ISMS Compliance Manager
Hexagon Mining, Inc.
The Company:
Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications.
Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous — ensuring a scalable, sustainable future.
Hexagon’s Mining division solves surface and underground mine challenges with proven technologies for planning, operations, and safety.
Hexagon (Nasdaq Stockholm: HEXA B) has approximately 24,000 employees in 50 countries and net sales of approximately 5.5bn USD. Learn more at hexagon.com and follow us @HexagonAB.
The Role:
The Compliance Manager is accountable for the design, operation, and continuous improvement of the organisation’s Information Security Management System (ISMS) and its associated certification programme. This role is not a technical security engineering position. Instead, it demands a highly organised, process-oriented compliance professional who can orchestrate cross-functional teams, manage external auditors, close control gaps, and ensure that the control environment remains audit-ready at all times. The Compliance Manager serves as the primary interface between the organisation’s day-to-day operations and its ISO 27001 certification obligations.
Major Areas of Responsibility:
- ISMS Program Ownership
- Own, maintain, and continuously improve the ISO 27001-aligned Information Security Management System (ISMS), including its scope, Statement of Applicability (SoA), risk treatment plan, and all supporting documentation.
- Serve as the internal subject-matter authority for ISO/IEC 27001 standard requirements and, where applicable, supplementary standards (ISO 27002, 27005, 27017, 27018, SOC 2 overlap).
- Maintain the organisation’s certification roadmap and annual audit calendar, coordinating with the external certification body and any internal audit function.
- Ensure the ISMS programme remains aligned with organisational strategy, evolving business requirements, regulatory changes, and threat landscape shifts.
- Control Framework Management
- Maintain a complete, current, and authoritative ISO 27001 control framework, mapping Annex A controls (and relevant supplementary controls) to business processes, asset owners, and accountable teams.
- Conduct and manage periodic control effectiveness assessments to verify that controls are designed adequately and are operating as intended.
- Drive gap remediation: identify control deficiencies, assign remediation owners, set target dates, track progress to closure, and escalate where timelines are at risk.
- Ensure evidence artefacts (policies, procedures, records, logs, test results) are complete, current, well-organised, and retained in accordance with the ISMS evidence management framework.
- Manage policy and procedure lifecycle—drafting, review, approval, version control, and annual attestation—in collaboration with policy owners.
- Audit Management & Readiness
- Scope, plan, and manage both internal and external ISO 27001 audits (Stage 1, Stage 2 certification, and annual surveillance/recertification audits).
- Serve as the primary liaison with the external certification body: coordinate logistics, manage the audit schedule, prepare opening and closing meetings, and facilitate auditor access to systems, evidence, and personnel.
- Proactively assess control adequacy before external audits.
- Manage all audit findings (minor nonconformities, major nonconformities, and observations): ensure timely root cause analysis, corrective action plans, evidence of closure, and follow-up verification.
- Maintain a perpetual audit-readiness posture, ensuring the organisation can demonstrate an effective ISMS at any point during the certification cycle—not only at audit time.
- Risk Management Integration
- Facilitate the information security risk assessment and risk treatment process working with technical and business stakeholders to identify, evaluate, and treat information security risks.
- Maintain the risk register and risk treatment plan, tracking risk acceptance decisions, treatment progress, and residual risk posture.
- Ensure risk assessment outputs are reflected in the SoA and control framework, and that significant residual risks are escalated appropriately to leadership.
- Cross-Functional Stakeholder Engagement
- Identify and engage the correct accountable owners across product, engineering, infrastructure, IT, legal, HR, and business operations to obtain evidence, close gaps, and ensure control sustainability.
- Facilitate Management Review meetings as required by the standard, preparing agenda materials, risk summaries, audit result summaries, and improvement recommendations.
- Develop and maintain a stakeholder engagement model that clarifies each team’s ISMS responsibilities without requiring them to become compliance specialists.
- Act as a trusted advisor to leadership on the organisation’s compliance posture, certification status, and material risks.
- Support teams as they address questions regarding information security management, including responses to customer security questionnaires
- Manage and support incident response efforts, including containment, investigation, and recovery.
- Compliance Programme Governance
- Maintain a compliance calendar covering ISMS obligations—control reviews, policy attestations, risk assessments, internal audits, and external audit milestones.
- Produce regular compliance status reports and management dashboards that accurately reflect the state of the control environment, open gaps, and remediation progress.
- Contribute to supplier assurance activities by assessing third-party compliance requirements relevant to the ISMS scope.
Key Stakeholders:
This role will be successful if able to build relationships and work directly with the following stakeholders:
- VP of Information Technology and Data
- Group Privacy and Information Security Officer
- Group Governance, Risk, and Compliance
- SVP of Product
- SVP of Engineering
- Engineering Management
- Legal and Compliance
Knowledge and Experience - Required:
- Bachelor’s degree in Information Security, Computer Science, Business Administration, or a related field; or equivalent professional experience.
