The Senior IT Security Compliance Engineer is responsible for developing, maintaining, and advancing the organization’s security compliance posture. This role leads security audits, manages compliance frameworks, and ensures the effectiveness of security controls across the organization. The position works closely with cross‑functional stakeholders to support regulatory requirements, customer security inquiries, and continuous security improvements in a SaaS/cloud-based environment.
Key Responsibilities- Develop, review, and maintain IT security policies, standards, procedures, and guidelines in alignment with industry best practices and regulatory requirements.
- Lead and coordinate compliance initiatives for security frameworks and standards, including but not limited to ISO 27001, SOC 2, CMMC, NIST, and internal security assessments.
- Manage audit readiness activities, including documentation preparation, evidence collection, stakeholder coordination, and remediation tracking for internal and external audits.
- Respond to customer and partner security questionnaires, ensuring accurate, consistent, and timely responses.
- Conduct periodic security and risk assessments to evaluate the effectiveness of security controls and identify improvement opportunities.
- Track, manage, and follow up on vulnerability remediation efforts in collaboration with IT, engineering, and operations teams.
- Prepare and deliver security metrics, compliance reports, and executive-level summaries.
- Provide security awareness, training, and education to employees to promote a strong security culture across the organization.
- Support continuous improvement of governance, risk, and compliance (GRC) processes and tooling.
- Strong knowledge of information security principles, risk management, and compliance frameworks, with a solid understanding of ISO 27001 requirements and controls.
- Hands-on experience supporting audits and compliance programs for frameworks such as ISO 27001, SOC 2, CMMC, NIST, or similar.
- GRC-related certification (e.g., CISSP, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor) is preferred.
- Experience working in SaaS or technology-driven environments is highly desirable.
- Familiarity with cloud computing platforms and cloud security principles.
- Excellent written and verbal communication skills, with proven ability to produce clear, high-quality security documentation and reports.
- Minimum of 5 years of professional experience in cybersecurity, information security, or compliance-related roles.
- Bachelor’s degree in Computer Engineering, Computer Science, Information Security, or a related field.
Skills Required
- Strong knowledge of information security principles, risk management, and compliance frameworks including ISO 27001
- Hands-on experience supporting audits and compliance programs for ISO 27001, SOC 2, CMMC, NIST, or similar
- GRC-related certification (e.g., CISSP, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor)
- Experience working in SaaS or technology-driven environments
- Familiarity with cloud computing platforms and cloud security principles
- Excellent written and verbal communication skills and ability to produce security documentation and reports
- Minimum of 5 years professional experience in cybersecurity, information security, or compliance-related roles
- Bachelor's degree in Computer Engineering, Computer Science, Information Security, or a related field
Arrow Electronics, Inc. Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Arrow Electronics, Inc. and has not been reviewed or approved by Arrow Electronics, Inc..
-
Affordable Benefits — Medical coverage includes multiple options with income-tiered employer contributions that substantially reduce costs for lower-wage employees (the base plan was heavily subsidized for earners under $55,000). These affordability measures, alongside EAP and telemedicine, help the overall package offset middling base pay in some roles.
-
Parental & Family Support — New parents receive fully paid leave (six weeks at 100% pay in prior materials, with more recent reporting of up to 12 weeks fully paid for the delivering parent in the U.S.). Backup dependent care and related family supports are also provided.
-
Leave & Time Off Breadth — Many salaried roles have unlimited PTO, while hourly staff receive competitive accrual-based PTO, with added flexibility from floating holidays and observance of MLK Day. These options indicate a broad time-off framework across employee groups.
Arrow Electronics, Inc. Insights
What We Do
A Fortune 500 company, ranked #133 in 2024, with over 22,000 employees worldwide, Arrow guides innovation forward for over 220,000 leading technology manufacturers and service providers. With 2023 sales of $33 billion, Arrow develops technology solutions that improve business and daily life. Arrow.com is the easiest place for innovators to create, make and manage technology.
Why Work With Us
Arrow is much more than products and services. We are a team of many backgrounds in a global ecosystem, working toward one common goal: to help customers create a better tomorrow, where innovation improves the quality of life and the benefits of technology are more accessible to all. Join us in building a better tomorrow for many!
Gallery







