×
Register Here to Apply for Jobs or Post Jobs. X

Senior IT Compliance Analyst

Job in Scottsdale, Maricopa County, Arizona, 85261, USA
Listing for: Onsemi
Full Time position
Listed on 2026-01-15
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Business Analyst, IT Consultant
Job Description & How to Apply Below

In this global, hands-on role reporting to the Director, Assurance & Trust, you will lead our governmental IT compliance program across U.S. export controls and modern cybersecurity frameworks. The IT Compliance Lead will develop and manage onsemi’s enterprise-wide compliance strategy, ensuring adherence to federal standards such as CMMC, DFARS, NIST 800-171, ITAR, and EAR. This role is critical in protecting sensitive information, maintaining audit readiness, and driving compliance initiatives across the organization.

You will own the compliance roadmap, drive audit readiness and external assessments, and serve as the primary IT liaison to internal compliance teams, regulators, and assessors, ensuring continuous monitoring and an audit ready posture for all IT systems and processes. Success in this role requires close partnership with IT, Legal, Engineering, Sales, Operations, and Leadership, a bias for action, and meticulous attention to detail.

Responsibilities
  • Develop and lead onsemi’s enterprise-wide compliance strategy and program, covering CMMC, DFARS, NIST 800-171, ITAR/EAR, and CUI handling, including policies, procedures, and controls.
  • Drive CMMC compliance initiatives, ensuring adherence to NIST SP 800-171 standards and serving as the primary liaison with external CMMC Third-Party Assessor Organizations (C3

    PAOs) and internal IT and Legal & Compliance teams.
  • Identify and assess compliance risks and gaps related to CUI and technical data; develop and implement mitigation strategies and Plans of Action and Milestones (POA&Ms).
  • Lead remediation efforts for POA&Ms during CMMC Level 2 gap assessments and prepare onsemi for achieving CMMC Level 2 certification by 2027.
  • Oversee ITAR and export compliance remediation for IT-related gaps, partnering with Legal and Compliance teams to ensure regulatory adherence.
  • Prepare, maintain, and manage all required documentation, including System Security Plans (SSPs), POA&Ms, security logs, and training records, ensuring audit readiness for government or third-party assessments.
  • Advise senior leadership on strategic IT compliance risks, mitigation plans, and integration with business objectives.
  • Manage audit readiness and external assessments, ensuring documentation, evidence, and control implementation meet regulatory requirements.
  • Monitor regulatory updates (DoD, DDTC, etc.) and recommend adjustments to IT compliance programs.
  • Conduct IT compliance gap assessments and collaborate with IT, Business, Facilities, Legal, and Compliance teams to ensure security, access, and incident reporting controls comply with CUI, ITAR, and EAR requirements.
  • Support incident reporting and response coordination, ensuring DFARS and ITAR/EAR IT requirements are met.
  • Develop, implement, and enforce cybersecurity policies, incident response plans, and SSPs to protect CUI.
  • Maintain compliance metrics and risk tracking, reporting status and findings to leadership.
  • Continuously evaluate and enhance compliance programs, incorporating industry best practices and benchmarking.
  • Lead policy governance, including development, review, and lifecycle management of compliance-related policies.
  • Develop and deliver compliance training and awareness programs for employees and contractors handling CUI or export-controlled data.
  • Provide end-user support and training on IT tools, cybersecurity awareness, and best practices.
Qualifications
  • 3 to 5 years of experience in compliance, information security, or defense contracting
  • 3 to 5 years of experience in cybersecurity, with a focus on CMMC compliance or a similar framework (e.g., NIST 800-171, ISO 27001, ITAR, EAR).
  • 3 to 5 years of experience with U.S. export laws; practical application of NIST 800‑171 control families; building SSP/POA&M; enabling SPRS submissions and audit readiness.
  • Deep understanding of Controlled Unclassified Information (CUI) regulations, including NIST SP 800-171 and DFARS.
  • Familiarity with FAR, DFARS, ITAR, and EAR regulations and their application to CUI handling.
  • Familiarity with SSPs, POA&Ms, and CMMC compliance documentation.
  • Experience developing and overseeing CUI programs to ensure compliance with federal regulations.
  • Experience…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary