Senior Compliance Analyst – Continuous Compliance Framework (hybrid - Seattle)

Nordstrom Nordstrom · Retail · Seattle, WA

Senior Compliance Analyst to lead the transformation and maturation of a Continuous Compliance Framework (CCF), focusing on AI-assisted testing and automation within a GRC tool. This role involves tailoring controls, configuring the GRC module, collaborating across business and technology teams, and integrating with risk and governance programs. The analyst will partner with Security Engineers to design AI-driven testing features and support audits like PCI.

What you'd actually do

  1. Lead the transformation and ongoing maturation of the CCF, including updating and tailoring controls to reflect the current organizational environment, risk profile, and regulatory landscape.
  2. Configure and manage the CCF program module within Nordstrom’s GRC tool, ensuring accurate representation of controls, testing schedules, evidence requirements, and ownership assignments.
  3. Collaborate with stakeholders across business and technology teams to define control language, testing frequency, and implementation guidance that is practical and aligned with operational realities.
  4. Partner with Security Engineers to design AI-driven testing and automated evidence collection features within the GRC tool; the Senior Analyst provides functional requirements while Engineers lead technical builds.
  5. Design and implement enterprise compliance assessment methodologies that integrate multiple regulatory domains (e.g., NIST, CIS, SOX, HIPAA, CCPA).

Skills

Required

  • 4–6 years of regulatory compliance experience with demonstrated ownership of cross-functional compliance initiatives.
  • Direct experience building and managing Continuous Compliance Framework (CCF) or Common Control Framework programs.
  • Hands-on experience configuring compliance programs within GRC tools and platforms.
  • Experience working with stakeholders to define control language, RACI, and testing cadence.
  • Demonstrated experience developing KPIs and KRIs for compliance programs.
  • Familiarity with PCI DSS sufficient to support assessments and control testing activities.
  • Experience partnering with engineering or security teams to implement automated or AI-assisted control testing.
  • Proven ability to align compliance operations with strategic business objectives.
  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent work experience.
  • Deep knowledge about multiple regulatory frameworks (CIS, NIST, SOX, HIPAA, CCPA, PCI DSS v4.x) and their control implications.

What the JD emphasized

  • AI-assisted testing
  • automated evidence collection