ISMS Compliance Manager

Hexagon Mining

Tucson (AZ)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hexagon Mining in Tucson is seeking a Compliance Manager to oversee the Information Security Management System (ISMS) and manage ISO 27001 certification. You will need to have 5+ years of experience in compliance and audit management, and strong project management skills.

The role requires excellent communication abilities to engage various stakeholders and ensure effective compliance governance.

Qualifications

  • 5+ years in information security compliance or audit management.
  • Experience managing an ISO 27001 ISMS certification cycle.
  • Capability to manage projects and compliance documentation.

Responsibilities

  • Own and improve ISO 27001-aligned ISMS.
  • Conduct and manage internal and external audits.
  • Engage with stakeholders across various departments.

Skills

Information Security Compliance
GRC Management
ISO 27001 Management
Cross-Functional Collaboration
Risk Assessment

Education

Bachelor’s degree in Information Security or related field

Tools

ISO 27001 Standards
Compliance Tools

Job description

The Company

Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications. Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous — ensuring a scalable, sustainable future. Hexagon’s Mining division solves surface and underground mine challenges with proven technologies for planning, operations, and safety. Hexagon (Nasdaq Stockholm: HEXA B) has approximately 24,000 employees in 50 countries and net sales of approximately 5.5bn USD. Learn more at hexagon.com.

The Role

The Compliance Manager is accountable for the design, operation, and continuous improvement of the organisation’s Information Security Management System (ISMS) and its associated certification programme. This role is not a technical security engineering position. Instead, it demands a highly organised, process-oriented compliance professional who can orchestrate cross-functional teams, manage external auditors, close control gaps, and ensure that the control environment remains audit-ready at all times. The Compliance Manager serves as the primary interface between the organisation’s day-to-day operations and its ISO 27001 certification obligations.

Major Areas Of Responsibility
  • ISMS Program Ownership
    • Own, maintain, and continuously improve the ISO 27001‑aligned ISMS, including its scope, Statement of Applicability, risk treatment plan, and supporting documentation.
    • Serve as the internal subject‑matter authority for ISO/IEC 27001 requirements and supplementary standards.
    • Maintain the certification roadmap and annual audit calendar, coordinating with the certification body and internal audit.
    • Ensure alignment with strategy, business changes, regulatory updates, and threat shifts.
  • Control Framework Management
    • Maintain an authoritative ISO 27001 control framework, mapping Annex A controls to business processes, asset owners, and accountable teams.
    • Conduct and manage periodic control effectiveness assessments.
    • Drive gap remediation: identify deficiencies, assign owners, set target dates, track progress, and escalate as needed.
    • Ensure evidence artefacts are complete, current, and retained per the ISMS framework.
    • Manage policy and procedure lifecycle: drafting, review, approval, version control, and annual attestation.
  • Audit Management & Readiness
    • Scope, plan, and manage internal and external ISO 27001 audits.
    • Serve as liaison with the certification body: coordinate logistics, manage schedule, prepare meetings, facilitate auditor access.
    • Proactively assess control adequacy before audits.
    • Manage audit findings: root‑cause analysis, corrective actions, evidence of closure, follow‑up.
    • Maintain perpetual audit‑readiness posture.
  • Risk Management Integration
    • Facilitate risk assessment and treatment, identifying, evaluating, and treating information security risks.
    • Maintain the risk register and treatment plan, tracking decisions and progress.
    • Ensure risk outputs reflected in the SoA and control framework, escalating significant residual risks.
  • Cross‑Functional Stakeholder Engagement
    • Identify and engage owners across product, engineering, infrastructure, IT, legal, HR, and operations to obtain evidence, close gaps, and ensure control sustainability.
    • Facilitate Management Review meetings, prepare agenda, risk summaries, audit results, and improvement recommendations.
    • Develop stakeholder engagement model clarifying ISMS responsibilities.
    • Act as advisor to leadership on compliance posture, certification status, and risks.
    • Support teams on information security questions and customer security questionnaires.
    • Manage and support incident response efforts.
  • Compliance Programme Governance
    • Maintain a compliance calendar covering ISMS obligations.
    • Produce regular compliance status reports and dashboards.
    • Contribute to supplier assurance activities by assessing third‑party compliance requirements.
Key Stakeholders
  • VP of Information Technology and Data
  • Group Privacy and Information Security Officer
  • Group Governance, Risk, and Compliance
  • SVP of Product
  • SVP of Engineering
  • Engineering Management
  • Legal and Compliance
Knowledge And Experience - Required
  • Bachelor’s degree in Information Security, Computer Science, Business Administration, or related field; or equivalent experience.
  • 5+ years in information security compliance, GRC, or audit management.
  • Hands‑on experience managing an ISO 27001 ISMS through a full certification or recertification cycle.
  • Ability to manage cross‑functional stakeholders without direct authority.
  • Experience maintaining control frameworks, risk registers, and ISMS documentation libraries.
  • Track record of writing and managing information security policies and procedures.
Knowledge And Experience - Desired
  • Deep knowledge of ISO/IEC 27001:2022 and supporting guidance.
  • Strong understanding of information security risk assessment methodologies.
  • Ability to interpret compliance and audit requirements without technical security practice.
  • Excellent written and verbal communication skills.
  • Strong project and programme management skills.
  • CISM or CRISC certification.
  • Knowledge of complementary frameworks such as SOC 2, NIST CSF, CIS Controls, GDPR, or CCPA.
  • Prior experience in a regulated industry where certification drives obligations.
Travel
  • Travel is expected to complete job function, including potential significant periods related to audit readiness and execution. Overall travel is not to exceed 50% of time.

Hexagon is an Equal Opportunity Employer. We prohibit discrimination against any job applicant based on protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISMS Compliance Manager
ISMS Compliance Manager

Hexagon Mining, Inc. • Tucson (AZ)

On-site
USD 80,000 - 100,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Information Security Program Lead
Information Security Program Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
ISMS Compliance Lead — ISO 27001 & Audit Readiness
ISMS Compliance Lead — ISO 27001 & Audit Readiness

Hexagon Mining, Inc. • Tucson (AZ)

On-site
USD 80,000 - 100,000
Information Security Compliance Specialist
Information Security Compliance Specialist

Securiport • Reston (VA)

On-site
USD 75,000 - 95,000
Information Security Compliance Specialist
Information Security Compliance Specialist

Securiport LLC • Reston (VA)

On-site
USD 70,000 - 95,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Pennsylvania

On-site
USD 120,000 - 155,000
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

Jobtailor • New Haven (CT)

On-site
USD 120,000 - 160,000