> Markdown version of [/jobs/ext/2873811-compliance-analyst-2-pci-hybrid-seattle](https://www.wearedevelopers.com/jobs/ext/2873811-compliance-analyst-2-pci-hybrid-seattle). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Compliance Analyst 2 - PCI (Hybrid - Seattle) - **Company:** Nordstrom, Inc. - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $121,500.0 - $188,500.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Document Management Systems, Network Segmentation, PCI Data Security Standards, Systems Development Life Cycle, Cloud Platform System, Large Language Models, Servicenow - **Published:** September 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3b9a581e95dd42db ## About the Role * 2+ years of hands-on professional experience running PCI DSS assessments, along with CCF and/or SOX experience or equivalent. * Working understanding of at least one relevant framework or standard (e.g., PCI DSS, NIST 800-30/CSF, ISO 27005, SOX, HIPAA) and the ability to apply it correctly to routine scenarios. * Experience with, or strong aptitude for, hands-on technical control testing (e.g., firewall rule reviews, access reviews, log configuration checks) and gap analysis. * Experience building or maintaining RACIs, or strong understanding of how to document control ownership and accountability. * Interest in and aptitude for metrics - comfortable helping design or track KPIs/KRIs that reflect program health. * Experience using AI and automation to make compliance work more effective - e.g., evidence pulls, LLM-assisted review - and the ability to evaluate what's actually a time-saver versus what still needs a human eye. * Strong organizational skills - able to juggle evidence collection, testing, and documentation across two programs without dropping things. * Clear written and verbal communication skills, including the ability to translate technical findings into business-friendly language. * Ability to work with minimal supervision on established processes, while knowing when to escalate., * Pursuing or holding an associate-level certification such as CISA, CRISC, ISO 27001 Implementer, CIPM, or CIPP. * Experience with a GRC platform (e.g., ServiceNow, OnSpring, AuditBoard, Archer or similar) for tracking findings and evidence. * Familiarity with cloud environments (AWS, Azure, or GCP) as they relate to compliance scope. ## Description This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position. Compliance doesn't have to mean dusty binders and once-a-year fire drills - on this team, it's about building programs that are sharp, current, and built to last. Nordstrom's Governance, Risk & Compliance (GRC) team is looking for a Compliance Analyst to help build out three of our most active programs: the Continuous Compliance Framework (CCF), Financial Control Audit, and PCI DSS. All three are actively maturing, and you'll be right there building alongside us - standing up RACIs, shaping the KPIs/KRIs that show program health, and helping put governance structures in place that actually hold. This isn't a "maintain what already exists" role; it's a "help us build the thing" role. You'll also team up with the rest of the Compliance crew to find smarter, faster ways to get the work done - putting AI and automation to work so evidence collection and control testing stop feeling like a grind and start feeling like a well-oiled machine. This is a great fit for someone who loves getting hands-on: technical control testing, evidence and documentation, RACI and governance design, program metrics - the whole toolkit. You'll work closely with senior analysts across both programs, and as things mature, you'll pick up direct ownership of specific pieces of CCF and/or PCI. Come for the compliance, stay for the team that actually makes it fun., * Conduct hands-on testing of CCF controls using established methodologies, and document results clearly so control owners can act on them. * Help build out and maintain the CCF module in Nordstrom's GRC tool - control status, testing schedules, evidence records, and ownership assignments. * Build and maintain RACIs for CCF controls, working with stakeholders to document clear ownership and accountability. * Collect, organize, and validate evidence from control owners, following up on gaps or missing documentation. * Partner with the Compliance team to build and test AI-assisted and automated workflows that streamline evidence collection and control testing, validating them on real controls to distinguish genuine time-savers from tasks still needing a human eye. * Catch anomalies, exceptions, or gaps that automated evidence pulls or AI-assisted review surface, and loop in senior analysts for follow-up. * Support development of basic remediation recommendations for identified control gaps, in partnership with senior analysts. * Track remediation activities and status updates to keep the compliance posture current. * Support the design of KPIs and KRIs for the CCF program, helping translate testing and remediation data into metrics leadership can use. * As you grow in the role, take direct ownership of specific CCF modules or control domains. PCI DSS and Financial Control Audit - Build & Support * Conduct hands-on technical control testing for PCI DSS v4.x and Financial Control Audit - firewall rule reviews, access reviews, patch compliance, SDLC, change management, and log configuration checks. * PCI DSS scoping, evidence collection, and control testing activities across the annual assessment cycle. * Help build and maintain the CDE asset inventory - network segmentation documentation, data flow diagrams, and system component registers. * Build and maintain RACIs and governance documentation for the PCI program and Financial Control Audit, clarifying ownership across control owners and stakeholders. * Assist with periodic control testing: scheduling, evidence requests, and tracking exceptions through to resolution. * Support QSA fieldwork by coordinating document requests and helping prepare evidence packages under senior analyst guidance. * Support the design of PCI program KPIs and KRIs and track outcomes over time (e.g., open findings age, control test pass rates, inventory coverage). * Apply PCI DSS requirements to routine technical assessment scenarios and escalate anything outside established procedures. * As you grow in the role, take direct ownership of specific PCI modules or control domains., * Organize and maintain evidence repositories and information records with clear structure and categorization. * Extract and compile information from multiple sources (control owners, tickets, prior assessments) into clear, useful summaries. * Put AI tools to work drafting and summarizing documentation from source material, reviewing the output for accuracy before it goes into final records - and sharing what you learn about where it shines and where it doesn't. * Create and update process documentation, translating technical detail into business-friendly language. * Coordinate review cycles for documentation to keep it current and applicable. * Develop basic reports on control status, testing progress, and remediation metrics. Operational Execution * Execute recurring GRC activities - findings updates, assessment tickets, evidence tracking - with minimal supervision. * Apply established procedures to routine technical assessment work; recognize when a situation falls outside standard protocol and escalate to senior analysts or program owners. * Perform quality checks on your own deliverables before handoff. * Take on increasing ownership of specific CCF and/or PCI modules as your technical testing, RACI, and governance experience grows. * Support audit and assessment preparation for both CCF and PCI, and coordinate handoffs with other team members. * Monitor operational metrics for your area and flag opportunities for process improvement. ## Related Videos - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Reliable scalability: How Amazon.com scales on AWS](https://www.wearedevelopers.com/videos/983-reliable-scalability-how-amazon-com-scales-on-aws) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)