Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

ISMS Compliance Manager

Hexagon AB

Compliance Manager

The Compliance Manager is accountable for the design, operation, and continuous improvement of the organisation's Information Security Management System (ISMS) and its associated certification programme. This role is not a technical security engineering position. Instead, it demands a highly organised, process-oriented compliance professional who can orchestrate cross-functional teams, manage external auditors, close control gaps, and ensure that the control environment remains audit-ready at all times. The Compliance Manager serves as the primary interface between the organisation's day-to-day operations and its ISO 27001 certification obligations.

Major Areas of Responsibility:

  • ISMS Program Ownership
    • Own, maintain, and continuously improve the ISO 27001-aligned Information Security Management System (ISMS), including its scope, Statement of Applicability (SoA), risk treatment plan, and all supporting documentation.
    • Serve as the internal subject-matter authority for ISO/IEC 27001 standard requirements and, where applicable, supplementary standards (ISO 27002, 27005, 27017, 27018, SOC 2 overlap).
    • Maintain the organisation's certification roadmap and annual audit calendar, coordinating with the external certification body and any internal audit function.
    • Ensure the ISMS programme remains aligned with organisational strategy, evolving business requirements, regulatory changes, and threat landscape shifts.
  • Control Framework Management
    • Maintain a complete, current, and authoritative ISO 27001 control framework, mapping Annex A controls (and relevant supplementary controls) to business processes, asset owners, and accountable teams.
    • Conduct and manage periodic control effectiveness assessments to verify that controls are designed adequately and are operating as intended.
    • Drive gap remediation: identify control deficiencies, assign remediation owners, set target dates, track progress to closure, and escalate where timelines are at risk.
    • Ensure evidence artefacts (policies, procedures, records, logs, test results) are complete, current, well-organised, and retained in accordance with the ISMS evidence management framework.
    • Manage policy and procedure lifecycle—drafting, review, approval, version control, and annual attestation—in collaboration with policy owners.
  • Audit Management & Readiness
    • Scope, plan, and manage both internal and external ISO 27001 audits (Stage 1, Stage 2 certification, and annual surveillance/recertification audits).
    • Serve as the primary liaison with the external certification body: coordinate logistics, manage the audit schedule, prepare opening and closing meetings, and facilitate auditor access to systems, evidence, and personnel.
    • Proactively assess control adequacy before external audits.
    • Manage all audit findings (minor nonconformities, major nonconformities, and observations): ensure timely root cause analysis, corrective action plans, evidence of closure, and follow-up verification.
    • Maintain a perpetual audit-readiness posture, ensuring the organisation can demonstrate an effective ISMS at any point during the certification cycle—not only at audit time.
  • Risk Management Integration
    • Facilitate the information security risk assessment and risk treatment process working with technical and business stakeholders to identify, evaluate, and treat information security risks.
    • Maintain the risk register and risk treatment plan, tracking risk acceptance decisions, treatment progress, and residual risk posture.
    • Ensure risk assessment outputs are reflected in the SoA and control framework, and that significant residual risks are escalated appropriately to leadership.
  • Cross-Functional Stakeholder Engagement
    • Identify and engage the correct accountable owners across product, engineering, infrastructure, IT, legal, HR, and business operations to obtain evidence, close gaps, and ensure control sustainability.
    • Facilitate Management Review meetings as required by the standard, preparing agenda materials, risk summaries, audit result summaries, and improvement recommendations.
    • Develop and maintain a stakeholder engagement model that clarifies each team's ISMS responsibilities without requiring them to become compliance specialists.
    • Act as a trusted advisor to leadership on the organisation's compliance posture, certification status, and material risks.
    • Support teams as they address questions regarding information security management, including responses to customer security questionnaires.
    • Manage and support incident response efforts, including containment, investigation, and recovery.
  • Compliance Programme Governance
    • Maintain a compliance calendar covering ISMS obligations—control reviews, policy attestations, risk assessments, internal audits, and external audit milestones.
    • Produce regular compliance status reports and management dashboards that accurately reflect the state of the control environment, open gaps, and remediation progress.
    • Contribute to supplier assurance activities by assessing third-party compliance requirements relevant to the ISMS scope.

