> Markdown version of [/jobs/ext/1503017-project-lead-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/1503017-project-lead-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PROJECT - Lead Security Engineer II - **Company:** Deloitte T.T.L. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, CompTIA Security+, Cyber Security, Linux System Administration, Windows Servers, Red Hat Enterprise Linux, SAP (Applications), Secure Coding, Tripwire, Software Vulnerability Management, Nessus, Comptia Linux+, Splunk, Plan of Action and Milestones - **Published:** July 30, 2026 - **Apply:** https://apply.deloitte.com/en_US/careers/Login?jobId=361059 ## About the Role * Ability to work independently and collaborate as part of a team * Effective written and verbal communication skills * Meticulous attention to detail and quality of work product * Ability to build and sustain professional relationships * Ability to lead projects or workstreams * Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment * Strong interpersonal skills and professional demeanor * Ability to meet deadlines * Ability to mentor and provide clear guidance to others, * Bachelor's degree * Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future * Active Secret security clearance required with the ability to obtain a Top Secret clearance. * Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve * 4+ years of cybersecurity experience, including 2+ years in cloud security. * 4+ years of experience with IAM, encryption, boundary security, logging, and cloud monitoring. * 3+ years of experience with AWS * 2+ years of the following experience: + Experience with RMF, NIST 800-53, STIGs, and federal authorization practices. + Experience with ACAS/Nessus + Experience with Splunk + Experience with securing AWS environments, preferably in regulated or government settings. * CompTIA Security+ CE DoD 8570/8140-compliant baseline cybersecurity certification Preferred: * OS / Computing Environment Certifications or Training Certificate of Completion (40+ hours): + Tripwire: Windows Server Administration certification/training covering Windows Server 2022, or similar + Splunk: CompTIA Linux+ or Red Hat Certified System Administrator (RHCSA), or similar * CISSP, CASP/SecurityX, CySA, or similar * Splunk Core Certified User / Power User / Admin * Experience with AWS GovCloud in a DoW or IC environment. * Experience with SAP cybersecurity tooling, including SecurityBridge * Experience with RMF, STIGs, POA&M management, and DoD vulnerability management processes Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@deloitte.com. Recruiting tips ## Description As a PROJECT - Lead Security Engineer II on the Enterprise Security team, you will support cybersecurity operations for the Client's program by administering and sustaining tools used for continuous monitoring, vulnerability management, log analysis, and security operations support. * Administer Tripwire to support file integrity monitoring, configuration assessment, and cybersecurity control execution. * Support administration of Splunk, SecurityBridge, and ESS, including configuration, monitoring, reporting, and operational support. * Perform and coordinate ACAS scans, analyze findings, prioritize vulnerabilities, and track remediation with system owners and technical teams. * Support system hardening, patch coordination, access reviews, and incident analysis across Windows and Linux environments. * Maintain documentation, standard operating procedures, Plan of Action and Milestones (POA&M) inputs, and audit evidence in alignment with Department of Defense (DoD), Risk Management Framework (RMF), and program requirements. ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)