Cyber Senior Consultant - Cloud DevSecOps

Deloitte T.T.L.
Kansas City, MO, United States
16 days ago
Apply on www.kansasworks.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Cloud Computing Cloud Engineering Continuous Integration Systems Development Life Cycle Software Engineering Software Vulnerability Management Software Security Kubernetes Devsecops Static Application Security Testing
+1 more
Dynamic Application Security Testing

Job description

Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte’s Cloud Cyber Services team and become a member of the largest group of cybersecurity professionals worldwide., + Execute assigned DevSecOps and Secure SDLC workstreams across assessments, design, implementation, testing, and operationalization; coordinate with client stakeholders and delivery team members to complete assigned activities on time and with high quality.

  • Assess current-state security capabilities across people, processes, technology, and governance; analyze gaps and contribute to target-state recommendations, prioritized roadmaps, operating models, and implementation plans.

  • Design and implement Secure-by-Design and Application Security processes across the software development lifecycle, including application intake, risk classification, architecture reviews, threat modeling, control assessments, approvals, exception management, and go-live governance.

  • Support the integration of security tooling, automation, and AI-enabled capabilities into CI/CD and developer workflows, including SAST, DAST, SCA, secrets, infrastructure-as-code, container, API, and vulnerability management, as well as AI-assisted triage, remediation, validation, and secure AI guardrails.

  • Perform cloud-native and software supply chain security assessments, including cloud, container, Kubernetes, runtime, dependency, SBOM, artifact integrity, secure build, code-signing, secrets management, and software provenance activities; help define and prioritize remediation actions.

  • Contribute to client delivery and team development by facilitating workshops, preparing technical and executive deliverables, tracking work plans, risks, issues, and dependencies, supporting metrics and dashboards, mentoring junior practitioners, reviewing work for quality, and contributing to proposals and reusable practice assets.

Requirements

  • Ability to work independently and collaborate as part of a team

  • Effective written and verbal communication

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.kansasworks.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all