Key Stakeholders:

  • VP of Information Technology and Data
  • Group Privacy and Information Security Officer
  • Group Governance, Risk, and Compliance
  • SVP of Product
  • SVP of Engineering
  • Engineering Management
  • Legal and Compliance

Knowledge and Experience - Required:

  • Bachelor's degree in Information Security, Computer Science, Business Administration, or a related field; or equivalent professional experience.
  • 5+ years of experience in information security compliance, GRC (Governance, Risk, and Compliance), or audit management roles.
  • Demonstrated, hands-on experience managing an ISO 27001 ISMS through at least one full certification or recertification audit cycle—including scoping, internal audits, external audit management, and nonconformity remediation.
  • Proven ability to manage cross-functional stakeholders without direct authority—influencing product, engineering, HR, legal, and operations teams to meet compliance obligations.
  • Experience maintaining control frameworks, risk registers, and ISMS documentation libraries.
  • Track record of writing and managing information security policies and procedures.

Knowledge and Experience - Desired:

  • Deep knowledge of the ISO/IEC 27001:2022 standard, Annex A controls, and supporting guidance in ISO/IEC 27002:2022.
  • Strong understanding of information security risk assessment methodologies.
  • Ability to read, interpret, and apply compliance and audit requirements without needing to be a hands-on technical security practitioner.
  • Excellent written and verbal communication skills; able to translate complex compliance requirements into clear, actionable guidance for non-security audiences.
  • Strong project and programme management skills: ability to manage multiple workstreams, deadlines, and stakeholders simultaneously.
  • CISM (Certified Information Security Manager) or CRISC (Certified in Risk and Information Systems Control).
  • Working knowledge of complementary frameworks such as SOC 2 (Type I/II), NIST CSF, CIS Controls, GDPR, or CCPA—particularly where they overlap with or supplement the ISO 27001 control environment.
  • Prior experience in a regulated industry (financial services, healthcare, or public sector) where certification drives contractual or regulatory obligations.

Travel:

  • Travel is expected to complete job function - including potential significant periods of travel related to coordination of audit readiness and execution. Overall travel is not to exceed 50% of time.

Hexagon is an Equal Opportunity Employer. We prohibit discrimination against any job applicant based on protected characteristics.

Vacancy posted 11 hours ago
Similar jobs that could be interesting for youBased on the ISMS Compliance Manager in Tucson, AZ vacancy
  •  ...at hexagon.com and follow us @HexagonAB. The Role: The Compliance Manager is accountable for the design, operation, and continuous improvement...  ...the organisation's Information Security Management System (ISMS) and its associated certification programme. This role is not... 
    Suggested
    Shift work

    Hexagon Mining

    Tucson, AZ
    11 hours ago
  • $74.25k

     ...are building more than programs. We are building careers that make a difference. Position Overview Prevention of Sexual Abuse Compliance Manager (PSA Compliance Manager) plays a crucial role in developing and implementing strategies aimed at preventing sexual abuse and... 
    Suggested
    Odd job
    Temporary work
    Interim role
    Local area
    Relocation package
    Flexible hours
    Night shift
    Weekend work
    Day shift

    VQ

    Tucson, AZ
    3 days ago
  •  ...government agencies. AKIVA is a certified Service-Disabled Veteran-Owned Small Business (SDVOSB). Position Overview The Compliance & HR Manager owns workforce compliance, onboarding administration, personnel documentation, employment eligibility verification,... 
    Suggested
    Long term contract
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Work from home
    Flexible hours

    AKIVA AI

    Tucson, AZ
    26 days ago
  •  ...-Owned Small Business (SDVOSB). Position Overview The CDL Compliance Coordinator oversees commercial driving compliance for temporary personnel assigned to operate customer-owned or customer-managed commercial vehicles. This role administers driver qualification,... 
    Suggested
    Long term contract
    Full time
    Temporary work
    Work at office
    Work from home
    Flexible hours

    AKIVA AI

    Tucson, AZ
    26 days ago
  •  ...Job Description Job Description ProStratus, a Certified Level 2 Managed Security Service Provider (MSSP), is seeking a skilled CMMC Compliance Analyst to join our team. In this role, you will play a critical part in supporting our clients’ efforts to achieve and maintain... 
    Suggested

    ProStratus, LLC

    Tucson, AZ
    24 days ago
  • $165k - $220k

     ...Regulatory Affairs leads global regulatory strategy, reporting, compliance, labeling, and regulatory intelligence to support product...  ...health authority interactions, ensure highquality submissions, and manage regulatory risk across the product lifecycle. Responsibilities... 
    Temporary work
    Work visa

    Bausch + Lomb

    Tucson, AZ
    4 days ago
  • Cadden Community Management is seeking a Community Association Manager (CAM) in Southern Arizona. The role involves oversight of homeowner associations, ensuring compliance and financial management in an organized environment. Ideal candidates would have significant HOA... 

