HomeApplication Security EngineerCloud Security Engineer, Secret Cleared
Deloitte

Cloud Security Engineer, Secret Cleared

Deloitte·Arlington, Virginia, US

Posted 1w ago

Full-Time
Apply Now

About the Role

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Work You'll Do • Application Security: Evaluate, enhance, and document secure software development practices. Lead AppSec assessments, support remediation efforts, and help set security requirements for platforms and custom applications. • Compliance & RMF (NIST): Provide deep support for federal compliance initiatives, specializing in NIST 800-53 and RMF processes. Develop control implementation plans, assist with artifacts, advise on audit readiness and manage POAMs • DevSecOps (Cloud Security): Guide secure DevOps practices, integrating security into CI/CD pipelines and cloud architectures. Partner with teams to implement security automation and validate environments (AWS,). • Vulnerability Assessment & VAT Management: Conduct and coordinate vulnerability scans using Tenable, Inspector, or similar tools. Drive VAT resolution by engaging stakeholders, tracking remediation, and closing findings. • Technical Project Delivery: Take charge of critical projects-organizing tasks, managing deadlines, and ensuring results. Handle ad-hoc assignments and maintain excellent documentation. • Consulting: Communicate solutions and risks to technical and non-technical stakeholders. Lead and support ISSO activities, compliance reviews, and team enablement. The Team Deloitte's Government and Public Services (GPS) practice - our people, ideas, technology, and outcomes-are designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise. The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals. Qualifications Required: • Bachelor's degree required. • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future. • Active Secret Clearance. • Ability to work onsite up to two days a week onsite. • 5+ years in cloud security, security engineering, DevSecOps, or security automation, along with a strong understanding of cloud security fundamentals: IAM, network segmentation, encryption/KMS, secrets management, logging/monitoring, secure storage patterns. • Security + certification or similar industry cert. • 3+ years' experience within the following: • * At least one major cloud platform (AWS or Azure strongly preferred). • Demonstrated automation capability: • Proficiency in Python, PowerShell, or similar. • Experience integrating APIs, automating workflows, and producing auditable outputs. • Experience implementing security controls and/or compliance work in regulated environments (federal, healthcare, finance, etc.). • Familiarity with Git-based workflows and CI/CD systems. Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

What you'll do

  • Application Security: Evaluate, enhance, and document secure software development practices
  • Lead AppSec assessments, support remediation efforts, and help set security requirements for platforms and custom applications
  • Compliance & RMF (NIST): Provide deep support for federal compliance initiatives, specializing in NIST 800-53 and RMF processes
  • Develop control implementation plans, assist with artifacts, advise on audit readiness and manage POAMs
  • DevSecOps (Cloud Security): Guide secure DevOps practices, integrating security into CI/CD pipelines and cloud architectures
  • Partner with teams to implement security automation and validate environments (AWS,)
  • Vulnerability Assessment & VAT Management: Conduct and coordinate vulnerability scans using Tenable, Inspector, or similar tools
  • Drive VAT resolution by engaging stakeholders, tracking remediation, and closing findings
  • Technical Project Delivery: Take charge of critical projects-organizing tasks, managing deadlines, and ensuring results
  • Handle ad-hoc assignments and maintain excellent documentation
  • Consulting: Communicate solutions and risks to technical and non-technical stakeholders
  • Lead and support ISSO activities, compliance reviews, and team enablement
  • The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need
  • Team members focus on delivering services to clients, without additional expectations related to business development or promotion

Requirements

  • Bachelor's degree required
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
  • Active Secret Clearance
  • Ability to work onsite up to two days a week onsite
  • 5+ years in cloud security, security engineering, DevSecOps, or security automation, along with a strong understanding of cloud security fundamentals: IAM, network segmentation, encryption/KMS, secrets management, logging/monitoring, secure storage patterns
  • Security + certification or similar industry cert
  • 3+ years' experience within the following:
  • Demonstrated automation capability:
  • Proficiency in Python, PowerShell, or similar
  • Experience integrating APIs, automating workflows, and producing auditable outputs
  • Experience implementing security controls and/or compliance work in regulated environments (federal, healthcare, finance, etc.)
  • Familiarity with Git-based workflows and CI/CD systems
  • Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

Benefits

  • Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals
Back to all jobs