Senior GRC Compliance Analyst (Hybrid, Seattle)
NordstromAbout the role
Job Description
Join Nordstrom's Governance, Risk, and Compliance (GRC) team as a Senior Analyst, leading the development of compliance assessment methodologies and operational standards across multiple regulatory domains. You will serve as a primary point of contact for regulators and senior compliance stakeholders, lead technical scoping discussions across hybrid on-premises and cloud environments, drive de-scoping initiatives with technical teams, and build cross-functional partnerships that embed compliance into our technology ecosystem.
In this role, you will build comprehensive compliance assessment programs that integrate multiple regulatory domains with business objectives. You will lead senior stakeholder workshops on complex regulatory topics while managing critical external relationships with regulators and auditors. Your ability to translate complex technical environments into clear compliance requirements will be critical to program success.
Are you a strategic compliance leader who excels at designing enterprise-wide methodologies? Do you have a passion for building operational excellence in regulatory compliance with a strong background in PCI? Do you think about ways to integrate multiple regulatory domains while maintaining audit trail integrity? Join our team and be part of a company that is on the cutting edge of retail technology geared at getting consumers the products they love in a safe and secure environment.
A Day in the Life...
Methodology Design & Operational Standards
- Mature and formalize the PCI DSS compliance program from foundational elements, establishing policies, procedures, RACI, and operational workflows that meet QSA and acquiring bank expectations
- Design comprehensive compliance assessment methodologies for enterprise regulatory requirements, creating frameworks that integrate multiple regulatory domains and align with business objectives
- Develop operational standards and quality criteria for compliance processes, ensuring consistency and effectiveness across the organization while meeting diverse regulatory requirements
- Implement integrated controls across multiple regulatory and business domains, ensuring comprehensive compliance coverage and efficient resource utilization
- Define, design and implement KPIs and KRIs for the compliance space
Third-Party & External Relationship Management
- Manage third-party compliance assessments including external regulatory examinations, compliance consulting engagements, and specialized regulatory advisory projects
- Serve as primary liaison with internal and external compliance auditors and stakeholders, representing the organization's compliance posture and remediation efforts
- Make significant commitments for third-party compliance assessments, regulatory consulting, and compliance platforms within established enterprise frameworks
Strategic Alignment & Leadership
- Align operational activities with strategic objectives by participating in medium-term planning (6-18 months) and ensuring compliance initiatives support business goals and regulatory expectations
- Lead senior stakeholder workshops on complex regulatory topics, facilitating decision-making and consensus-building around compliance strategies and regulatory risk tolerance
- Coordinate cross-functional regulatory initiatives across Legal, IT, Finance, and Business teams to ensure comprehensive regulatory coverage and strategic execution
- Contribute to the strategic vision and roadmap for the Compliance Assessment Team, developing reusable, scalable solutions to enhance program efficiency and support organizational growth
Stakeholder Engagement & Education
- Educate senior stakeholders on regulatory compliance requirements and changes through workshops, strategic sessions, and consultation to improve organizational compliance awareness and readiness
- Facilitate decision-making processes around complex regulatory scenarios, helping leadership understand regulatory risk tolerance and compliance strategy options
- Provide expert guidance on regulatory interpretation and application across diverse business contexts and technical environments
You Own This If You Have...
Required Qualifications
Experience:
- 6-8 years of regulatory compliance experience with demonstrated leadership of cross-functional regulatory initiatives, including at least 2 years leading or building PCI programs
- Proven track record of designing and implementing enterprise-level compliance methodologies across multiple regulatory domains
- Demonstra
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s