Compliance Analyst – PCI
Job in
Seattle, King County, Washington, 98127, USA
Listed on 2026-09-14
Listing for:
Jobtailor
Full Time
position Listed on 2026-09-14
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
Job Description & How to Apply Below
- Conduct hands-on testing of Continuous Compliance Framework controls and document results
- Build and maintain the CCF module in Nordstrom's GRC tool, including control status, testing schedules, evidence records, and ownership assignments
- Build and maintain RACIs for CCF, PCI, and Financial Control Audit programs
- Collect, organize, validate, and follow up on control evidence and documentation gaps
- Build and test AI-assisted and automated workflows for evidence collection and control testing
- Identify anomalies, exceptions, and gaps in automated evidence pulls or AI-assisted review
- Support remediation recommendations and track remediation activities
- Support design and tracking of KPIs and KRIs for compliance programs
- Conduct technical control testing for PCI DSS v4.x and Financial Control Audit
- Perform PCI DSS scoping, evidence collection, and testing across the annual assessment cycle
- Maintain the CDE asset inventory, network segmentation documentation, data flow diagrams, and system component registers
- Support QSA fieldwork by coordinating document requests and preparing evidence packages
- Organize evidence repositories and information records
- Compile information from multiple sources into clear summaries
- Draft and summarize documentation using AI tools, reviewing outputs for accuracy
- Create and update process documentation and translate technical details into business-friendly language
- Develop reports on control status, testing progress, and remediation metrics
- Execute recurring GRC activities with minimal supervision
- Perform quality checks and coordinate audit and assessment preparation
- Monitor operational metrics and flag process improvement opportunities
- Take increasing ownership of CCF and/or PCI modules
- 2+ years of hands-on professional experience running PCI DSS assessments, along with CCF and/or SOX experience or equivalent
- Working understanding of at least one relevant framework or standard, such as PCI DSS, NIST 800-30/CSF, ISO 27005, SOX, or HIPAA
- Experience with or strong aptitude for hands-on technical control testing and gap analysis
- Experience building or maintaining RACIs, or strong understanding of documenting control ownership and accountability
- Interest in and aptitude for metrics, including KPIs/KRIs
- Experience using AI and automation in compliance work and evaluating effectiveness
- Strong organizational skills
- Clear written and verbal communication skills, including translating technical findings into business-friendly language
- Ability to work with minimal supervision and know when to elevate
- Pursuing or holding an associate-level certification such as CISA, CRISC, ISO 27001 Implementer, CIPM, or CIPP (preferred)
- Experience with a GRC platform such as Service Now, OnSpring, Audit Board, or Archer (preferred)
- Familiarity with cloud environments such as AWS, Azure, or GCP (preferred)
- Must be available to work in the office at Nordstrom corporate headquarters a minimum of 4 days/week
- Associate-level certification is preferred, not required
Demonstrates expertise in conducting PCI DSS assessments and technical control testing while effectively utilizing AI and automation for compliance processes. Proficient in building and maintaining compliance frameworks, documenting control ownership, and translating technical findings into business-friendly language.
Highest-signal resume keywords- PCI DSS Assessment
- Technical Control Testing
- GRC Platform Experience
- AI and Automation in Compliance
- RACI Documentation
- Continuous Compliance Framework
- Gap Analysis
- KPI/KRI Tracking
- Evidence Collection
- Control Testing
- Documentation Drafting
- Quality Checks
- Process Documentation
- Metrics Evaluation
- Anomaly Identification
- Organizational Skills
- Clear Communication
- Minimal Supervision
- Escalation Awareness
- CISA
- CRISC
- ISO 27001 Implementer
- CIPM
- CIPP
- PCI DSS
- NIST 800-30
- ISO 27005
SOX - HIPAA
- Service Now
- On Spring
- Audit Board
- Archer
- AWS
- Azure
- GCP
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×