{"id":1146968,"url":"https://alion.io/job/cig-acsg-it-grc-specialist","title":"IT GRC Specialist","company":{"id":1105292,"name":"Canadian Institute of Geomatics","domain":"cig-acsg.ca","url":"https://alion.io/company/cig-acsg","size_band":"501-1000","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"iCIMS","truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"hybrid","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Tucson, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":124000,"max_usd":260000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":240},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"GDPR","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST 800-171","optional":false}],"status":"live","first_seen_at":"2026-09-23T15:42:29Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-24T02:45:37Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Overview\nHexagon’s Autonomous Solutions division is looking for an IT GRC Specialist to join our team in Tucson, AZ. Reporting to the appropriate IT leadership team, this role will support Hexagon Autonomous Solutions’ governance, risk, and compliance capability by ensuring IT systems, controls, and processes align with regulatory requirements, internal policies, and business-adopted standards while helping strengthen the security, integrity, and compliance posture of the organization.\nThe Location: This position is based in Tucson, AZ in a hybrid capacity.\nThe Company: Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications.\nOur technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous, ensuring a scalable, sustainable future.\nResponsibilities\nAs IT GRC Specialist you will be responsible for these activities:\nSupport the implementation and maintenance of security controls aligned with industry-standard frameworks including ISO 27001, COBIT, SOX, and NIST.\nConduct regular reviews of corporate policies and procedures while serving as a key liaison for internal and external IT audits.\nPerform gap assessments against business-adopted standards, regulatory requirements, and compliance frameworks while supporting remediation planning and execution.\nEstablish and maintain reporting on compliance health, risk status, and governance activities for assigned projects and initiatives.\nAdminister and enhance GRC platforms and associated IT governance processes.\nServe as the primary point of contact for IT compliance, governance, and audit-related activities.\nDevelop and maintain IT policies, standards, procedures, and process documentation.\nLead IT risk assessment activities and support broader information security risk management initiatives.\nPerform risk assessments, control effectiveness testing, and compliance evaluations.\nSupport third-party risk management activities through risk assessments and vendor review processes.\nDevelop and maintain security awareness training programs for new employees and annual compliance training initiatives.\nCollect, evaluate, and organize evidence supporting audits, investigations, customer requests, and compliance inquiries.\nAssist with the completion of customer security and compliance questionnaires.\nQualifications\nMust Have:\nBachelor’s degree in Computer Science, Computer Engineering, Management Information Systems, Information Technology, or a related field. Equivalent combinations of education, certifications, and experience will be considered.\n10+ years of experience working within large, complex IT environments.\nKnowledge of information security standards and compliance requirements including ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, and GDPR.\nExperience with IT and information security technologies and controls including cybersecurity, networks, infrastructure, applications, cloud services, and enterprise platforms.\nProven experience in IT governance, risk management, and compliance.\nStrong communication and interpersonal skills with the ability to work effectively with cross-functional stakeholders.\nNice To Have:\nProfessional certifications such as CISSP, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or similar.\nExperience supporting global manufacturing, industrial technology, or multinational organizations.\nExperience with GRC platforms, audit management tools, and compliance automation solutions.\nKey Success Factors:\nStrong understanding of governance, risk, compliance, and information security principles.\nAbility to build trusted relationships across IT, Information Security, Legal, Finance, Procurement, and business teams.\nStrong analytical skills with the ability to identify risks and develop practical remediation strategies.\nExcellent organizational skills with the ability to manage multiple audits, assessments, and compliance initiatives simultaneously.\nCommitment to continuous improvement and operational excellence.\nAbility to communicate complex compliance and risk concepts clearly to both technical and non-technical audiences.\nNot sure if you meet all the qualifications for this role? Let us decide! At Hexagon, we are committed to a diverse and inclusive work environment. If you’re excited about the opportunities this role could bring, we encourage you to apply. If you have any questions about the role or our company, please email our team at  and we will be pleased to follow up with you. Please do not send cover letters or resumes to this address.","description_format":"text","description_chars":4803,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Space & Aerospace","Earth Observation","Navigation & Mapping"],"lifecycle":[{"event":"open","at":"2026-09-23T15:42:29Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":50,"reasons":["conf:2","win:early"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cig-acsg-it-grc-specialist","json_url":"https://alion.io/job/cig-acsg-it-grc-specialist.json","meta":{"generated_at":"2026-09-24T08:47:03Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}