    Cadden Community Management

    Tucson, AZ
    1 day ago
  • Akiva Technologies LLC is seeking a Compliance & HR Manager in Tucson, Arizona. This role requires ownership of workforce compliance and onboarding administration. The ideal candidate will have extensive knowledge of HR compliance and federal employment laws. Benefits include... 
    Remote job

    Akiva Technologies LLC

    Tucson, AZ
    3 days ago
  •  ...Job Description Job Description Director – Responsible AI, Governance & Compliance Location: US / Canada (Remote/Hybrid) Type: Contract / Full-Time Overview: We are looking for a Director-level leader to drive Responsible AI, governance, and compliance... 
    Full time
    Contract work
    Remote work

    NavitasPartners

    Tucson, AZ
    17 days ago
  •  ...is looking for an energetic International Regulatory Affairs Manager. The successful candidate will be responsible for managing SynCardia...  ...the U.S. However, due to state-specific employment law and compliance considerations, we are currently unable to hire employees... 
    Currently hiring
    Work at office
    Remote work

    SYNCARDIA SYSTEMS, LLC.

    Tucson, AZ
    14 days ago
  • $100k - $120k

     ...Select how often (in days) to receive an alert: Trade Compliance Specialist - Tucson, AZ Apply now Date: May 5, 20...  ...and audit readiness. The primary focus of this role is FTZ management. Limited support to broader non-FTZ global trade compliance initiatives... 
    Temporary work
    Remote work

    Belden

    Tucson, AZ
    3 days ago
  •  ...Cybersecurity Compliance Specialist This position will require access to ITAR and/or EAR controlled technical data, technology or source...  ...position reporting to the Information Technology & Systems Manager. The Cybersecurity & Compliance Specialist is responsible for... 
    For contractors
    Work at office

    RE Darling

    Tucson, AZ
    2 days ago
  • $21 per hour

     ...Description Job Overview: As the Compliance Coordinator, you will be responsible for regularly touring the neighborhoods street-...  ...~​Previous experience in compliance monitoring, property management, or related field is highly preferred Physical Requirements... 
    Hourly pay
    Full time
    Work at office
    Local area
    Monday to Friday

    FirstService Residential

    Tucson, AZ
    8 days ago
  •  ...term goals for the nursing staff. Anticipates and effectively manage changes in census and acuity and allocates nursing resources...  ...nursing protocols within the facility to meet all regulatory, compliance and quality care standards. Responsible for the quality of care... 

    Noor Staffing Group

    Tucson, AZ
    26 days ago
  •  ...on making an impact and want the excitement of being on a team that wins. Job Description Job Summary: The Senior Export Compliance Specialist will serve as a key export control subject matter expert supporting Teledyne FLIR Defense programs, including unmanned... 
    Minimum wage
    Permanent employment
    Work experience placement
    Local area

    Teledyne

    Tucson, AZ
    3 days ago
  •  ...Title : Compliance Analyst Pay : $40.00/hr on W2! Location : Tucson, AZ 6 months contract US Citizenship required Description Key Responsibilities include: • Evaluate purchase orders for compliance to FAR, DFAR and company policies/procedures • Support... 
    Contract work
    Work at office

    Trispoke Managed Services Pvt Ltd

    Tucson, AZ
    2 days ago
  •  ...a certified Service-Disabled Veteran-Owned Small Business (SDVOSB). Position Overview AKIVA is seeking a Program Manager & Compliance Lead to own end-to-end delivery of our on-call / on-demand staffing operation supporting a public-sector client in the Seattle... 
    Permanent employment
    Full time
    Contract work
    Temporary work
    For subcontractor
    Work at office
    Local area

    AKIVA AI

    Tucson, AZ
    24 days ago
  •  ...We are seeking a reliable, tenacious, and values-driven professional to join our team as a Compliance Coordinator. This role reports directly to the Compliance Manager and regularly collaborates with the onboarding and operations departments. What's in it for... 
    Permanent employment
    Full time
    Immediate start
    Shift work

    Buckled In

    Tucson, AZ
    4 days ago
  • $130k - $160k

     ...services, ensuring high standards of patient care, regulatory compliance, staff development, and operational excellence within an inpatient...  ...excellent leadership, communication, and operational management skills while fostering a culture centered on patient safety, clinical... 

