Senior GRC Compliance Analyst - Continuous Compliance Framework (Hybrid - Seattle)
Nordstrom
- Location
- Seattle, WA
- Work model
- Hybrid
- Level
- Senior
- H-1B history
- 74 approvals (FY2023)
- Posted
- Sep 12, 2026
About this role
Job Description
This role is offered as hybrid in Seattle, WA. Candidates must be available to work in office at the Nordstrom corporate headquarters a minimum of 4 days/week to be considered for this position. We're turning “prove it” into a fast, repeatable habit instead of a fire drill. If you're a compliance pro who thrives on building scalable, tech-enabled frameworks and wants to be at the forefront of AI-assisted testing and automation, we want to meet you. Ditch the old-school “box-checking” mentality — that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own the Common Control Framework (CCF) from the ground up: maturing it, running it, and testing control effectiveness so it keeps pace with evolving threats and regulations — and so audits go from dreaded to no-big-deal. You'll be the functional lead for the CCF module in our GRC tool and the driving force behind automating evidence collection and control testing, so your team (and everyone you support) can stop doing the same manual grind on repeat. A critical aspect of this role is cross-functional collaboration with the Governance and Risk teams to ensure the CCF, risk management, and governance programs are integrated and mutually reinforcing. You'll also support audits and assessments such as PCI, contributing to a security posture the organization can trust — proactive instead of reactive, and built to scale. A Day in the Life… Continuous Compliance Framework (CCF) Transformation Lead the transformation and ongoing maturation of the CCF, tailoring controls to reflect the current organizational environment, risk profile, and regulatory landscape. Configure and manage the CCF program module within Nordstrom's GRC tool, ensuring accurate representation of controls, testing schedules, evidence requirements, and ownership assignments. Collaborate with stakeholders across business and technology teams to define control language, testing frequency, and implementation guidance that's practical and aligned with operational realities — no black boxes, no ambiguity about who owns what. Build out RACI models for every control in the CCF, so ownership and accountability are crystal clear across teams. Design and roll out KPIs and KRIs for the CCF and broader compliance program, laying the groundwork for real-time control health monitoring instead of once-a-year snapshots. AI & Automation for Evidence Collection and Control Testing Think outside the (compliance) box — dream up new, innovative ways to manage the CCF and boost compliance effectiveness, and get hands-on evaluating and piloting AI/automation tools that cut evidence review time, catch control exceptions earlier, and free you up for the work that actually needs a human brain. Define functional requirements for AI-assisted control testing (e.g., automated evidence validation, anomaly detection in control performance, natural-language summarization of audit evidence), partnering with Engineers on complex builds requiring multiple system integrations, while directly building and implementing automation and AI-driven solutions for more contained use cases. Identify controls that are strong candidates for automation or continuous monitoring based on testing frequency, evidence type, and data source availability, and build the roadmap to get there. Contribute to the long-term vision for self-service compliance tooling — dashboards or interfaces that let control owners and stakeholders check their own compliance posture without waiting on the GRC team. Build reusable, scalable testing and automation patterns so the team isn't reinventing the wheel every time a new framework or regulation comes into scope. GRC Program Integration Work closely with the Governance and Risk teams to ensure the CCF, risk management program, and governance program are integrated, with aligned control sets, shared evidence, and coordinated