> Markdown version of [/jobs/ext/190246-cloud-security-architect-devsecops-manager](https://www.wearedevelopers.com/jobs/ext/190246-cloud-security-architect-devsecops-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Architect -DevSecOps Manager - **Company:** Deloitte T.T.L. - **Location:** Boston, MA, United States - **Experience:** Experienced - **Salary:** $144,200.0 - $265,600.0 - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Cloud Computing, Cloud Computing Security, Continuous Integration, Open Web Application Security, Public Key Infrastructure, Systems Development Life Cycle, Power BI, Software Security, Devsecops, Servicenow - **Published:** May 15, 2026 - **Apply:** https://dejobs.org/x/x/BF9BC945EB2F40CB84115A89930F5458/job/ ## About the Role * 6+ years of experience in technical consulting, client problem solving, and delivery leadership. * 2+ years designing or leading DevSecOps / Secure SDLC programs (assessment, roadmap, operating model, and implementation oversight). * Experience translating policy/standards into engineering-ready controls and workflows; familiarity with security control frameworks (e.g., NIST CSF and/or NIST 800-53). * Experience with automation/workflow platforms (e.g., ServiceNow or similar) to support security intake, governance, and evidence collection. * Experience with application security and modern engineering ecosystems (CI/CD concepts, containers, SDLC tooling). * BA/BS degree preferably in a technical field. Additional Requirements: * Ability to travel up to 80%, on average, based on the work you do and the clients and industries/sectors you serve * Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices. Preferred: * Previous consulting or Big 4 experience. * Certifications (e.g., CCSP or comparable); familiarity with industry maturity models (e.g., OWASP SAMM, BSIMM) and/or supply chain frameworks (e.g., SLSA). * Experience with code signing/PKI concepts and security tooling ecosystems; experience with dashboarding/analytics (e.g., Power BI) a plus. * Understanding of regulatory/compliance requirements (e.g., ISO 27001/27017, SOC 2, PCI, HIPAA, SOX, GLBA, NIST 800-53). ## Description Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cloud Cyber Services team and become a member of the largest group of cybersecurity professionals worldwide., As a DevSecOps Security Architect (Manager), you will lead client engagements that define, operationalize, and scale secure-by-design software delivery in cloud-agnostic environments. Responsibilities include: * Lead delivery of DevSecOps / Secure SDLC programs as a project manager and/or architect, overseeing onsite/offshore teams across governance, identity, application security, platform/infrastructure security, monitoring, resilience, and data protection. * Design and implement Secure by Design / security engagement intake workflows that streamline how engineering teams initiate governance/security processes (e.g., rationalizing questionnaires, automating routing/approvals, reducing cycle time). * Build or tailor controls frameworks and control mappings (e.g., aligned to NIST 800-53 and enterprise policies/standards) and translate them into actionable engineering requirements and measurable outcomes. * Conduct DevSecOps current-state assessments (people/process/technology), facilitate leading-practices workshops, and produce multi-year roadmaps with sequenced initiatives, resourcing, and cost estimates. * Define DevSecOps operating model options (team structure, service catalog, intake, RACI, governance forums) and drive executive decision-making on the target approach. * Embed security into CI/CD and SDLC workflows (requirements, design, build, test, deploy, operate) including security controls, evidence capture, and release/go-live governance. * Advance software supply chain security (e.g., dependency risk, artifact integrity, code signing, PKI/HSM considerations) and guide implementation patterns appropriate to client context. * Support container and runtime security assessments and backlog acceleration; help teams prioritize security work without stalling delivery. * Define metrics, reporting, and dashboards (e.g., delivery throughput, control compliance, intake cycle time, risk burndown, vulnerability trends) to improve transparency and accountability. * Function as the primary day-to-day client interface, building rapport and driving outcomes across Engineering, Security, Risk/Compliance, and Operations. * Assist in business development (scope, estimates, pricing, proposals) and contribute to eminence (POVs/whitepapers) and internal enablement The team Deloitte's Cyber Cloud team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive Secure.Vigilant.Resilient. TM cyber risk programs. Join the team developing the future state of cyber risk solutions. ## Related Videos - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)