    Taphealthcare

    Tucson, AZ
    25 days ago
  • Job Description Job Description Description: Tucson, AZ | Full-time | On-site About SynCardia Systems LLC SynCardia develops, manufactures, and commercializes the SynCardia Total Artificial Heart (STAH), the only commercially available total artificial heart...
    Full time
    Work at office

    SYNCARDIA SYSTEMS, LLC.

    Tucson, AZ
    14 days ago
  •  ...commercial and Medicare health plans. Collaborates with program manager and HR to compile and submit credentialing documents and...  ...Professionals and Independently Licensed Professional staff, ensuring compliance with regulatory bodies (Joint Commission, NCQA, URAC, CMS,... 

    Intermountain Centers

    Tucson, AZ
    5 days ago
  • ## Labor Compliance Officer IApplyremote type: Onsite Worklocations: City Halltime type: Full timeposted on: Posted 2 Days Agojob requisition...  ...is performed under the direct supervision of the Procurement Manager. This position does not supervise.**Duties and... 
    Hourly pay
    Contract work
    For contractors
    Work experience placement
    For subcontractor
    Work at office
    Local area
    Monday to Friday
    Flexible hours

    Tucson Police Department

    Tucson, AZ
    2 days ago
  • $69.91k - $83.89k

     ...Wastewater Reclamation Department is hiring a Permit Regulatory Compliance Officer to lead and supervise the Industrial Wastewater...  ...activities to prevent pollution into the sewers. The team also manages an active FOG program to ensure proper handling of fats, oils,... 
    Flexible hours

    Pima County

    Tucson, AZ
    5 days ago
  • Broughton Group is seeking talented individuals for Regulatory Analyst positions in Tucson, Arizona. The role involves analyzing the revenue requirements for utility affiliates and preparing financial analyses. Candidates may enter at various levels from no experience to...

    Broughton Group

    Tucson, AZ
    1 day ago
  • A leading cybersecurity firm in Tucson is seeking a Cyber Security Specialist to protect organizational networks and systems from unauthorized access and attacks. This role includes developing security policies, conducting assessments, and responding to incidents. The ideal...

    Ascension Fed

    Tucson, AZ
    4 days ago
  • $26.57 - $39.86 per hour

     ...Business Enterprise Compliance Specialist I Position Specific Summary The Business Enterprise Compliance Specialist I position at...  ...performed under the supervision of the Contract Administration Manager. This position does not supervise. Duties and... 
    Hourly pay
    Full time
    Contract work
    For contractors
    Work experience placement
    For subcontractor
    Work at office
    Local area
    Flexible hours

    Tucson Talent

    Tucson, AZ
    2 days ago
  • Overview Hexagon’s Autonomous Solutions business area is looking for a Program Manager, Legal and Compliance to join our team. The role will report to and support the VP, Business Area General Counsel and Compliance Officer in planning, leading, and executing programs for... 
    Work at office

    Hexagon Autonomous Solutions

    Tucson, AZ
    4 days ago
  • $101k - $203k

    Itlearn360 is seeking a Manager, Logistics for an onsite position in Tucson, AZ. This leadership role focuses on transportation operations, requiring strong knowledge of SAP and compliance with IATA and 49 CFR regulations. The candidate must have significant management... 

    Itlearn360

    Tucson, AZ
    5 days ago
  •  ...Clinical quality and patient safety Nursing workforce performance and engagement Regulatory compliance and evidence-based practice Resource and financial management The CNO partners with executive leadership, the medical staff, and the governing board to... 

    Other Executive

    Tucson, AZ
    2 days ago
  •  ...is seeking an experienced cultural resource professional to lead its Cultural Resources Compliance and Regulatory Programs, reporting to the Historic Preservation Officer. The manager ensures compliance with federal, state, and local preservation laws and supervises... 
    Local area

    Pima County

    Tucson, AZ
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to ISMS Compliance Manager. Be the first to apply!