- 5+ years of experience in information security compliance, GRC (Governance, Risk, and Compliance), or audit management roles.
- Demonstrated, hands-on experience managing an ISO 27001 ISMS through at least one full certification or recertification audit cycle—including scoping, internal audits, external audit management, and nonconformity remediation.
- Proven ability to manage cross-functional stakeholders without direct authority—influencing product, engineering, HR, legal, and operations teams to meet compliance obligations.
- Experience maintaining control frameworks, risk registers, and ISMS documentation libraries.
- Track record of writing and managing information security policies and procedures.
Knowledge and Experience - Desired:
- Deep knowledge of the ISO/IEC 27001:2022 standard, Annex A controls, and supporting guidance in ISO/IEC 27002:2022.
- Strong understanding of information security risk assessment methodologies.
- Ability to read, interpret, and apply compliance and audit requirements without needing to be a hands-on technical security practitioner.
- Excellent written and verbal communication skills; able to translate complex compliance requirements into clear, actionable guidance for non-security audiences.
- Strong project and programme management skills: ability to manage multiple workstreams, deadlines, and stakeholders simultaneously.
- CISM (Certified Information Security Manager) or CRISC (Certified in Risk and Information Systems Control).
- Working knowledge of complementary frameworks such as SOC 2 (Type I/II), NIST CSF, CIS Controls, GDPR, or CCPA—particularly where they overlap with or supplement the ISO 27001 control environment.
- Prior experience in a regulated industry (financial services, healthcare, or public sector) where certification drives contractual or regulatory obligations.
Travel:
- Travel is expected to complete job function - including potential significant periods of travel related to coordination of audit readiness and execution. Overall travel is not to exceed 50% of time.
Hexagon is an Equal Opportunity Employer. We prohibit discrimination against any job applicant based on protected characteristics.
- ...Prevention Of Sexual Abuse (PSA) Compliance Manager - JOR The Prevention of Sexual Abuse Compliance Manager for La Jornada is responsible for the implementation, training, documentation and ongoing compliance with ORR Policy Section 4, 5 and the Interim Final Rule...SuggestedContract workInterim roleWork at officeFlexible hoursNight shiftWeekend work
$45 - $55 per hour
...Job Title: Regulatory Affairs Manager - PHCS Location: Tucson, AZ Type: Contract Compensation: $45-55.00/hr... ...leadership principles. Responsibilities • Submission & Compliance: Oversee the development of complex registration dossiers and...SuggestedContract workTemporary workLocal area- ...Title : Compliance Analyst Pay : $40.00/hr on W2! Location : Tucson, AZ 6 months contract US Citizenship required Description Key Responsibilities include: • Evaluate purchase orders for compliance to FAR, DFAR and company policies/procedures • Support...SuggestedContract workWork at office
$45 - $55 per hour
...Job Description Job Description Regulatory Affairs Manager Location: Tucson, AZ Employment Type: 1 year - W2 -Contract... ...technologies. Key Responsibilities Regulatory Submissions & Compliance: Lead the development of complex regulatory registration...SuggestedContract work- ...Generous Paid Time Off (PTO) ~401k Retirement Plan with Company Match ~ And much more... Job Responsibilities The Manager, Compliance and Regulatory Affairs reports to the AVP, Legal & Compliance and has a key role in supporting the implementation of the seven...SuggestedContract workTemporary work
$159.12k - $238.68k
...Division Manager Risk & Compliance Your Work Shapes the World at Caterpillar Inc. When you join Caterpillar, you're joining a global team who cares not just about the work we do but also about each other. We are the makers, problem solvers, and future world builders...Part timeRelocation packageFlexible hours- ...Credentialing Specialist The Credentialing Specialist position requires an organized individual with good time management skills and related industry experience, (both facility and clinic credentialing / privileging). The Credentialing Specialist will be responsible...Full timeContract workWork at officeRelocationMonday to FridayFlexible hoursDay shift
$84.6k - $157.2k
...engineering changes, labeling, product changes, and documentation for compliance and for changes requiring regulatory agency approval, as per... ..., development, clinical affairs, quality, or program management in IVD, medical device, or pharma industries. Experience in Healthcare...Local areaRemote workRelocation package- ...care. The ideal candidate will have a proven track record in nursing leadership, with a focus on strategic planning, operational management, and the promotion of a culture of excellence. A strong educational background in nursing, including a Master's degree in nursing...
- ...team. The successful candidate will be responsible for planning, managing, and coordinating various business and commercial development... ...Deputy Chief Revenue Officer will also be expected to ensure compliance with all relevant laws and regulations, and to be responsive...
- ...embed strategies across operations and with the CCEO to guarantee compliance, accountability, and continuous modernization that keeps... ...Stakeholder Engagement & Partnership Building Cultivate and manage strategic partnerships with K-12 schools, community colleges, universities...Contract workTemporary workApprenticeship
- ...medical billing knowledge and understanding in order to monitor and manage accounts, claims, claims resolution, accounts receivable, and... ...etc.) Keep track and process accounts and incoming payments in compliance with financial policies and procedures. Send daily / weekly...Work at office
$127.92k - $191.88k
...supports revenue growth at Tucson International Airport (TUS) and Ryan Airfield (RYN). This position oversees property and lease management, concessions, and ground transportation while supporting regional economic development initiatives that strengthen the airport system...Relocation- ...Commercial Development Division to execute the tasks of the Agreement Management Lifecycle Standard Operating Procedure (SOP). Evaluate the... ...(KPIs) related to revenue growth, tenant performance, lease compliance and commercial development. Direct and oversee all...Work at officeLocal areaImmediate start
$157.2k - $298.8k
...state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act. RaytheonTemporary workWork experience placementFlexible hours$72.01k - $86.4k
...Employee Relations Compliance Officer Open Until Filled Job Type: Classified Job Classification: 5410 - Employee Relations Compliance... ...in creating and/or presenting training for employees and management; Assists with Merit System Commission/Law Enforcement Merit...Work experience placement- ...250 employees across the state. We're 100% Arizona owned and managed, which means you'll never feel like a number here. Our team delivers... ...and equipment used in surveying. May perform mapping compliance or related office survey duties as a temporary assignment to satisfy...Temporary workFor contractorsWork at officeFlexible hoursNight shift
- ...genetic information, political affiliation, military service, or any other non-merit based factor. These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career...For contractorsWork experience placement
- ...acceptable; robust research funding is welcomed but not required. Entrepreneurial mindset and comfort leading growth, change management, and service line expansion. About the Community Immediate access to hiking, cycling, trail running, golf, scenic drives...Local areaImmediate startRelocation package
- ...operations, including strategic planning, fundraising, financial management, program oversight, and community partnerships. This is a... ...programming Supervise personnel and ensure financial/regulatory compliance Serve as the public face of SAAS and advocate for adaptive sports...Full timeFlexible hoursWeekend workAfternoon shift
- ...Overview The Executive Director provides strategic leadership and day-to-day management, ensuring CSDP advances its mission, remains financially sustainable, and operates effectively. As the leader of a small, collaborative team, the Executive Director is both a strategic...Local area
$130k - $140k
...purpose and joy while leading our community to success!About Grace Management, Inc.Grace Management, Inc. is a national leader in senior... ...mission of the organization. The Executive Director maintains compliance with federal, state, and local regulations. The Executive...Daily paidFull timeWork at officeLocal areaHome officeWeekend work$16.21 - $16.96 per hour
...rewards program ~ Uniforms paid for and laundered GEAR UP FOR YOUR ROLE: As a Crew Chief, you're an important part of our management team, focused on giving top-notch service to customers. You'll team up with the General Manager to guide the crew, keep things...Full timeFlexible hours- ...Architecture, AI/ML risk mitigation, and Post-Quantum Computing readiness. Key Responsibilities: Provide continuous technical management for the security operations shift. Perform weekly audits of security monitors and account privilege changes. Monitor SIEM...Work at officeLocal areaShift work
$54.83k - $71.73k
DEPARTMENT OF PUBLIC SAFETY The Department of Public Safety’s mission is to provide public safety to the state of Arizona. Visit our website at DETENTION TRANSPORT OFFICER Salary: $54,831.92 - $71,726.51 The Arizona Department of Public Safety is seeking motivated and...Temporary workRotating shift$36.19 per hour
Duties Transporting, guarding, and escorting detainees. Benefits Paid vacation, sick leave, holidays. Rate $36.19 includes Health and Welfare Requirements US citizen, 21 years of age. 3 years’ combined experience with either law enforcement, military, or corrections. Pass...$235k - $255k
...developing and executing pricing strategies that drive significant business impact, collaborating with key stakeholders such as Product Managers and Directors to optimize business performance. In this role, you will lead initiatives focused on enhancing pricing models and...Remote jobWork from homeFlexible hoursNight shift$107.5k - $204.5k
...status of the technical data packages and readiness for test Managing and presenting to Stakeholders and Customer community, in... ...qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era...Temporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours$36.19 per hour
Armed Transportation Officers Asset Protection & Security Services, a 30-year company, with 24 years of those years specializing in detention and transportation, is looking for people to be part of our team. If you meet the requirements or have questions, please contact...- ...provider in Tucson, Arizona is seeking a Rehab Director to lead their therapy teams. The role involves overseeing clinical excellence, compliance with healthcare regulations, and staff development. Ideal candidates will have a relevant degree, state certification, and...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to ISMS Compliance Manager. Be the first to apply!
- regulatory compliance Tucson, AZ
- compliance team leader Tucson, AZ
- regulatory compliance specialist Tucson, AZ
- regulatory compliance associate Tucson, AZ
- environmental compliance Tucson, AZ
- corporate compliance Tucson, AZ
- finance compliance Tucson, AZ
- vendor compliance Tucson, AZ
- medicaid compliance Tucson, AZ
- director quality assurance regulatory affairs Tucson, AZ




