| Location | Minneapolis, Minnesota |
What you’ll do
Niron Magnetics is seeking a Manager, I.T. Security Governance, Risk and Compliance (FSO) to own the security program that protects our data, our systems, and our customers’ controlled information. Reporting to the Sr. Manager of I.T. Infrastructure and Security Operations, you will define the policies, standards, and control requirements under which Niron operates, run our regulatory compliance and audit program, and independently verify that our controls are working.
This is a governance and assurance role, not an operational security role. You will define requirements, document them in an audit-ready form, independently verify control effectiveness, and drive remediation. The I.T. Infrastructure and Security Operations team will administer security tools, triage alerts, patch systems, and perform technical responses. To preserve the credibility of your assessments, you will also have a direct line to the Head of I.T. and the Security Committee.
You will also serve as Niron’s Facility Security Officer (FSO) and Insider Threat Program Senior Official (ITPSO) under 32 CFR Part 117, the NISPOM Rule. Those designations carry their own regulatory duties, described below, and will be Niron’s primary point of contact with the Defense Counterintelligence and Security Agency (DCSA).
Own the Security Policy and Standards Framework
• Develop, publish, and maintain enterprise security policies, standards, and procedures spanning I.T., O.T., cloud, and in conjunction with the Facilities team, physical security.
• Translate framework requirements into control standards and configuration baselines the I.T. Operations team can implement and be measured against.
• Define vulnerability risk ratings and remediation service levels, and verify closure independently rather than accepting self-reported status.
• Own the policy exception and control deviation process, including documented compensating controls, approval, and expiration.
• Maintain the System Security Plan and associated control narratives in a continuously audit-ready state.
Lead Regulatory Compliance and Audit
• Own Niron’s compliance program across NIST SP 800-171, CMMC Level 2, DFARS 252.204-7012, ITAR, EAR, and ISO 27001.
• Maintain the SPRS score and the Plan of Action and Milestones (POA&M), and drive the roadmap to CMMC certification.
• Plan and manage penetration tests, independent security assessments, internal assessments, external audits, and C3PAO engagements, including scoping, evidence collection, remediation tracking, and verified closure.
• Serve as the security subject matter expert for customer security questionnaires, supplier assessments, and contract flow-down requirements.
• Own cyber insurance applications, attestations, and renewal questionnaires.
Own Government Cloud (GCC and GCC High) Compliance
• Own the compliance posture of Niron’s Microsoft 365 Government Community Cloud environment, including GCC High, where controlled unclassified information (CUI) is processed, stored, or transmitted.
• Define and maintain the CUI enclave boundary across Niron’s dual-tenant environment, including approved data locations, classification and labeling requirements, sharing restrictions, external collaboration, guest access, and cross-tenant data flows. Working with the I.T. Operations team, verify that these requirements are enforced in practice.
• Validate that government cloud services in use meet FedRAMP Moderate or High equivalence and DFARS 252.204-7012 requirements, and retain evidence of that validation.
• Own the data spillage response process for controlled information, including detection criteria, containment expectations, sanitization, and reporting obligations.
• Assess proposed cloud services, applications, integrations, and AI capabilities for government-tenant eligibility and controlled-data restrictions before adoption.
Serve as Facility Security Officer (FSO)
• Act as Niron’s primary point of contact with DCSA and the assigned Industrial Security Representative.
• Establish and maintain the facility clearance (FCL), including sponsorship, CAGE code and facility records, Key Management Personnel designations and exclusion resolutions, and foreign ownership, control, or influence (FOCI) reporting.
• Run the personnel security program: clearance sponsorship and submission, continuous vetting enrollment, eligibility and access tracking, SF-312 execution, indoctrination and debriefing, and accurate records in the DCSA systems of record.
• Review each DD Form 254, translate its requirements into facility procedures, and flow security requirements down to subcontractors.
• Govern classified and controlled material handling, including marking, storage, reproduction, transmission, destruction, visit authorizations, and closed area or approved container management where applicable.
• Deliver NISP-required initial briefings, annual refresher briefings, derivative classification training, and foreign travel briefings and debriefings.
• Report adverse information, suspicious contacts, foreign contacts and travel, and security violations within required timeframes, and conduct inquiries into potential loss or compromise.
