Compliance Analyst 2 - PCI (Hybrid - Seattle)

NordstromSeattle, WA
$121,500 - $188,500Hybrid

About The Position

This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position. Compliance doesn't have to mean dusty binders and once-a-year fire drills — on this team, it's about building programs that are sharp, current, and built to last. Nordstrom's Governance, Risk & Compliance (GRC) team is looking for a Compliance Analyst to help build out three of our most active programs: the Continuous Compliance Framework (CCF), Financial Control Audit, and PCI DSS. All three are actively maturing, and you'll be right there building alongside us — standing up RACIs, shaping the KPIs/KRIs that show program health, and helping put governance structures in place that actually hold. This isn't a "maintain what already exists" role; it's a "help us build the thing" role. You'll also team up with the rest of the Compliance crew to find smarter, faster ways to get the work done — putting AI and automation to work so evidence collection and control testing stop feeling like a grind and start feeling like a well-oiled machine. This is a great fit for someone who loves getting hands-on: technical control testing, evidence and documentation, RACI and governance design, program metrics — the whole toolkit. You'll work closely with senior analysts across both programs, and as things mature, you'll pick up direct ownership of specific pieces of CCF and/or PCI. Come for the compliance, stay for the team that actually makes it fun.

Requirements

  • 2+ years of hands-on professional experience running PCI DSS assessments, along with CCF and/or SOX experience or equivalent.
  • Working understanding of at least one relevant framework or standard (e.g., PCI DSS, NIST 800-30/CSF, ISO 27005, SOX, HIPAA) and the ability to apply it correctly to routine scenarios.
  • Experience with, or strong aptitude for, hands-on technical control testing (e.g., firewall rule reviews, access reviews, log configuration checks) and gap analysis.
  • Experience building or maintaining RACIs, or strong understanding of how to document control ownership and accountability.
  • Interest in and aptitude for metrics — comfortable helping design or track KPIs/KRIs that reflect program health.
  • Experience using AI and automation to make compliance work more effective — e.g., evidence pulls, LLM-assisted review — and the ability to evaluate what's actually a time-saver versus what still needs a human eye.
  • Strong organizational skills — able to juggle evidence collection, testing, and documentation across two programs without dropping things.
  • Clear written and verbal communication skills, including the ability to translate technical findings into business-friendly language.
  • Ability to work with minimal supervision on established processes, while knowing when to escalate.

Nice To Haves

  • Pursuing or holding an associate-level certification such as CISA, CRISC, ISO 27001 Implementer, CIPM, or CIPP.
  • Experience with a GRC platform (e.g., ServiceNow, OnSpring, AuditBoard, Archer or similar) for tracking findings and evidence.
  • Familiarity with cloud environments (AWS, Azure, or GCP) as they relate to compliance scope.

Responsibilities

  • Conduct hands-on testing of CCF controls using established methodologies, and document results clearly so control owners can act on them.
  • Help build out and maintain the CCF module in Nordstrom's GRC tool — control status, testing schedules, evidence records, and ownership assignments.
  • Build and maintain RACIs for CCF controls, working with stakeholders to document clear ownership and accountability.
  • Collect, organize, and validate evidence from control owners, following up on gaps or missing documentation.
  • Partner with the Compliance team to build and test AI-assisted and automated workflows that streamline evidence collection and control testing, validating them on real controls to distinguish genuine time-savers from tasks still needing a human eye.
  • Catch anomalies, exceptions, or gaps that automated evidence pulls or AI-assisted review surface, and loop in senior analysts for follow-up.
  • Support development of basic remediation recommendations for identified control gaps, in partnership with senior analysts.
  • Track remediation activities and status updates to keep the compliance posture current.
  • Support the design of KPIs and KRIs for the CCF program, helping translate testing and remediation data into metrics leadership can use.
  • As you grow in the role, take direct ownership of specific CCF modules or control domains.
  • Conduct hands-on technical control testing for PCI DSS v4.x and Financial Control Audit — firewall rule reviews, access reviews, patch compliance, SDLC, change management, and log configuration checks.
  • PCI DSS scoping, evidence collection, and control testing activities across the annual assessment cycle.
  • Help build and maintain the CDE asset inventory — network segmentation documentation, data flow diagrams, and system component registers.
  • Build and maintain RACIs and governance documentation for the PCI program and Financial Control Audit, clarifying ownership across control owners and stakeholders.
  • Assist with periodic control testing: scheduling, evidence requests, and tracking exceptions through to resolution.
  • Support QSA fieldwork by coordinating document requests and helping prepare evidence packages under senior analyst guidance.
  • Support the design of PCI program KPIs and KRIs and track outcomes over time (e.g., open findings age, control test pass rates, inventory coverage).
  • Apply PCI DSS requirements to routine technical assessment scenarios and escalate anything outside established procedures.
  • As you grow in the role, take direct ownership of specific PCI modules or control domains.
  • Organize and maintain evidence repositories and information records with clear structure and categorization.
  • Extract and compile information from multiple sources (control owners, tickets, prior assessments) into clear, useful summaries.
  • Put AI tools to work drafting and summarizing documentation from source material, reviewing the output for accuracy before it goes into final records — and sharing what you learn about where it shines and where it doesn't.
  • Create and update process documentation, translating technical detail into business-friendly language.
  • Coordinate review cycles for documentation to keep it current and applicable.
  • Develop basic reports on control status, testing progress, and remediation metrics.
  • Execute recurring GRC activities — findings updates, assessment tickets, evidence tracking — with minimal supervision.
  • Apply established procedures to routine technical assessment work; recognize when a situation falls outside standard protocol and escalate to senior analysts or program owners.
  • Perform quality checks on your own deliverables before handoff.
  • Take on increasing ownership of specific CCF and/or PCI modules as your technical testing, RACI, and governance experience grows.
  • Support audit and assessment preparation for both CCF and PCI, and coordinate handoffs with other team members.
  • Monitor operational metrics for your area and flag opportunities for process improvement.

Benefits

  • Medical/Vision
  • Dental
  • Retirement
  • Paid Time Away
  • Life Insurance
  • Disability
  • Merchandise Discount
  • EAP Resources
  • Performance-based incentives/bonuses
  • 401k
  • Holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service