineer 2, Merchandise Order Management - (Hybrid, Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 166,000 - 258,000
Medical/Vision, Dental, Retirement and
Paid Time Away
Life Insurance and Disability
+1
Product Manager II — Customer Data Platform & Marketing Technology (Hybrid - Seattle)
Product Manager II — Customer Data Platform & Marketing Technology (Hybrid - Seattle)

Nordstrom • Seattle (WA)

On-site
USD 122,000 - 189,000
Medical/Vision/Dental
Retirement & PTO
Life Insurance
+2
Data Analyst 3 - Store Operations
Data Analyst 3 - Store Operations

Nordstrom • United States

On-site
USD 90,000 - 140,000
Medical & Vision coverage
Dental coverage
Merchandise Discount
+2