Talent.com
Hexagon Mining, Inc.
ISMS Compliance ManagerHexagon Mining, Inc. • Tucson, AZ, US
ISMS Compliance Manager

ISMS Compliance Manager

Hexagon Mining, Inc. • Tucson, AZ, US
30+ days ago
Job type
  • Full-time
Job description

The Company: Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications. Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous - ensuring a scalable, sustainable future. Hexagon's Mining division solves surface and underground mine challenges with proven technologies for planning, operations, and safety. Hexagon (Nasdaq Stockholm: HEXA B) has approximately 24,000 employees in 50 countries and net sales of approximately 5.5bn USD. Learn more at hexagon.com and follow us @HexagonAB. The Role: The Compliance Manager is accountable for the design, operation, and continuous improvement of the organisation's Information Security Management System (ISMS) and its associated certification programme. This role is not a technical security engineering position. Instead, it demands a highly organised, process-oriented compliance professional who can orchestrate cross-functional teams, manage external auditors, close control gaps, and ensure that the control environment remains audit-ready at all times. The Compliance Manager serves as the primary interface between the organisation's day-to-day operations and its ISO 27001 certification obligations. Major Areas of Responsibility: * ISMS Program Ownership * Own, maintain, and continuously improve the ISO 27001-aligned Information Security Management System (ISMS), including its scope, Statement of Applicability (SoA), risk treatment plan, and all supporting documentation. * Serve as the internal subject-matter authority for ISO/IEC 27001 standard requirements and, where applicable, supplementary standards (ISO 27002, 27005, 27017, 27018, SOC 2 overlap). * Maintain the organisation's certification roadmap and annual audit calendar, coordinating with the external certification body and any internal audit function. * Ensure the ISMS programme remains aligned with organisational strategy, evolving business requirements, regulatory changes, and threat landscape shifts. * Control Framework Management * Maintain a complete, current, and authoritative ISO 27001 control framework, mapping Annex A controls (and relevant supplementary controls) to business processes, asset owners, and accountable teams. * Conduct and manage periodic control effectiveness assessments to verify that controls are designed adequately and are operating as intended. * Drive gap remediation: identify control deficiencies, assign remediation owners, set target dates, track progress to closure, and escalate where timelines are at risk. * Ensure evidence artefacts (policies, procedures, records, logs, test results) are complete, current, well-organised, and retained in accordance with the ISMS evidence management framework. * Manage policy and procedure lifecycle-drafting, review, approval, version control, and annual attestation-in collaboration with policy owners. * Audit Management & Readiness * Scope, plan, and manage both internal and external ISO 27001 audits (Stage 1, Stage 2 certification, and annual surveillance/recertification audits). * Serve as the primary liaison with the external certification body: coordinate logistics, manage the audit schedule, prepare opening and closing meetings, and facilitate auditor access to systems, evidence, and personnel. * Proactively assess control adequacy before external audits. * Manage all audit findings (minor nonconformities, major nonconformities, and observations): ensure timely root cause analysis, corrective action plans, evidence of closure, and follow-up verification. * Maintain a perpetual audit-readiness posture, ensuring the organisation can demonstrate an effective ISMS at any point during the certification cycle-not only at audit time. * Risk Management Integration * Facilitate the information security risk assessment and risk treatment process working with technical and business stakeholders to identify, evaluate, and treat information security risks. * Maintain the risk register and risk treatment plan, tracking risk acceptance decisions, treatment progress, and residual risk posture. * Ensure risk assessment outputs are reflected in the SoA and control framework, and that significant residual risks are escalated appropriately to leadership. * Cross-Functional Stakeholder Engagement * Identify and engage the correct accountable owners across product, engineering, infrastructure, IT, legal, HR, and business operations to obtain evidence, close gaps, and ensure control sustainability. * Facilitate Management Review meetings as required by the standard, preparing agenda materials, risk summaries, audit result summaries, and improvement recommendations. * Develop and maintain a stakeholder engagement model that clarifies each team's ISMS responsibilities without requiring them to become compliance specialists. * Act as a trusted advisor to leadership on the organisation's compliance posture, certification status, and material risks. * Support teams as they address questions regarding information security management, including responses to customer security questionnaires * Manage and support incident response efforts, including containment, investigation, and recovery. * Compliance Programme Governance * Maintain a compliance calendar covering ISMS obligations-control reviews, policy attestations, risk assessments, internal audits, and external audit milestones. * Produce regular compliance status reports and management dashboards that accurately reflect the state of the control environment, open gaps, and remediation progress. * Contribute to supplier assurance activities by assessing third-party compliance requirements relevant to the ISMS scope. Key Stakeholders: This role will be successful if able to build relationships and work directly with the following stakeholders: * VP of Information Technology and Data * Group Privacy and Information Security Officer * Group Governance, Risk, and Compliance * SVP of Product * SVP of Engineering * Engineering Management * Legal and Compliance Knowledge and Experience - Required: * Bachelor's degree in Information Security, Computer Science, Business Administration, or a related field; or equivalent professional experience. * 5+ years of experience in information security compliance, GRC (Governance, Risk, and Compliance), or audit management roles. * Demonstrated, hands-on experience managing an ISO 27001 ISMS through at least one full certification or recertification audit cycle-including scoping, internal audits, external audit management, and nonconformity remediation. * Proven ability to manage cross-functional stakeholders without direct authority-influencing product, engineering, HR, legal, and operations teams to meet compliance obligations. * Experience maintaining control frameworks, risk registers, and ISMS documentation libraries. * Track record of writing and managing information security policies and procedures. Knowledge and Experience - Desired: * Deep knowledge of the ISO/IEC 27001:2022 standard, Annex A controls, and supporting guidance in ISO/IEC 27002:2022. * Strong understanding of information security risk assessment methodologies. * Ability to read, interpret, and apply compliance and audit requirements without needing to be a hands-on technical security practitioner. * Excellent written and verbal communication skills; able to translate complex compliance requirements into clear, actionable guidance for non-security audiences. * Strong project and programme management skills: ability to manage multiple workstreams, deadlines, and stakeholders simultaneously. * CISM (Certified Information Security Manager) or CRISC (Certified in Risk and Information Systems Control). * Working knowledge of complementary frameworks such as SOC 2 (Type I/II), NIST CSF, CIS Controls, GDPR, or CCPA-particularly where they overlap with or supplement the ISO 27001 control environment. * Prior experience in a regulated industry (financial services, healthcare, or public sector) where certification drives contractual or regulatory obligations. Travel: * Travel is expected to complete job function - including potential significant periods of travel related to coordination of audit readiness and execution. Overall travel is not to exceed 50% of time. Hexagon is an Equal Opportunity Employer. We prohibit discrimination against any job applicant based on protected characteristics.

