ISMS Compliance Manager
Hexagon Group
The Company:Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications.Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous — ensuring a scalable, sustainable future.Hexagon’s Mining division solves surface and underground mine challenges with proven technologies for planning, operations, and safety.Hexagon (Nasdaq Stockholm: HEXA B) has approximately 24,000 employees in 50 countries and net sales of approximately 5.5bn USD. Learn more at hexagon.com and follow us @HexagonAB.The Role:The Compliance Manager is accountable for the design, operation, and continuous improvement of the organisation’s Information Security Management System (ISMS) and its associated certification programme. This role is not a technical security engineering position. Instead, it demands a highly organised, process-oriented compliance professional who can orchestrate cross-functional teams, manage external auditors, close control gaps, and ensure that the control environment remains audit-ready at all times. The Compliance Manager serves as the primary interface between the organisation’s day-to-day operations and its ISO 27001 certification obligations.Major Areas of Responsibility:ISMS Program OwnershipOwn, maintain, and continuously improve the ISO 27001-aligned Information Security Management System (ISMS), including its scope, Statement of Applicability (SoA), risk treatment plan, and all supporting documentation.Serve as the internal subject-matter authority for ISO/IEC 27001 standard requirements and, where applicable, supplementary standards (ISO 27002, 27005, 27017, 27018, SOC 2 overlap).Maintain the organisation’s certification roadmap and annual audit calendar, coordinating with the external certification body and any internal audit function.Ensure the ISMS programme remains aligned with organisational strategy, evolving business requirements, regulatory changes, and threat landscape shifts.Control Framework ManagementMaintain a complete, current, and authoritative ISO 27001 control framework, mapping Annex A controls (and relevant supplementary controls) to business processes, asset owners, and accountable teams.Conduct and manage periodic control effectiveness assessments to verify that controls are designed adequately and are operating as intended.Drive gap remediation: identify control deficiencies, assign remediation owners, set target dates, track progress to closure, and escalate where timelines are at risk.Ensure evidence artefacts (policies, procedures, records, logs, test results) are complete, current, well-organised, and retained in accordance with the ISMS evidence management framework.Manage policy and procedure lifecycle—drafting, review, approval, version control, and annual attestation—in collaboration with policy owners.Audit Management & ReadinessScope, plan, and manage both internal and external ISO 27001 audits (Stage 1, Stage 2 certification, and annual surveillance/recertification audits).Serve as the primary liaison with the external certification body: coordinate logistics, manage the audit schedule, prepare opening and closing meetings, and facilitate auditor access to systems, evidence, and personnel.Proactively assess control adequacy before external audits.Manage all audit findings (minor nonconformities, major nonconformities, and observations): ensure timely root cause analysis, corrective action plans, evidence of closure, and follow-up verification.Maintain a perpetual audit-readiness posture, ensuring the organisation can demonstrate an effective ISMS at any point during the certification cycle—not only at audit time.Risk Management IntegrationFacilitate the information security risk assessment and risk treatment process working with technical and business stakeholders to identify, evaluate, and treat information security risks.Maintain the risk register and risk treatment plan, tracking risk acceptance decisions, treatment progress, and residual risk posture.Ensure risk assessment outputs are reflected in the SoA and control framework, and that significant residual risks are escalated appropriately to leadership.Cross-Functional Stakeholder EngagementIdentify and engage the correct accountable owners across product, engineering, infrastructure, IT, legal, HR, and business operations to obtain evidence, close gaps, and ensure control sustainability.Facilitate Management Review meetings as required by the standard, preparing agenda materials, risk summaries, audit result summaries, and improvement recommendations.Develop and maintain a stakeholder engagement model that clarifies each team’s ISMS responsibilities without requiring them to become compliance specialists.Act as a trusted advisor to leadership on the organisation’s compliance posture, certification status, and material risks.Support teams as they address questions regarding information security management, including responses to customer security questionnairesManage and support incident response efforts, including containment, investigation, and recovery.Compliance Programme GovernanceMaintain a compliance calendar covering ISMS obligations—control reviews, policy attestations, risk assessments, internal audits, and external audit milestones.Produce regular compliance status reports and management dashboards that accurately reflect the state of the control environment, open gaps, and remediation progress.Contribute to supplier assurance activities by assessing third-party compliance requirements relevant to the ISMS scope.Key Stakeholders:This role will be successful if able to build relationships and work directly with the following stakeholders:VP of Information Technology and DataGroup Privacy and Information Security OfficerGroup Governance, Risk, and ComplianceSVP of ProductSVP of EngineeringEngineering ManagementLegal and ComplianceKnowledge and Experience - Required:Bachelor’s degree in Information Security, Computer Science, Business Administration, or a related field; or equivalent professional experience.5+ years of experience in information security compliance, GRC (Governance, Risk, and Compliance), or audit management roles.Demonstrated, hands-on experience managing an ISO 27001 ISMS through at least one full certification or recertification audit cycle—including scoping, internal audits, external audit management, and nonconformity remediation.Proven ability to manage cross-functional stakeholders