Hexagon AB logo
Hexagon ABPosted 1 week ago

IT GRC Specialist

HybridTucson, Arizona, United States

Full TimeBachelors DegreeLarge

Job Summary

Support the implementation and maintenance of security controls aligned with ISO 27001, COBIT, SOX, and NIST frameworks. Conduct regular reviews of corporate policies, perform gap assessments against regulatory requirements, and lead IT risk assessment activities. Administer GRC platforms, establish compliance reporting, and serve as the primary contact for internal and external IT audits. Develop IT policies, standards, and security awareness training programs while managing third-party risk assessments and vendor reviews. Collect evidence for audits and assist with customer security questionnaires. This role requires a hybrid schedule in Tucson, AZ, and reports to IT leadership.

Required Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, Management Information Systems, Information Technology, or a related field
  • 10+ years of experience working within large, complex IT environments
  • Knowledge of information security standards and compliance requirements including ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, and GDPR
  • Experience with IT and information security technologies and controls including cybersecurity, networks, infrastructure, applications, cloud services, and enterprise platforms
  • Proven experience in IT governance, risk management, and compliance
  • Strong communication and interpersonal skills with the ability to work effectively with cross-functional stakeholders
  • Bachelor's degree in Computer Science, Computer Engineering, Management Information Systems, Information Technology, or a related field
  • 10+ years of experience working within large, complex IT environments
  • Knowledge of information security standards and compliance requirements including ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, and GDPR
  • Experience with IT and information security technologies and controls including cybersecurity, networks, infrastructure, applications, cloud services, and enterprise platforms
  • Proven experience in IT governance, risk management, and compliance
  • Strong communication and interpersonal skills with the ability to work effectively with cross-functional stakeholders

Desired Qualifications

  • Professional certifications such as CISSP, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or similar
  • Experience supporting global manufacturing, industrial technology, or multinational organizations
  • Experience with GRC platforms, audit management tools, and compliance automation solutions
  • Strong understanding of governance, risk, compliance, and information security principles
  • Ability to build trusted relationships across IT, Information Security, Legal, Finance, Procurement, and business teams
  • Strong analytical skills with the ability to identify risks and develop practical remediation strategies
  • Excellent organizational skills with the ability to manage multiple audits, assessments, and compliance initiatives simultaneously
  • Commitment to continuous improvement and operational excellence
  • Ability to communicate complex compliance and risk concepts clearly to both technical and non-technical audiences

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce