IT GRC Specialist

NovAtel Inc.

Tucson (AZ)

Hybrid

USD 95,000 - 140,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Hexagon Autonomous Solutions in Tucson, AZ is seeking an IT GRC Specialist to join our Hybrid team. You will support governance, risk, and compliance, ensuring IT systems align with regulatory requirements and internal policies while strengthening security and integrity.

You will lead security control implementations (ISO 27001, NIST, CMMC), coordinate internal and external audits, perform gap assessments, develop policies, and manage GRC platforms.

Qualifications

  • Bachelor’s degree in CS, CE, MIS, IT, or related field; equivalent combos accepted.
  • 10+ years in large, complex IT environments.
  • Knowledge of ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, GDPR.
  • Experience with cybersecurity, networks, cloud, and enterprise platforms.
  • Proven governance, risk management, and compliance experience.
  • Strong communication and cross-functional collaboration.

Responsibilities

  • Implement and maintain security controls per ISO 27001, COBIT, SOX, and NIST.
  • Review policies and coordinate internal/external IT audits.
  • Perform gap assessments against standards and regulatory requirements.
  • Report on compliance health, risk status, and governance.
  • Administer and enhance GRC platforms and governance processes.
  • Serve as primary contact for IT compliance and audit activities.
  • Develop and maintain IT policies, standards, procedures.
  • Lead IT risk assessment activities and risk management initiatives.
  • Perform risk assessments, control testing, and compliance evaluations.
  • Support third-party risk management and vendor reviews.
  • Develop security awareness training programs.
  • Collect evidence for audits, investigations, and inquiries.
  • Assist with customer security/compliance questionnaires.

Skills

IT governance
Risk management
Compliance frameworks
InfoSec controls
Audits coordination
Policy development
Security training
Cross-functional collaboration
Communication skills

Education

Bachelor’s degree in Computer Science, Computer Engineering, MIS, Information Technology, or related field

Tools

GRC platforms
Audit management tools
Compliance automation solutions

Job description

Overview

Hexagon’s Autonomous Solutions division is looking for an IT GRC Specialist to join our team in Tucson, AZ. Reporting to the appropriate IT leadership team, this role will support Hexagon Autonomous Solutions’ governance, risk, and compliance capability by ensuring IT systems, controls, and processes align with regulatory requirements, internal policies, and business-adopted standards while helping strengthen the security, integrity, and compliance posture of the organization.

The Location:This position is based in Tucson, AZ in a hybrid capacity.

The Company: Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications.

Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous, ensuring a scalable, sustainable future.

Responsibilities

AsIT GRC Specialistyou will be responsible for these activities:

  • Support the implementation and maintenance of security controls aligned with industry-standard frameworks including ISO 27001, COBIT, SOX, and NIST.
  • Conduct regular reviews of corporate policies and procedures while serving as a key liaison for internal and external IT audits.
  • Perform gap assessments against business-adopted standards, regulatory requirements, and compliance frameworks while supporting remediation planning and execution.
  • Establish and maintain reporting on compliance health, risk status, and governance activities for assigned projects and initiatives.
  • Administer and enhance GRC platforms and associated IT governance processes.
  • Serve as the primary point of contact for IT compliance, governance, and audit-related activities.
  • Develop and maintain IT policies, standards, procedures, and process documentation.
  • Lead IT risk assessment activities and support broader information security risk management initiatives.
  • Perform risk assessments, control effectiveness testing, and compliance evaluations.
  • Support third-party risk management activities through risk assessments and vendor review processes.
  • Develop and maintain security awareness training programs for new employees and annual compliance training initiatives.
  • Collect, evaluate, and organize evidence supporting audits, investigations, customer requests, and compliance inquiries.
  • Assist with the completion of customer security and compliance questionnaires.
Qualifications

Must Have:

  • Bachelor’s degree in Computer Science, Computer Engineering, Management Information Systems, Information Technology, or a related field. Equivalent combinations of education, certifications, and experience will be considered.
  • 10+ years of experience working within large, complex IT environments.
  • Knowledge of information security standards and compliance requirements including ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, and GDPR.
  • Experience with IT and information security technologies and controls including cybersecurity, networks, infrastructure, applications, cloud services, and enterprise platforms.
  • Proven experience in IT governance, risk management, and compliance.
  • Strong communication and interpersonal skills with the ability to work effectively with cross-functional stakeholders.

Nice To Have:

  • Professional certifications such as CISSP, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or similar.
  • Experience supporting global manufacturing, industrial technology, or multinational organizations.
  • Experience with GRC platforms, audit management tools, and compliance automation solutions.

Key Success Factors:

  • Strong understanding of governance, risk, compliance, and information security principles.
  • Ability to build trusted relationships across IT, Information Security, Legal, Finance, Procurement, and business teams.
  • Strong analytical skills with the ability to identify risks and develop practical remediation strategies.
  • Excellent organizational skills with the ability to manage multiple audits, assessments, and compliance initiatives simultaneously.
  • Commitment to continuous improvement and operational excellence.
  • Ability to communicate complex compliance and risk concepts clearly to both technical and non-technical audiences.

At Hexagon, we are committed to a diverse and inclusive work environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT GRC Specialist
IT GRC Specialist

Hexagon Autonomous Solutions • Tucson (AZ)

Hybrid
USD 110,000 - 170,000
IT GRC & Compliance Lead (Hybrid, Tucson)
IT GRC & Compliance Lead (Hybrid, Tucson)

Hexagon Autonomous Solutions • Tucson (AZ)

Hybrid
USD 110,000 - 170,000
IT GRC Specialist – Hybrid, Tucson
IT GRC Specialist – Hybrid, Tucson

NovAtel Inc. • Tucson (AZ)

Hybrid
USD 95,000 - 140,000
GRC Cybersecurity Specialist
GRC Cybersecurity Specialist

We Place People Executive Search Firm • Austin (TX)

On-site
USD 110,000 - 140,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Austin (TX)

On-site
USD 80,000 - 100,000
Information Technology Governance Manager
Information Technology Governance Manager

Signet Jewelers • United States

Hybrid
USD 140,000 - 170,000
401(k) matching
GRC Analyst
GRC Analyst

Recru • Houston (TX)

Hybrid
USD 90,000 - 120,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville LLC • Fountain Inn (SC)

On-site
USD 100,000 - 130,000