Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)

Nordstrom

Seattle (WA)

Hybrid

USD 142,000 - 221,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical/Vision, Dental, Retirement
Paid Time Away
Life Insurance
Disability insurance
Merchandise Discount
EAP Resources

Job summary

Nordstrom is seeking a Senior Analyst for the Governance, Risk and Compliance (GRC) program. You will own the Common Control Framework (CCF) from inception, mature it, run it, and test control effectiveness in a scalable, AI-enabled environment.

This role requires cross‑functional collaboration with GRC, risk, and compliance teams to ensure controls align with evolving threats and regulations. Hybrid in Seattle, WA, with a minimum four in‑office days per week.

Qualifications

  • Experience leading cross-functional compliance initiatives.
  • Ability to design control language, RACI, and testing cadence.
  • Experience with PCI DSS and PCI assessments.
  • Configuring and maturing a Common Control Framework (CCF).

Responsibilities

  • Lead transformation and maturation of the CCF with tailored controls.
  • Configure CCF module in Nordstrom's GRC tool with controls, testing schedules, and ownership.
  • Collaborate with business and tech teams on control language and implementation guidance.
  • Build RACI models for all controls and design KPIs/KRIs for the program.
  • Develop and pilot AI/automation to cut evidence review time and improve testing.

Skills

Regulatory compliance
Cross-functional collaboration
GRC tooling
AI/Automation
PCI familiarity
Stakeholder engagement
Program leadership

Education

Bachelor's or Master's in IT/CS/Cybersecurity

Tools

GRC tools/platforms

Job description

Job Description

This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position.

We're turning “prove it” into a fast, repeatable habit instead of a fire drill. If you're a compliance pro who thrives on building scalable, tech-enabled frameworks and wants to be at the forefront of AI-assisted testing and automation, we want to meet you.

Ditch the old-school “box-checking” mentality — that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own the Common Control Framework (CCF) from the ground up: maturing it, running it, and testing control effectiveness so it keeps pace with evolving threats and regulations — and so audits go from dreaded to no-big-deal. You'll be the functional lead for the CCF module in our GRC tool and the driving force behind automating evidence collection and control testing, so your team (and everyone you support) can stop doing the same manual grind on repeat.

A critical aspect of this role is cross-functional collaboration with the Governance and Risk teams to ensure the CCF, risk management, and governance programs are integrated and mutually reinforcing. You'll also support audits and assessments such as PCI, contributing to a security posture the organization can trust — proactive instead of reactive, and built to scale.