Create a job alert for this search

ISMS Compliance Manager • Tucson, AZ, US

Similar jobs

Clinical Contracts Manager II

Tranzeal IncTucson, AZ, United States
Full-time

Assist in overcoming technical hurdles during contract scoping, negotiations and execution.Develop compliance measures for contract organization within the Salesforce environment.Develop and improv... Show more

 • Promoted

Manager, Contracts (Onsite)

RaytheonTucson, AZ, United States
Full-time

At Raytheon, the foundation of everything we do is rooted in our values and a higher calling to help our nation and allies defend freedoms and deter aggression.We bring the strength of more than 10... Show more

 • Promoted

US_Contracts Manager III_CO

HireTalentTucson, AZ, United States
Full-time

Assist in overcoming technical hurdles during contract scoping, negotiations and execution.Develop compliance measures for contract organization within the Salesforce environment.Develop and improv... Show more

 • Promoted

Raytheon SkillBridge AMRAAM Supplier Obsolescence Manager

RaytheonTucson, AZ, United States
Full-time

At Raytheon, the foundation of everything we do is rooted in our values and a higher calling to help our nation and allies defend freedoms and deter aggression.We bring the strength of more than 1... Show more

 • Promoted

ISMS Compliance Manager

Hexagon ABTucson, AZ, United States
Full-time

The Compliance Manager is accountable for the design, operation, and continuous improvement of the organisation's Information Security Management System (ISMS) and its associated certification prog... Show more