• Conduct the annual FSO self-inspection using a scope tailored to Niron’s operations and the DCSA security review process, and promptly disclose reportable vulnerabilities.
• Maintain continuous readiness for DCSA security reviews, including current records, available evidence, and documented corrective action status.
• Coordinate with the export control function on ITAR and EAR obligations where they intersect classified work, foreign national access, and technical data handling.
Manage Risk and Third-Party Risk
• Maintain the enterprise security risk register and lead periodic risk assessments covering I.T., O.T., cloud, and physical security in coordination with Facilities.
• Run the third-party and vendor risk program, including security review of new vendors, contract security terms, and periodic reassessment.
• Prepare risk acceptance recommendations, escalate material decisions to the Head of I.T. and the Security Committee, and report security posture, control effectiveness, and risk trends to I.T. leadership, executive leadership, the Security Committee, and the board.
Own the Insider Threat Program
• Maintain the insider threat program plan, self-certification, and required reporting.
• Chair the insider threat working group across Security, I.T., O.T., H.R., Legal, and Engineering, and keep it meeting and producing records rather than existing on paper.
• Define reportable indicators and the monitoring, user activity, and data loss prevention requirements needed to detect insider risk to classified material, CUI, and proprietary process and manufacturing data.
• Review referrals and indicators, decide what warrants inquiry, and direct the Sr. Manager of I.T. Infrastructure and Security Operations on containment, mitigation, and technical response.
• Own insider threat awareness training and maintain a confidential reporting pathway that employees understand and can readily use.
• Coordinate inquiries with H.R., Legal, and outside counsel, preserve evidence, and make required reports to DCSA.
Verify Control Effectiveness
• Design and execute a control testing program that independently confirms controls operate as documented.
• Lead quarterly user access reviews and privileged access certification, and validate joiner, mover, and leaver execution against policy.
• Review configuration baselines, logging coverage, backup restoration evidence, and disaster recovery test results to confirm compliance with stated requirements.
• Define detection use cases and log coverage requirements for the operations team and MDR partner to implement.
• Own the security metrics program: patch compliance, finding aging, phishing performance, training completion, and control test results.
Own the Incident Response and Continuity Programs
• Own the incident response plan, severity definitions, escalation criteria, and communication and notification procedures.
• Plan and facilitate tabletop exercises across I.T., O.T., facilities, and executive stakeholders.
• Lead post-incident reviews and drive corrective actions to completion.
• Advise on regulatory, contractual, and customer breach notification obligations, including DFARS 72-hour reporting.
• Define recovery time and recovery point objectives with the business, and validate that continuity and recovery plans actually meet them.
Lead Security Awareness and Training
• Own the enterprise security awareness program, including annual workforce training, role-based modules, and phishing simulations.
• Deliver targeted training for high-risk roles and personnel handling CUI, export-controlled technical data, or other controlled information, and retain completion records as compliance evidence.
Provide Security Architecture and Project Assurance
• Set security requirements and provide risk-based design guidance for new systems, applications, integrations, and O.T. deployments before implementation.
• Govern O.T. security in partnership with O.T. engineering, including segmentation architecture, remote access standards, and IEC 62443 aligned industrial control system requirements.
• Define physical security policy in partnership with Facilities, including access authorization rules, badge review cadence, and video retention requirements, and audit adherence to them.
How This Role Works with I.T. Infrastructure and Security Operations
Niron separates security assurance from security execution so that the person defining and testing controls is not solely dependent on the team implementing them. This role owns governance, risk decisions, independent assurance, the insider threat program, and all assigned FSO duties. The I.T. Infrastructure and Security Operations team owns day-to-day technical implementation and response. Material risks, unresolved findings, and matters involving the reporting chain may be escalated directly to the Head of I.T. and the Security Committee.
• You set the bar: policies, control standards, risk ratings, and remediation service levels are authored here; the operations team implements them and is measured against them.
• You do not run the tools: you will not administer security consoles, patch systems, or triage alerts day to day. You specify what those activities must achieve and confirm the outcome.
• You test independently: you validate control operation with your own evidence, including for the operations team you sit within, and you report findings unfiltered.
• Insider threat is oversight here, mitigation there: you own the program, set the indicators, and decide what is investigated; the operations team implements the monitoring, performs containment, and carries out remediation at your direction.