without direct authority—influencing product, engineering, HR, legal, and operations teams to meet compliance obligations.Experience maintaining control frameworks, risk registers, and ISMS documentation libraries.Track record of writing and managing information security policies and procedures.Knowledge and Experience - Desired:Deep knowledge of the ISO/IEC 27001:2022 standard, Annex A controls, and supporting guidance in ISO/IEC 27002:2022.Strong understanding of information security risk assessment methodologies.Ability to read, interpret, and apply compliance and audit requirements without needing to be a hands-on technical security practitioner.Excellent written and verbal communication skills; able to translate complex compliance requirements into clear, actionable guidance for non-security audiences.Strong project and programme management skills: ability to manage multiple workstreams, deadlines, and stakeholders simultaneously.CISM (Certified Information Security Manager) or CRISC (Certified in Risk and Information Systems Control).Working knowledge of complementary frameworks such as SOC 2 (Type I/II), NIST CSF, CIS Controls, GDPR, or CCPA—particularly where they overlap with or supplement the ISO 27001 control environment.Prior experience in a regulated industry (financial services, healthcare, or public sector) where certification drives contractual or regulatory obligations.Travel:Travel is expected to complete job function - including potential significant periods of travel related to coordination of audit readiness and execution. Overall travel is not to exceed 50% of time.Hexagon is an Equal Opportunity Employer. We prohibit discrimination against any job applicant based on protected characteristics.Department: GENERAL MANAGEMENT Location: Tucson, AZ HeadquartersJob type: Full Time
$106.1k - $197k
...compilation, which includes the development of submission/product registration dossiers of more complex products/programs. You develop and manage parts of comprehensive global regulatory submissions and registration plans. You interface with external management. You understand...SuggestedFull timeLocal areaWorldwideRelocation package- ...of Position:Hexagon’s Mining division is looking for a Customs Compliance and Logistics Coordinator to join our high-tech engineering... ...excellence and continuous improvement. Reporting to our Supply Chain Manager, you will be part of a dynamic and supportive supply chain...SuggestedFull time
$10 per hour
...initiatives across the facility. Recruit, mentor, and retain top nursing talent to build a high-performing, compassionate care team. Manage nursing budgets, staffing plans, and resource allocation to support operational goals. Serve as a key liaison between nursing,...SuggestedTemporary workLocal area- ...care. The ideal candidate will have a proven track record in nursing leadership, with a focus on strategic planning, operational management, and the promotion of a culture of excellence. A strong educational background in nursing, including a Master's degree in nursing...Suggested
- ...contingent upon award of contract SOSi is seeking a Risk and Compliance Analyst to support mission requirements for a structured... ...a DoD Program of Record. Proficient in JCIDS, requirements management tools, and stakeholder engagement to define and validate operational...SuggestedFull timeContract workFor contractorsRemote workWorldwide
$130k - $160k
...inpatient psychiatric setting. ~3 years of progressive nursing management or administrative nursing experience. ~ Prior CNO/DON... ...nursing protocols within the facility to meet all regulatory, compliance and quality care standards. Responsible for the quality of...Relocation package- ...Credentialing Specialist The Credentialing Specialist position requires an organized individual with good time management skills and related industry experience, (both facility and clinic credentialing / privileging). The Credentialing Specialist will be responsible...Full timeContract workWork at officeRemote workRelocationMonday to FridayFlexible hoursDay shift
- ...medical billing knowledge and understanding in order to monitor and manage accounts, claims, claims resolution, accounts receivable, and... ....) • Keep track and process accounts and incoming payments in compliance with financial policies and procedures. Send daily / weekly...Work at office
$107.5k - $204.5k
...aerospace and defense.Raytheon is seeking an experienced Program Management, Planning & Scheduling manager to join the Program Design &... ...and supporting documents to ensure quality, completeness and compliance.Support EAC and LRE processes as they relate to the Program IMSLead...Full timeContract workTemporary workWork experience placementFor subcontractorWork at officeRemote workRelocationRelocation packageFlexible hours- ...Trust Architecture, AI/ML risk mitigation, and Post-Quantum Computing readiness. Key Responsibilities:Provide continuous technical management for the security operations shift.Perform weekly audits of security monitors and account privilege changes.Monitor SIEM and...Full timeWork at officeLocal areaRemote workShift work
- ...term goals, strategies, and achieves desired outcomes; ensuring compliance and accreditation; and guides Tucson Medical Center aligning... ...development and succession planning.Oversee the development and management of the Tucson Medical Center budget, ensuring the organization...Temporary workLocal area
- ...ResponsibilitiesGeneral Core Duties Provide strategic leadership and management of day-to-day operations and set a clear vision and execution... ...Availability of the Annual Security and Fire Safety ReportIn compliance with the Jeanne Clery Disclosure of Campus Security Policy and...Full timeTemporary workTraineeshipWork at officeLocal areaRelocationWeekday work
$159.12k - $238.68k
...quality deliverables that are actionable, high impact, and lead to successful change on time. Be a trusted advisor to senior leaders, managing internal business partner expectations and relationships. Support the Senior Director in executing the team’s vision and owning at...Flexible hours- ...RTX in Tucson, Arizona is seeking an NSMS Manager, Supply Chain Management to support Production Assurance for Naval Standard Missile Systems production. The role involves leading material strategies, supplier management, and cross-functional collaboration with Program...
