Senior GRC Compliance Analyst – Continuous Compliance Framework

Jobtailor

Seattle (WA)

On-site

USD 150,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor in Seattle seeks a Compliance Architect to lead the transformation and ongoing maturation of the Common Control Framework (CCF). You will configure the CCF module in our GRC platform, define control language, testing frequency, and ownership, and drive KPI/KRI development.

The role requires 4–6 years in regulatory compliance with experience building CCF programs, plus strong AI/automation in control testing and cross-functional collaboration.

Qualifications

  • 4–6 years of regulatory compliance experience with cross-functional ownership.

Responsibilities

  • Lead transformation and maturation of the Common Control Framework (CCF).
  • Configure and manage the CCF module within GRC tools.
  • Define control language, testing cadence, and ownership.

Skills

Regulatory compliance
CCF/CCF program management
AI/automation in compliance
GRC tooling configuration
RACI and testing cadence
KPIs and KRIs development
Stakeholder engagement
Audit/PCI knowledge
Communication to leadership

Education

Bachelor's or Master’s in IT/Cybersecurity/CS

Tools

GRC Tools
AI Tools

Job description

  • Lead the transformation and ongoing maturation of the Common Control Framework (CCF)
  • Configure and manage the CCF module within Nordstrom's GRC tool
  • Define control language, testing frequency, implementation guidance, and ownership assignments
  • Build RACI models for every CCF control
  • Design and roll out KPIs and KRIs for the CCF and broader compliance program
  • Evaluate and pilot AI and automation tools for evidence collection and control testing
  • Define functional requirements for AI-assisted control testing and partner with Engineers on complex integrations
  • Build and implement automation and AI-driven solutions for contained use cases
  • Identify controls suitable for automation or continuous monitoring and build an implementation roadmap
  • Contribute to self-service compliance tooling, dashboards, and interfaces
  • Build reusable testing and automation patterns
  • Integrate CCF, risk management, and governance programs with aligned controls, evidence, and reporting
  • Harmonize compliance controls with risk appetite and governance structures
  • Participate in cross-GRC planning and develop unified leadership reporting
  • Support PCI DSS assessments and serve as a subject matter partner to the PCI program owner
  • Design and implement enterprise compliance assessment methodologies across regulatory domains
  • Develop operational standards and quality criteria for compliance processes
  • Advise on control testing approaches, evidence collection, and documentation quality
  • Engage stakeholders, lead workshops, and facilitate working sessions
  • Liaise with internal and external auditors
  • Align CCF activities with strategic business and security objectives
  • Contribute to the Compliance Assessment team's roadmap toward continuous control monitoring and self-service tools
  • Coordinate cross-functional compliance initiatives
Requirements
  • 4–6 years of regulatory compliance experience with demonstrated ownership of cross-functional compliance initiatives
  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs
  • Experience leveraging AI and automation to enhance CCF and control testing effectiveness
  • Experience with AI/ML-assisted compliance or security monitoring tools, including designing prompts, workflows, or integrations supporting control testing at scale
  • Hands‑on experience configuring compliance programs within GRC tools and platforms
  • Experience defining control language, RACI, and testing cadence with stakeholders
  • Experience developing KPIs and KRIs for compliance programs
  • Familiarity with PCI DSS sufficient to support assessments and control testing
  • Experience partnering with engineering or security teams on automated or AI‑assisted control testing and evidence collection
  • Proven ability to align compliance operations with strategic business objectives
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent work experience
  • Deep knowledge of multiple regulatory frameworks, including CIS, NIST, SOX, HIPAA, CCPA, and PCI DSS v4.x
  • Experience testing technical controls and documenting audit evidence
  • Understanding of enterprise compliance architecture and integrated control frameworks
  • Familiarity with GRC tool configuration and workflow design
  • Working knowledge of AI/automation tools for compliance testing and evidence collection
  • Strong control framework design and documentation capabilities
  • Ability to develop and communicate KPIs/KRIs and compliance metrics to leadership
  • Strong written and verbal communication skills, including presenting to senior leadership
  • Ability to work autonomously, manage competing priorities, and drive programs to completion
  • Ability to work across risk, governance, and compliance teams
  • Professional certifications such as CISA, CRISC, CIPP, or CIPM preferred
  • PCI ISA, QSA, or other PCI-related certifications a plus
  • Experience with GRC platform implementation and administration preferred
  • Background in regulatory consulting or internal/external audit preferred
  • Experience leading enterprise‑wide compliance transformation initiatives preferred
  • Proficiency in compliance automation, scripting, or security tooling preferred
Core Competencies

Demonstrates expertise in regulatory compliance frameworks, particularly in building and managing Common Control Frameworks (CCF) and leveraging AI and automation for compliance testing. Proven ability to align compliance operations with strategic business objectives and develop key performance indicators (KPIs) and key risk indicators (KRIs) for effective compliance management.

Highest-signal resume keywords
  • Common Control Framework (CCF) Management
  • AI/ML-Assisted Compliance Tools
  • GRC Tool Configuration
  • Regulatory Compliance Experience
  • KPI/KRI Development
Hard Skills
  • Regulatory Compliance
  • Control Framework Design
  • Compliance Automation
  • Evidence Collection
  • Control Testing
  • Risk Management
  • Continuous Compliance Framework (CCF)
  • Documentation Quality
  • Enterprise Compliance Architecture
  • Workflow Design
Soft Skills
  • Strong Communication Skills
  • Stakeholder Engagement
  • Workshop Facilitation
  • Autonomous Work
  • Priority Management
Certifications & Qualifications
  • CISA
  • CRISC
  • CIPP
  • CIPM
  • PCI ISA
  • PCI QSA
Industry Keywords
  • PCI DSS
  • NIST
  • SOX
  • HIPAA
  • CCPA
  • CIS
  • Compliance Assessment
  • Audit Evidence
  • Regulatory Frameworks
  • Compliance Metrics
Tools & Technologies
  • GRC Tools
  • AI Tools
  • Automation Tools
  • Compliance Dashboards
  • Self-Service Compliance Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance Analyst 2 – PCI
Compliance Analyst 2 – PCI

Jobtailor • Seattle (WA)

On-site
USD 90,000 - 140,000
GRC Lead
GRC Lead

Jobtailor • Houston (TX)

On-site
USD 120,000 - 180,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)

Relha LLC • Seattle (WA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Medical/Vision & Dental
Retirement plan
Paid time away
+1
GRC Analyst – Public Sector
GRC Analyst – Public Sector

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior Technical Governance Program Manager
Senior Technical Governance Program Manager

Jobtailor • California (MO)

On-site
USD 120,000 - 190,000
Senior Manager – GRC Financial Services Technology
Senior Manager – GRC Financial Services Technology

Jobtailor • Illinois

On-site
USD 110,000 - 160,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Jobtailor • California (MO)

On-site
USD 120,000 - 170,000
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Senior Security Compliance Analyst
Senior Security Compliance Analyst

Jobtailor • Burlington (MA)

On-site
USD 120,000 - 165,000