• FSO duties are yours alone: the facility clearance, personnel security, classified material handling, and DCSA reporting are not delegable to the operations team, which supports you on the technical controls behind them.
• Independence is preserved by design: you hold a direct line to the Head of I.T. and the Security Committee for risk acceptance, audit findings, and security reporting, and they participate in your performance review. Findings that involve your reporting chain go to them.
Qualifications
• Bachelor’s degree in Information Security, Computer Science, or a related field, or equivalent experience.
• U.S. citizenship, and the ability to obtain and maintain a U.S. security clearance at the level required by Niron’s facility clearance. FSO duties under 32 CFR Part 117 require both.
• Experience serving as an FSO, assistant FSO, or ITPSO, or equivalent hands-on experience running a NISP security program, including DCSA interaction, self-inspections, and personnel security administration.
• Working knowledge of 32 CFR Part 117, DD Form 254 interpretation, SEAD 3 reporting requirements, and continuous vetting.
• 7+ years in information security, with at least 3 years focused on governance, risk, and compliance.
• Deep working knowledge of NIST SP 800-171 and CMMC Level 2, including SSP and POA&M development and SPRS scoring.
• Demonstrated experience preparing for and managing external audits or assessments, and owning findings to closure.
• Experience with a Microsoft 365 Government Community Cloud (GCC or GCC High) environment, CUI boundary definition, and DFARS 252.204-7012 requirements.
• Familiarity with Microsoft Purview sensitivity labeling and data loss prevention in a GCC High environment.
• Working knowledge of ITAR and EAR export control requirements as they apply to technical data and technology transfer.
• Familiarity with ISO 27001, CIS Controls, and the NIST Cybersecurity Framework.
• Ability to write clear policy and control documentation that holds up under third-party assessment.
• Sound technical judgment across cloud, network, endpoint, identity, O.T., and physical security, sufficient to specify and evaluate controls without administering them.
• Excellent communication skills, and the credibility and spine to hold peers and leadership accountable to their commitments.
Preferred Certifications & Training
• Preferred credentials include one or more of the following: CISSP, CISM, CISA, CRISC, CCP or CCA, Security+ or CySA+, GICSP or IEC 62443 training, DCSA CDSE FSO Program Management and ITPSO training, or ISP certification.
Our pay and benefits
Recruiters and Employment Agencies: Please note that Niron Magnetics does not accept unsolicited resumes from external agencies. Any unsolicited resumes submitted to our career site, hiring managers, or employees will be considered the property of Niron Magnetics. Consequently, we reserve the right to hire these candidates at our discretion without any financial obligation to the submitting agency.
The following notices apply only to positions involving access to export-controlled technology, technical data, or CUI as determined by the nature of the role and applicable program requirements
Export Control / ITAR Notice
This position may require access to information, technology, or technical data controlled under U.S. export control laws, including the International Traffic in Arms Regulations (ITAR, 22 C.F.R. Parts 120–130) and the Export Administration Regulations (EAR, 15 C.F.R. Parts 730–774), as well as Controlled Unclassified Information (CUI) as defined under 32 C.F.R. Part 2002. Where such access is required, the Company will evaluate all available license exceptions and exemptions before determining that a formal export authorization is necessary. If an export authorization is required, the Company will determine, based on legitimate business and regulatory considerations alone, whether to pursue one. The Company is not obligated to seek an export authorization in every circumstance, and any decision regarding authorization will never be based on a candidate's citizenship status, immigration status, or national origin. Each candidate's eligibility will be evaluated individually through a consistent, documented review process. The Company complies fully with all applicable federal anti-discrimination laws, including Title VII of the Civil Rights Act of 1964 (42 U.S.C. § 2000e et seq.), the anti-discrimination provisions of the Immigration and Nationality Act (8 U.S.C. § 1324b), and Executive Order 11246 as implemented by 41 C.F.R. Part 60. The Company does not discriminate on the basis of national origin, citizenship status, or immigration status in any aspect of employment.
Controlled Unclassified Information (CUI)
This role may involve access to Controlled Unclassified Information (CUI). Candidates selected for roles involving CUI will be required to comply with all applicable safeguarding and handling requirements, including those under NIST SP 800-171 and any governing contractual obligations.