Nordstrom is looking for a technically deep PCI SME who thrives at the intersection of hands-on payment security work and program building. You’ll own our PCI DSS v4.0 compliance program end-to-end — from scoping and evidence collection through control testing and QSA coordination — while simultaneously building the operational backbone (processes, tooling, documentation) that keeps the program humming year-round, not just during assessment season. You’re the person who knows what’s in scope. When an engineer asks “does this new microservice touch the CDE?” or a product manager wants to know if their new payment flow creates PCI exposure, you’re the one they come to — and you give them a real answer, not a “it depends, let me escalate.” You’ll also be a go-to resource and mentor for the other compliance analysts on the team. You won’t manage anyone’s performance reviews, but your PCI expertise will help level everyone up — answering questions, reviewing their work, and making sure the team speaks PCI fluently. If you get a little too excited about data flow diagrams, have strong opinions about network segmentation, and have ever caught a scoping error that saved your company a world of pain — keep reading.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior