Senior Privacy & Cybersecurity Governance Analyst (Hybrid - Seattle)
NordstromAbout the role
Job Description
Join Nordstrom's Technology team as a Senior Privacy & Cybersecurity Governance Analyst, where you'll play a pivotal role in leading strategic privacy and security governance initiatives across the enterprise. You will be a subject matter expert and trusted advisor to leadership, building comprehensive governance programs that protect customer data, reduce risk, and ensure our organization remains audit-ready across complex regulatory landscapes.
In this role, you will lead domain-specific privacy and cybersecurity governance activities, driving compliance efforts, contributing to policy development, and mentoring junior team members. You will have authority to implement process improvements within your specialized domain and make domain-specific recommendations to senior staff for enterprise-wide changes. You will coordinate across multiple stakeholders to ensure comprehensive privacy and security input while developing integrated frameworks that support business objectives.
Are you a strategic thinker with deep expertise in privacy and cybersecurity governance? Do you have a passion for building scalable programs that protect customers and enable business growth? Do you think about ways to integrate privacy-by-design and security-by-design principles into everything we do? Join our team and be part of a company that is on the cutting edge of retail technology, committed to getting consumers the products they love in a safe, secure, and privacy-respecting environment.
A Day in the Life...
Privacy Subject Matter Expertise
- Serve as primary contact and subject matter expert for domain-specific data privacy activities or those within a specific privacy-related area of expertise (e.g., artificial intelligence, consumer credit, marketing)
- Identify emerging privacy threats and trends and advise on strategic initiatives to enhance data protection across the organization
- Evaluate and enhance privacy related risk assessment processes including identifying and anticipating changes in relevant industry and/or regulatory frameworks
- Implement process improvements within their specialized privacy domain, developing standardized approaches and best practices for recurring data privacy assessment scenarios
- Educate stakeholders on data privacy requirements and changes through training sessions, workshops, and consultation to improve organizational privacy awareness and readiness
- Analyze legal and regulatory developments in privacy and assess their business impact, ensuring the organization stays ahead of evolving compliance requirements
- Participate in investigations and remediation of privacy incidents or breaches, supporting incident response coordination and documentation
Integrated Privacy & Security Strategy
- Coordinate operational activities across multiple stakeholders including Legal, IT, Security, and Marketing to ensure comprehensive privacy and security input and effective data governance strategies, including owning initiative scoping, workplans, and milestone tracking end-to-end
- Identify and develop advanced risk management frameworks that integrate privacy and security considerations for holistic risk assessment and treatment
- Lead the build-out and operationalization of the Third-Party Risk Management (TPRM) program, including vendor assessment frameworks, risk tiering, intake workflows, and ongoing monitoring
- Evaluate and enhance privacy and security risk assessment processes, identifying and anticipating changes in relevant industry and regulatory frameworks
- Implement process improvements within specialized domains, developing standardized approaches and best practices for recurring assessment scenarios
- Develop integrated privacy and security metrics and reporting, creating dashboards and analytics that provide actionable insights to management and support strategic decision-making
- Represent the privacy and security governance team in cross-functional governance forums, building relationships and serving as a trusted advisor across the enterprise
Data Governance
- Maintain and mature the personal information (PI) inventory, ensuring data maps and records of processing activities (ROPAs) are accurate and sufficient to support DSR fulfillment and privacy compliance obligations
- Support data classification efforts for personal and sensitive data in partnership with IT and data teams, ensuring privacy requirements are reflected in classification taxonomies and handling standards
- Contribute to data minimization and retention reviews, advising on privacy obligations and regulatory require
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s