A Day in the Life...
Continuous Compliance Framework (CCF) Transformation
  • Lead the transformation and ongoing maturation of the CCF, tailoring controls to reflect the current organizational environment, risk profile, and regulatory landscape.
  • Configure and manage the CCF program module within Nordstrom's GRC tool, ensuring accurate representation of controls, testing schedules, evidence requirements, and ownership assignments.
  • Collaborate with stakeholders across business and technology teams to define control language, testing frequency, and implementation guidance that's practical and aligned with operational realities — no black boxes, no ambiguity about who owns what.
  • Build out RACI models for every control in the CCF, so ownership and accountability are crystal clear across teams.
  • Design and roll out KPIs and KRIs for the CCF and broader compliance program, laying the groundwork for real-time control health monitoring instead of once-a-year snapshots.
AI & Automation for Evidence Collection and Control Testing
  • Think outside the (compliance) box — dream up new, innovative ways to manage the CCF and boost compliance effectiveness, and get hands‑on evaluating and piloting AI/automation tools that cut evidence review time, catch control exceptions earlier, and free you up for the work that actually needs a human brain.
  • Define functional requirements for AI‑assisted control testing (e.g., automated evidence validation, anomaly detection in control performance, natural-language summarization of audit evidence), partnering with Engineers on complex builds requiring multiple system integrations, while directly building and implementing automation and AI‑driven solutions for more contained use cases.
  • Identify controls that are strong candidates for automation or continuous monitoring based on testing frequency, evidence type, and data source availability, and build the roadmap to get there.
  • Contribute to the long‑term vision for self‑service compliance tooling — dashboards or interfaces that let control owners and stakeholders check their own compliance posture without waiting on the GRC team.
  • Build reusable, scalable testing and automation patterns so the team isn't reinventing the wheel every time a new framework or regulation comes into scope.
GRC Program Integration
  • Work closely with the Governance and Risk teams to ensure the CCF, risk management program, and governance program are integrated, with aligned control sets, shared evidence, and coordinated reporting.
  • Identify opportunities to harmonize compliance controls with risk appetite and governance structures, reducing duplication and improving program efficiency.
  • Participate in cross-GRC planning sessions to align timelines, control mappings, and stakeholder engagement strategies across all three programs.
  • Support the development and communication of a unified GRC narrative for leadership, translating program health across risk, governance, and compliance into cohesive insights.
Compliance Assessment & Methodology
  • Serve as a subject matter partner to the PCI program owner to ensure CCF controls satisfy PCI DSS requirements and support the annual PCI assessment process.
  • Design and implement enterprise compliance assessment methodologies that integrate multiple regulatory domains (e.g., NIST, CIS, SOX, HIPAA, CCPA).
  • Develop operational standards and quality criteria for compliance processes, ensuring consistency and effectiveness across the organization, and pushing control testing toward continuous rather than once-a-year scrambles.
  • Serve as a subject matter resource for control testing approaches, evidence collection, and documentation quality.
Stakeholder Engagement
  • Engage cross-functional stakeholders to gather input on control design, testing feasibility, and ownership, building lasting partnerships that embed compliance into the technology ecosystem.
  • Lead workshops and working sessions with stakeholders to define control requirements, discuss testing approaches, and align on program direction.
  • Serve as a liaison with internal and external auditors as needed, representing the organization’s compliance posture and program maturity.
  • Champion transparent communication and shared ownership as the default way the team operates with the rest of the business.
Strategic Alignment & Program Leadership
  • Align CCF activities with strategic business and security objectives by participating in medium‑term planning (6–18 months) and ensuring compliance initiatives support organizational goals.
  • Contribute to the strategic vision and roadmap for the Compliance Assessment team, including the path toward continuous control monitoring and self‑service compliance tools.
  • Coordinate cross‑functional compliance initiatives to ensure comprehensive regulatory coverage and consistent execution.
You Own This If You Have...
Experience
Required Qualifications
  • 4–6 years of regulatory compliance experience with demonstrated ownership of cross‑functional compliance initiatives.
  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs.
  • Experience leveraging AI and automation enhance CCF and control testing effectiveness and with AI/ML‑assisted compliance or security monitoring tools, including designing prompts, workflows, or integrations that support control testing at scale.
  • Hands‑on experience configuring compliance programs within GRC tools and platforms.
  • Experience working with stakeholders to define control language, RACI, and testing cadence.
  • Demonstrated experience developing KPIs and KRIs for compliance programs.
  • Familiarity with PCI DSS sufficient to support assessments and control testing activities.
  • Experience partnering with engineers or security teams to design or implement automated or AI‑assisted control testing and evidence collection.
  • Proven ability to align compliance operations with strategic business objectives.
Education
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent work experience.
Technical Knowledge
  • Deep knowledge about multiple regulatory frameworks (CIS, NIST, SOX, HIPAA, CCPA, PCI DSS v4.x) and their control implications.
  • Experience testing technical controls and documenting evidence to support audits.
  • Understanding of enterprise compliance architecture and integrated control frameworks.
  • Familiarity with GRC tool configuration and workflow design.
  • Working knowledge of AI/automation tools applicable to compliance testing and evidence collection (e.g., automated evidence pulls, LLM‑assisted evidence review, anomaly detection for control exceptions).
Skills
  • Strong control framework design and documentation capabilities.
  • Excellent stakeholder engagement and facilitation skills; able to drive consensus across technical and non‑technical audiences.
  • Ability to develop and communicate KPIs/KRIs and compliance metrics to leadership.
  • Strong written and verbal communication skills, including experience presenting to senior leadership.
  • Self‑directed and results‑oriented; able to operate with autonomy, manage competing priorities, and drive programs to completion.
  • Collaborative mindset with the ability to work effectively across the GRC triad (risk, governance, compliance).
  • Comfort identifying where automation adds real value versus where human judgment is still required.
Preferred Qualifications
Certifications
  • Professional certifications preferred: CISA, CRISC, CIPP, CIPM, or equivalent.
  • PCI ISA, QSA, or other PCI-related certifications a plus.
Additional Experience
  • Experience with GRC platform implementation and administration.
  • Background in regulatory consulting or internal/external audit.
  • Experience leading enterprise‑wide compliance transformation initiatives.
  • Proficiency in compliance automation, scripting, or security tooling.
Pay Range Details

The pay range(s) below has been provided in compliance with state specific laws. Pay ranges may be different for other locations.

Pay offers are dependent on the location, as well as job-related knowledge, skills, and experience.

