DevSecOps-focused Senior Consultant, Enterprise Security

Deloitte T.T.L.
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 188K

Job location

Tech stack

Kubernetes Security
Amazon Web Services (AWS)
Azure
Bash
Cloud Computing
Cloud Computing Security
Code Review
Computer Security
Continuous Delivery
Continuous Integration
Global Positioning Systems (GPS)
Identity and Access Management
Information Systems Security Architecture Professional
Python
Openshift
Powershell
Cloud Services
Ansible
Zero Trust Network Access
Secure Coding
Security Software
Software Engineering
SonarQube
Google Cloud Platform
Sonatype
Software Security
Cloudformation
Kubernetes
Infrastructure Automation Frameworks
Terraform
Prisma Cloud Platform
Docker

Job description

Join Deloitte's Government & Public Services practice as a DevSecOps-focused Senior Consultant, Enterprise Security. In this role, you will help clients build, secure, and modernize software delivery environments by embedding security across the software development lifecycle. You will work across cloud, application, infrastructure, and platform teams to automate security controls, improve compliance, and strengthen resiliency in mission-driven environments., As a Senior Consultant, Enterprise Security on the GPS Cyber team, you will be responsible for…

  • Designing and implementing DevSecOps processes that integrate security controls into software development, build, release, and deployment workflows
  • Building and maintaining continuous integration and continuous delivery pipelines with automated security testing, code scanning, dependency scanning, and secrets detection
  • Supporting cloud and platform engineering teams with secure configuration, infrastructure as code, container security, and identity and access management practices
  • Collaborating with application developers, architects, and cyber teams to remediate vulnerabilities, improve secure coding practices, and strengthen release governance
  • Producing technical documentation, implementation artifacts, and status reporting to support delivery, audit readiness, and client stakeholder decision-making

Requirements

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others, * Bachelor's degree in computer science, cybersecurity, information technology, engineering, or mathematics
  • Local to the DMV area and have the ability to work onsite up to 5 days a week
  • Ability to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.
  • 4+ years of experience implementing DevSecOps practices across cloud or hybrid environments
  • 4+ years of experience building or administering continuous integration and continuous delivery (CI/CD) pipelines using Jenkins, GitLab CI, GitHub Actions, or Azure DevOps
  • 2+ years of experience integrating application security testing, dependency scanning, secrets scanning, or container security controls into CI/CD pipelines
  • 3+ years of experience with Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP), and infrastructure as code using Terraform, AWS CloudFormation, or Ansible
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Experience supporting federal, state, local, or higher education environments
  • Experience with National Institute of Standards and Technology (NIST) 800-53, NIST Secure Software Development Framework, FedRAMP, or Zero Trust security requirements
  • Experience with Docker, Kubernetes, OpenShift, or container orchestration security practices
  • Experience using SonarQube, Snyk, Prisma Cloud, Aqua, or comparable security tooling
  • Experience developing automation using Python, PowerShell, Bash, or Go
  • One or more certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer Associate, or Certified Kubernetes Security Specialist (CKS)

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $107,925 to $188,000.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

About the company

Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise., At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you. Our people and culture Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work. Our purpose Deloitte's purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more. Professional development From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. As used in this posting, "Deloitte" means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.

Apply for this position