Velosity is searching for a Senior Security and Compliance Analyst to support our manufacturing facility in Brooklyn Park, MN or Forest Lake, MN. A Senior Security and Compliance Analyst is responsible for Velosity's cybersecurity operations, regulated information protection practices, and audit readiness across the enterprise. This role helps protect information systems, manufacturing technology environments, cloud platforms, endpoints, identity systems, and controlled data while supporting business growth in defense, aerospace, and medical device manufacturing. The typical pay range for this role: $96,000 - $145,000. This role is also eligible for our 5% quarterly bonus target. This pay range reflects the base hourly rate or annual salary for positions within this job grade, based on our market-based pay structures. Actual compensation will depend on factors such as skills, relevant experience, education, internal equity, business needs, and local market conditions. While the full range is shared for transparency, offers are rarely made at the minimum or maximum of the range. This position includes a comprehensive benefits package that includes:
- Insurance: Medical, dental, vision, life and disability plans.
- Other Benefits Include: 401(k) with company match, PTO, holidays, and paid parental leave.
This is an on-site position. Who is Velosity? Velosity is not your typical manufacturing company. Founded in 1972, we are a state-of-the-art, custom contract manufacturer and injection molder providing creative solutions to our customers' unique manufacturing challenges. At Velosity, our culture & values are our competitive advantage. Engrained in everything we do are our values of Collaboration, Results-Driven, Continuous Improvement, Integrity, and Customer Satisfaction. Sound like you? Apply to join our team today. What You'll Love about Velosity:
- Excellent benefits package including medical, dental, life insurance, short term and long term disability, flex spending, 401k match, and MORE!
- Generous PTO offerings & 9 paid holidays annually
- Clean, friendly, and air-conditioned work environment
- Great opportunities for growth & advancement
- Quarterly bonus opportunity
- A family centric environment that hires and develops talent based on our values
- Casual Dress Code
Essential Duties:
- Lead security monitoring, alert triage, threat detection, incident response, containment, remediation, and post-incident review activities.
- Support Microsoft Defender MDR/XDR, SOC escalations, endpoint protection, email security, identity protection, logging, and related security tools.
- Monitor enterprise systems for indicators of compromise, unauthorized activity, privileged access misuse, and security control failures.
- Manage vulnerability assessments, remediation tracking, risk reporting, exception documentation, and follow-up with system owners.
- Support security impact reviews for new systems, vendors, applications, infrastructure changes, and business technology projects.
- Recommend and help sustain technical, procedural, and administrative controls based on business risk, customer requirements, and cybersecurity best practices.
- Support cybersecurity controls required for CMMC Level 2, NIST SP 800-171, DFARS cybersecurity expectations, and customer security requirements.
- Maintain or support SSPs, POA&Ms, risk registers, control narratives, assessment artifacts, evidence repositories, and audit-ready documentation.
- Prepare evidence and support internal reviews, customer assessments, regulatory audits, CMMC readiness activities, and external assessor interviews.
- Support protection of CUI, FCI, ITAR/EAR-controlled technical data, defense customer information, and other sensitive business information.
- Help ensure appropriate access controls, logging, monitoring, user reviews, secure collaboration, and data handling practices are followed.
- Partner with Quality, Engineering, Operations, HR, Supply Chain, Defense, and other stakeholders to support controlled information processes, investigations, escalations, and corrective actions.
- Develop, maintain, and improve security policies, procedures, standards, reports, and operational documentation.
- Support company-wide and role-based security awareness training related to cybersecurity, CUI handling, incident reporting, phishing, and controlled information protection.
- Provide practical cybersecurity guidance to employees, IT team members, project teams, and business leaders while staying current with applicable threats, technologies, regulations, and best practices.
Qualifications:
- One or more industry-recognized cybersecurity certifications preferred, such as CISSP, CISM, CRISC, CCSP, Security+, CySA+, GSEC, or equivalent experience.
- Experience supporting one or more regulated cybersecurity or quality frameworks preferred, such as CMMC Level 2, NIST SP 800-171, DFARS cybersecurity requirements, ITAR/EAR, ISO 27001, ISO 13485, AS9100, or similar compliance frameworks.
- Experience supporting CMMC Level 2, NIST SP 800-171 assessments, C3PAO audits, or defense contractor cybersecurity programs preferred. CMMC Registered Practitioner (RP), Registered Practitioner Advanced (RPA), Certified Assessor (CCA), or similar credentials are a plus.
- 4-7 years of progressive cybersecurity, information security, security operations, or security compliance experience. Equivalent combinations of hands-on cybersecurity operations, regulated industry experience, audit readiness, and compliance program ownership may be considered.
- Experience supporting cybersecurity and compliance programs within regulated manufacturing, defense, aerospace, medical device, government contractor, or similarly controlled environment preferred.
- Experience with secure CUI collaboration platforms and practices preferred, including Exostar Managed on Microsoft 365 or similar controlled collaboration environments.
- Practical experience with CMMC Level 2, NIST SP 800-171, DFARS cybersecurity requirements, CUI/FCI protection, SSPs, POA&Ms, control evidence, and audit readiness.
- Experience with ITAR/EAR-controlled technical data, export-controlled environments, secure collaboration, and access control concepts preferred.
- Hands-on experience with security monitoring, incident response, vulnerability management, endpoint protection, identity and access management, logging, and security reporting.
- Experience with Microsoft security technologies such as Microsoft Defender, Microsoft 365 security, Entra ID, Intune, Purview, Sentinel, or related SIEM/XDR tooling preferred.
- Knowledge of security frameworks and best practices such as NIST Cybersecurity Framework, NIST SP 800-171, CMMC, ISO 27001, CIS Controls, and Zero Trust principles.
- Ability to analyze security events, identify root causes, assess business risk, prioritize remediation, and communicate recommendations clearly.
- Strong written and verbal communication skills, including the ability to explain cybersecurity and compliance concepts to non-technical stakeholders.
- Ability to create clear, audit-ready documentation, reports, procedures, evidence summaries, and executive-level status updates.
- Ability to work independently, collaborate across departments, manage multiple priorities, and sustain change in a fast-paced regulated environment.
- Strong problem-solving, troubleshooting, follow-through, and continuous improvement skills.
Physical Requirements
- Walking is required within the facility. Sitting, standing, turning the head and torso, reaching, grasping, bending and flexing the arms, legs, wrists, and fingers are physical requirements. Must have correctable eyesight and good depth perception. Must be able to walk and sit.
- Must be able to prioritize multiple tasks and complete them in a timely manner; ability to make decisions with limited information, ability to lead, implement, and sustain change.
- Must be able to travel to the different Velosity locations as needed.
Work Environment Requirements
- Manufacturing environment, exposure to heat, noise, dust, dirt, oil and water
Licensing/Registration/Certification:
- Valid identification and the ability to work legally in the United States.
We are proud to be an Equal Opportunity Employer, including protected veterans and individuals with disabilities. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, marital status, familial status, disability status, status with regard to public assistance, membership or activity in a local commission, or any other status protected by applicable law. We maintain a drug-free workplace and perform pre-employment substance abuse testing. Velosity is an E-Verify employer. Velosity maintains ITAR-compliant operations in our facilities. Due to ITAR regulations, this role is only open to U.S. Citizens, lawful permanent residents (green card holders) or foreign nationals granted refugee or asylee status. Individuals with temporary visas (e.g. E, F-1, H-1, H-2, L, B, J, TN or OPT) are not eligible for hire in this role.
Monday- Friday, flexible with hours.
|