$132.4k - $251.6k
...Qualifications We Prefer: Degree in Engineering, Operations Management, Supply Chain, Business Administration, or Finance... ...qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era...Temporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours- Mister Car Wash in Tucson, AZ seeks a Sr. Director of Supply Chain & Strategic Sourcing to build and scale a centralized procurement function. Reporting to the CFO, you will lead indirect and select direct spend, shaping policies and governance to improve cost, service...
- Summary The officer is responsible for presiding over and delivering impartial school discipline hearings. The officer will liaise with the Department of Student Equity to identify, support, and forward disciplinary decisions that are restorative and redemptive for all...
- ...open, and interoperable datasets that increase the global research value of Biosphere 2.Ensure compliance with university, state, and federal requirements, risk management best practices, and environmental and cultural stewardship expectations associated with operating...Full timeTemporary workWork at officeRelocation
- ...plansCollaborate with internal consultants, developers, and project managers to deliver high‑quality outcomesMentor junior team members and... ...with construction modules such as project accounting, compliance, and field serviceBackground in process improvement, change management...Full time
$500 per month
...and Capabilities organization is seeking a Director of Capture Management to lead strategic competitive and strategic, complex sole... ...qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era...Temporary workWork experience placementWork at officeLocal areaRemote workRelocation packageFlexible hours- ...use of medications across the organization. This role involves managing daily pharmacy operations, overseeing clinical pharmacy... ...enhance patient care. The Director also focuses on regulatory compliance, quality improvement, and staff development.Essential FunctionsOversees...Relocation package
$131.3k - $237.35k
...program as needed to ensure consistency, interoperability, and compliance across multiple task orders.Serve as the principal systems... ...adoption, and data flow optimization.Collaborate with Product Managers, Release Train Engineers (RTEs), and cross-functional scrum teams...Full timeContract work- ...GSK#SeabiscuitSkillsDigital Fluency, Enterprise Thinking, External Stakeholder Management, High Impact Communication, Patient JourneyPlease visit GSK US... ...of applicable transfers of value is necessary to ensure GSK’s compliance to all federal and state US Transparency requirements. For...Full timeLocal area
$107.5k - $204.5k
...problems that create a safer, more secure world.The Raytheon Quality Management System (QMS) is a collection of business processes focused on... ...Will Do:Oversee, conduct, and plan internal QMS audits for compliance to the AS9100 series of standards in support of the Raytheon...Temporary workWork experience placementWork at officeRemote workFlexible hours$36.19 per hour
Asset Protection & Security Services, a 30-year company, with 24 years of those years specializing in detention and transportation, is looking for people to be part of our team. Position: Armed Transportation Officers Duties: transporting, guarding, and escorting detainees...- ...collaboration with the Chief Financial Officer, the Chief Budget & Fiscal Management Officer, the Chief Human Resources Officer (CHRO), the Provost... ...Availability of the Annual Security and Fire Safety ReportIn compliance with the Jeanne Clery Campus Safety Act (Clery Act), each year...Full timeWork experience placementWork at officeRelocation
- ...Job Title Chief of Police Job Description Major duties include, but are not limited to: Directs compliance and risk management activities, ensuring adherence to VA directives, and applicable federal, state, and local laws Oversees systemic compliance...Permanent employmentLocal areaRelocation packageMonday to Friday
$36.19 per hour
Duties Transporting, guarding, and escorting detainees. Benefits Paid vacation, sick leave, holidays. Rate $36.19 includes Health and Welfare Requirements US citizen, 21 years of age. 3 years’ combined experience with either law enforcement, military, or corrections. Pass...- ...executive leadership and strategic oversight of law enforcement operations, physical security, crisis intervention programs, and compliance activities across a multi-facility catchment area. Ensures integrated, Veteran-centric policing; adherence to federal, state, and...Local area
- ...Well-established organization providing youth development & leadership programs Industry Non-Profit Organization Management Type Non Profit Founded 1957 Employees 11-50 Specialties youth development charitable organization...Summer work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to ISMS Compliance Manager. Be the first to apply!
- housing compliance Tucson, AZ
- finance compliance Tucson, AZ
- environmental compliance Tucson, AZ
- regulatory compliance analyst Tucson, AZ
- customs compliance Tucson, AZ
- regulatory compliance specialist Tucson, AZ
- vendor compliance Tucson, AZ
- compliance Tucson, AZ
- compliance paralegal Tucson, AZ
- corporate compliance Tucson, AZ