$142,000.00 - $220,500.00 Annual

We’ve got you covered...
Benefits

Our employees are our most important asset and that’s reflected in our benefits. Nordstrom is proud to offer a variety of benefits to support employees and their families, including:

  • Medical/Vision, Dental, Retirement and Paid Time Away
  • Life Insurance and Disability
  • Merchandise Discount and EAP Resources

This position may be eligible for performance‑based incentives/bonuses. Benefits include 401k, medical/vision/dental/life/disability insurance options, PTO accruals, Holidays, and more. Eligibility requirements may apply based on location, job level, classification, and length of employment. Learn more in the Nordstrom Benefits Overview by copying and pasting the following URL into your browser: https://careers.nordstrom.com/pdfs/Ben_Overview_17-19.pdf

A few more important points...

The job posting highlights the most critical responsibilities and requirements of the job. It’s not all-inclusive. There may be additional duties, responsibilities and qualifications for this job.

For Los Angeles or San Francisco applicants: Nordstrom is required to inform you that we conduct background checks after conditional offer and consider qualified applicants with criminal histories in a manner consistent with legal requirements per Los Angeles, Cal. Muni. Code 189.04 and the San Francisco Fair Chance Ordinance. For additional state and location specific notices, please refer to the Legal Notices document within the FAQ section of the Nordstrom Careers site.

Applicants with disabilities who require assistance or accommodation should contact the nearest Nordstrom location, which can be identified at www.nordstrom.com.

Please be mindful that there may be legal notices and requirements related to this job posting that are specific to your state. Review the Career Site FAQ’s for relevant information and guidelines.

Current Nordstrom employees: To apply, log into Workday, click the Careers button and then click Find Jobs.

Nordstrom keeps job postings open for at least one day after the posting date.

© 2026 Nordstrom, Inc

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)
Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)

Relha LLC • Seattle (WA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Medical/Vision & Dental
Retirement plan
Paid time away
+1
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)
Principal Security Engineer - Identity and Access Management (Hybrid - Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 191,000 - 297,000
Medical/Vision, Dental, Retirement
Merchandise Discount
Senior 2 Technical Program Manager, AI Native Operating Model - HYBRID (Seattle, WA)
Senior 2 Technical Program Manager, AI Native Operating Model - HYBRID (Seattle, WA)

Nordstrom • Seattle (WA)

On-site
USD 166,000 - 258,000
Medical/Vision, Dental
Retirement
Merchandise Discount
+1
Compliance Analyst 2 – PCI
Compliance Analyst 2 – PCI

Jobtailor • Seattle (WA)

On-site
USD 90,000 - 140,000
Product Manager II — Customer Data Platform & Marketing Technology (Hybrid - Seattle)
Product Manager II — Customer Data Platform & Marketing Technology (Hybrid - Seattle)

Nordstrom • Seattle (WA)

On-site
USD 122,000 - 189,000
Medical/Vision/Dental
Retirement & PTO
Life Insurance
+2
Senior Full Stack Software Engineer (Hybrid, Seattle)
Senior Full Stack Software Engineer (Hybrid, Seattle)

Nordstrom • Seattle (WA)

Hybrid
USD 142,000 - 221,000
Medical/Vision/Dental
Retirement and PTO
Merchandise Discount
+1
Senior Program Manager, Human Resource Compliance (Hybrid, Seattle)
Senior Program Manager, Human Resource Compliance (Hybrid, Seattle)

Nordstrom • Seattle (WA)

On-site
USD 103,000 - 175,000
Medical/Vision and Dental Insurance
Retirement Plans
Paid Time Away
+1
Senior Technical Program Manager - Security Platform Engineering (Hybrid - Seattle)
Senior Technical Program Manager - Security Platform Engineering (Hybrid - Seattle)

Nordstrom, Inc. • Seattle (WA)

Hybrid
USD 142,000 - 221,000
Senior 2 Technical Program Manager, AI Native Operating Model - HYBRID (Seattle, WA)
Senior 2 Technical Program Manager, AI Native Operating Model - HYBRID (Seattle, WA)

Nordstrom, Inc. • Seattle (WA)

On-site
USD 166,000 - 258,000
Medical/Vision
Dental
401k
Senior Full Stack Software Engineer
Senior Full Stack Software Engineer

Nordstrom, Inc. • Seattle (WA)

On-site
USD 142,000 - 220,500
Medical/Vision, Dental Insurance
401k and Retirement Benefits
Merchandise Discount
+1