Senior Technical Pci Analyst (hybrid - Seattle)

Nordstrom Nordstrom · Retail · Seattle, WA

Senior Technical PCI Analyst responsible for owning and building Nordstrom's PCI DSS v4.0 compliance program end-to-end. This includes scoping, evidence collection, control testing, QSA coordination, and developing operational processes and tooling. The role requires deep payment security expertise, strong scoping skills in hybrid environments, and the ability to mentor other analysts.

What you'd actually do

  1. Drive the full PCI DSS v4.0 compliance lifecycle: scoping, gap assessment, evidence collection, control testing, and annual QSA coordination. You’re not handing this off — you’re running it.
  2. Build and maintain the CDE asset inventory — network segmentation docs, data flow diagrams, system component registers — across on-premises and cloud. If it touches cardholder data, you know about it.
  3. Design and run the periodic control testing program: scheduling, evidence requests, test procedures, exception tracking, and remediation follow-up. Assessment season should feel like a victory lap, not a fire drill.
  4. Write the policies, procedures, RACIs, and runbooks that make the program sustainable — so it doesn’t fall apart when you take a vacation.
  5. Track findings, owners, and milestones in the GRC platform and surface the right KPIs and KRIs (open findings age, control test pass rates, inventory coverage) so leadership always knows where things stand.

Skills

Required

  • 6–8 years of hands-on PCI DSS compliance experience
  • at least 3 years owning or co-owning a PCI program
  • Deep working knowledge of PCI DSS v4.0
  • Real scoping experience in hybrid on-premises and cloud environments
  • Hands-on control testing experience (firewall rule reviews, patch compliance, access reviews, log configurations, encryption assessments)
  • Experience building PCI programs from scratch (asset inventory, control testing schedules, evidence libraries, operational procedures)
  • Experience writing policies, procedures, RACIs, and runbooks
  • Experience with GRC platforms
  • Experience with cloud environments (AWS, Azure, GCP)

Nice to have

  • Mentoring other compliance analysts
  • Experience with SOX, HIPAA, and other frameworks
  • Experience with acquiring bank and payment brand relationships

What the JD emphasized

  • PCI SME
  • PCI DSS v4.0 compliance program
  • building the operational backbone
  • scoping
  • control testing
  • QSA coordination
  • hands-on payment security work
  • program building
  • PCI DSS v4.0
  • building PCI programs from scratch
  • hybrid on-premises and cloud environments
  • hands-on control testing chops