
11 - 50 employees
Founded 2024
🔒 Cybersecurity
📋 Compliance
💼 Consulting
Cybersecurity • Compliance • Consulting
Velero is a cybersecurity and compliance consulting firm that provides managed advisory and technical services to businesses of all sizes. Their offerings include offensive security and penetration testing, compliance advisory and assessments (SOC 2, HIPAA, NIST, ISO, PCI DSS, HITRUST, etc. ), privacy consulting (GDPR, CCPA/CPRA), public sector advisory (CMMC, FISMA, FedRAMP), due diligence and risk management for M&A and third‑party risk, AI security and scalability consulting, virtual CISO/CTO/CIO services, cloud advisory and engineering, and secure code reviews. Velero’s engagements include helping a growing SaaS company achieve SOC 2 certification via gap analysis, remediation roadmaps, controls implementation, and staff training. Based in Tampa, FL, they position themselves as a partner for organizations seeking to meet regulatory requirements and defend against cyber threats.
🕒 July 27
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
Founded 2024
🔒 Cybersecurity
📋 Compliance
💼 Consulting
Cybersecurity • Compliance • Consulting
Velero is a cybersecurity and compliance consulting firm that provides managed advisory and technical services to businesses of all sizes. Their offerings include offensive security and penetration testing, compliance advisory and assessments (SOC 2, HIPAA, NIST, ISO, PCI DSS, HITRUST, etc. ), privacy consulting (GDPR, CCPA/CPRA), public sector advisory (CMMC, FISMA, FedRAMP), due diligence and risk management for M&A and third‑party risk, AI security and scalability consulting, virtual CISO/CTO/CIO services, cloud advisory and engineering, and secure code reviews. Velero’s engagements include helping a growing SaaS company achieve SOC 2 certification via gap analysis, remediation roadmaps, controls implementation, and staff training. Based in Tampa, FL, they position themselves as a partner for organizations seeking to meet regulatory requirements and defend against cyber threats.
• Perform official CMMC Level 2 assessments for organizations seeking certification. • Evaluate the effectiveness of security controls, policies, and procedures, identifying compliance gaps. • Prepare comprehensive audit reports, including findings, recommendations, and remediation plans, following CMMC-AB standards. • Collaborate with a C3PAO (CMMC Third-Party Assessment Organization) to ensure assessments meet accreditation requirements. • Guide organizations through the formal CMMC assessment process, ensuring readiness and compliance with certification criteria. • Stay updated on CMMC requirements, standards, and best practices changes.
• Minimum of 5 years of experience in information security auditing, with a strong focus on NIST SP 800-171 compliance. • Proven experience conducting formal compliance audits and security assessments. • Familiarity with the Cybersecurity Maturity Model Certification (CMMC) Assessment Process and documentation requirements. • Strong knowledge of NIST SP 800-171 standards, security controls, and compliance requirements. • Deep understanding of information security principles, risk management, and audit methodologies. • Excellent written and verbal communication skills, with the ability to create detailed, high-quality assessment reports. • CMMC Certified Assessor (CCA) certification. • Candidates must currently hold, have previously held, or be willing to obtain the certification under client sponsorship. • Preferred Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Authorization Professional (CAP).
• Flexible, project-based engagements with the opportunity to work on high-impact cybersecurity compliance initiatives. • Competitive hourly compensation based on experience, certifications, and project scope. • Opportunity to work on 80+ hour engagements with established clients across regulated industries.
Apply Now🕒 June 25
Expert level SOC 2 Auditor at TestPros delivering IT assessment solutions. Evaluate internal controls and conduct gap analysis to enhance security posture.