 • Promoted

OSC Project Manager

RaytheonTucson, AZ, United States
Full-time

Tomahawk Equipment Replacement Project Manager.At Raytheon, the foundation of everything we do is rooted in our values and a higher calling to help our nation and allies defend freedoms and deter ... Show more

 • Promoted

Manager, Contracts (Onsite)

RTXTucson, AZ, United States
Full-time

At RTX, the world's largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world's most complex problems.With our three marke... Show more

 • Promoted

Asset Protection/Loss Prevention

Home Depot (Retail)Tucson, AZ, United States
Full-time

Asset Protection/Loss Prevention | Home Depot.The Asset Protection Specialist is primarily responsible for preventing financial loss caused by theft and fraud and supporting safety and environmenta... Show more

 • Promoted

Risk Management Consultant - Manning - Compliance and Innovation

El Rio Community Health CenterTucson, AZ, United States
Full-time

Schedule: Monday - Friday, 8am - 5pm.The Risk Management Consultant, is an integral part of the Compliance team and will work with the El Rio Health staff that provide comprehensive healthcare serv... Show more

 • Promoted

Performance Enablement Lead - MTS

Komatsu North AmericaTucson, AZ, United States
Full-time

Performance Enablement Lead - MTS.Shape the Future of Mining with Komatsu Mining Technology Solutions: At Komatsu Mining Technology Solutions, we're not just talking about progress and innovation -... Show more

 • Promoted • New!

Engagement Manager(XIN001_J54Q)

XinnovitTucson, AZ, United States
Full-time

Xinnovit is a global leader in technology consulting, outsourcing, and workforce management solutions.Our mission is to enable our clients to become more agile and competitive with the help of inno... Show more

 • Promoted

Integrated Project Manager (DOD Clearable)

AVTC GroupTucson, AZ, United States
Full-time

All Qualified candidates will be responded to in 24 hours or less.Ability to obtain and maintain a U.Employment type: Full Time W-2 or Contract.Benefits: including Health, Dental Vision, PTO, Holid... Show more

 • Promoted

NSMS International Programs - Project Mgmt

RaytheonTucson, AZ, United States
Full-time

International Principal Specialist, Project Management.At Raytheon, the foundation of everything we do is rooted in our values and a higher calling to help our nation and allies defend freedoms an... Show more

 • Promoted

Compliance Analyst, FinTech

Launch PotatoTucson, AZ, United States
Full-time

Compliance Analyst, FinTechLaunch Potato is a profitable digital media company that reaches over 30Mmonthly visitors through brands such as FinanceBuzz, All About Cookies, and OnlyInYourState.As Th... Show more

 • Promoted

Internal Manager in Training

Circle KTucson, AZ, United States
Full-time

Grand Canyon BU - Region 05 - Market 08: 3102 E Benson Hwy, Tucson, Arizona 85706.Leadership and Management: Directly supervises the activities of 2 or more full-time employees which may include As... Show more

 • Promoted

Lean Transformation Focal (Onsite) IV

RaytheonTucson, AZ, United States
Full-time

The foundation of everything we do is rooted in our values and a higher calling to help our nation and allies defend freedoms and deter aggression.We bring the strength of more than 100 years of e... Show more

 • Promoted

Lean Transformation Focal (Onsite) IV

RTXTucson, AZ, United States
Full-time

Raytheon Lean Transformation Focal.Person, or Immigration Status Requirements: The ability to obtain and maintain a U.Security Clearance Type: DoD Clearance: Secret.Security Clearance Status: Activ... Show more

 • Promoted

Contracts Manager III

Tranzeal IncTucson, AZ, United States
Full-time

Assist in overcoming technical hurdles during contract scoping, negotiations and execution.Develop compliance measures for contract organization within the Salesforce environment.Develop and improv... Show more

 • Promoted

2701796- Internal Manager in Training

Circle KTucson, AZ, United States
Full-time

Flexible availability required.The minimum qualifications for a Store Manager are:.High School diploma or GED preferred.Experience in retail sales preferred.Experience to perform the essential duti... Show more

 • Promoted

NSMS Supply Chain Lead

RaytheonTucson, AZ, United States
Full-time

Job Opportunity: Associate Director, Supply Chain Management.At Raytheon, the foundation of everything we do is rooted in our values and a higher calling to help our nation and allies defend freed... Show more