IT GRC Specialist

Hexagon
  • Tucson, Arizona
  • Full-time
17 days ago

Job Description

Overview:

Hexagon’s Autonomous Solutions division is looking for an IT GRC Specialist to join our team in Tucson, AZ. Reporting to the appropriate IT leadership team, this role will support Hexagon Autonomous Solutions’ governance, risk, and compliance capability by ensuring IT systems, controls, and processes align with regulatory requirements, internal policies, and business-adopted standards while helping strengthen the security, integrity, and compliance posture of the organization.

The Location: This position is based in Tucson, AZ in a hybrid capacity.

 

The Company: Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications.

Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous, ensuring a scalable, sustainable future.

Responsibilities:

As IT GRC Specialist you will be responsible for these activities:

  • Support the implementation and maintenance of security controls aligned with industry-standard frameworks including ISO 27001, COBIT, SOX, and NIST.
  • Conduct regular reviews of corporate policies and procedures while serving as a key liaison for internal and external IT audits.
  • Perform gap assessments against business-adopted standards, regulatory requirements, and compliance frameworks while supporting remediation planning and execution.
  • Establish and maintain reporting on compliance health, risk status, and governance activities for assigned projects and initiatives.
  • Administer and enhance GRC platforms and associated IT governance processes.
  • Serve as the primary point of contact for IT compliance, governance, and audit-related activities.
  • Develop and maintain IT policies, standards, procedures, and process documentation.
  • Lead IT risk assessment activities and support broader information security risk management initiatives.
  • Perform risk assessments, control effectiveness testing, and compliance evaluations.
  • Support third-party risk management activities through risk assessments and vendor review processes.
  • Develop and maintain security awareness training programs for new employees and annual compliance training initiatives.
  • Collect, evaluate, and organize evidence supporting audits, investigations, customer requests, and compliance inquiries.
  • Assist with the completion of customer security and compliance questionnaires.
Qualifications:

Must Have:

  • Bachelor’s degree in Computer Science, Computer Engineering, Management Information Systems, Information Technology, or a related field. Equivalent combinations of education, certifications, and experience will be considered.
  • 10+ years of experience working within large, complex IT environments.
  • Knowledge of information security standards and compliance requirements including ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, and GDPR.
  • Experience with IT and information security technologies and controls including cybersecurity, networks, infrastructure, applications, cloud services, and enterprise platforms.
  • Proven experience in IT governance, risk management, and compliance.
  • Strong communication and interpersonal skills with the ability to work effectively with cross-functional stakeholders.

Nice To Have:

  • Professional certifications such as CISSP, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or similar.
  • Experience supporting global manufacturing, industrial technology, or multinational organizations.
  • Experience with GRC platforms, audit management tools, and compliance automation solutions.

Key Success Factors:

  • Strong understanding of governance, risk, compliance, and information security principles.
  • Ability to build trusted relationships across IT, Information Security, Legal, Finance, Procurement, and business teams.
  • Strong analytical skills with the ability to identify risks and develop practical remediation strategies.
  • Excellent organizational skills with the ability to manage multiple audits, assessments, and compliance initiatives simultaneously.
  • Commitment to continuous improvement and operational excellence.
  • Ability to communicate complex compliance and risk concepts clearly to both technical and non-technical audiences.

Not sure if you meet all the qualifications for this role? Let us decide! At Hexagon, we are committed to a diverse and inclusive work environment. If you’re excited about the opportunities this role could bring, we encourage you to apply. If you have any questions about the role or our company, please email our team at hrrecruitingteam.ap@hexagon.com and we will be pleased to follow up with you. Please do not send cover letters or resumes to this address.

Numbers & Facts

LocationTucson, Arizona
Job TypeFull-time

Skills

  • Analysis Skillsunmatched
  • Auditingunmatched
  • Automationunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Communication Skillsunmatched
  • Computer Engineeringunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Improvementunmatched
  • Control Objectives for Information and related Technology (COBIT)unmatched
  • Corporate Policiesunmatched
  • Cross-Functionalunmatched
  • Documentationunmatched
  • Ecosystemsunmatched
  • External Auditunmatched
  • Financeunmatched
  • Governmentunmatched
  • ISO (International Organization for Standardization)unmatched
  • IT Governanceunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology/Systems Auditunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Interpersonal Skillsunmatched
  • Legalunmatched
  • Maintain Complianceunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Manufacturingunmatched
  • NIS (Network Information Service)unmatched
  • Operational Improvementunmatched
  • Organizational Skillsunmatched
  • Purchasing/Procurementunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Safety/Work Safetyunmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Security Complianceunmatched
  • Staff Trainingunmatched
  • Strategic Planningunmatched
  • Technical Leadershipunmatched
  • Testingunmatched
  • Training Programunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vendor/Supplier Evaluationunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder