
at Deloitte
Big FourPosted 3 days ago
No clicks
This employer did not include a short summary.
- Compensation
- $105,400 – $207,800 USD
- City
- Atlanta, Austin, Boston, Chicago, Dallas, Denver, Houston, Los Angeles, Miami, Minneapolis, New York City, Philadelphia, San Diego, San Francisco, Seattle, Washington DC
- Country
- United States
Currency: $ (USD)
Full Job Description
Deloitte US
- Home
- Jobs
- Entry level
- Experienced
- Global Firm Roles
- Events
- Login
Cyber Senior Consultant - Cloud DevSecOps
Atlanta, Georgia, United States
Austin, Texas, United States
Baltimore, Maryland, United States
Boston, Massachusetts, United States
Charlotte, North Carolina, United States
Chicago, Illinois, United States
Cincinnati, Ohio, United States
Columbus, Ohio, United States
Costa Mesa, California, United States
Dallas, Texas, United States
Denver, Colorado, United States
Detroit, Michigan, United States
Houston, Texas, United States
Jersey City, New Jersey, United States
Kansas City, Missouri, United States
Los Angeles, California, United States
McLean, Virginia, United States
Miami, Florida, United States
Minneapolis, Minnesota, United States
Morristown, New Jersey, United States
Nashville, Tennessee, United States
New York, New York, United States
Philadelphia, Pennsylvania, United States
Pittsburgh, Pennsylvania, United States
Sacramento, California, United States
San Diego, California, United States
San Francisco, California, United States
San Jose, California, United States
Seattle, Washington, United States
Tempe, Arizona, United States
Washington, District of Columbia, United States
Caution against fraudulent job offers. Learn more.
Position Summary
Cyber Senior Consultant - DevSecOps
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cloud Cyber Services team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/31/2026
Work Youll Do
As a Senior Consultant, you will:
- Execute assigned DevSecOps and Secure SDLC workstreams across assessments, design, implementation, testing, and operationalization; coordinate with client stakeholders and delivery team members to complete assigned activities on time and with high quality.
- Assess current-state security capabilities across people, processes, technology, and governance; analyze gaps and contribute to target-state recommendations, prioritized roadmaps, operating models, and implementation plans.
- Design and implement Secure-by-Design and Application Security processes across the software development lifecycle, including application intake, risk classification, architecture reviews, threat modeling, control assessments, approvals, exception management, and go-live governance.
- Support the integration of security tooling, automation, and AI-enabled capabilities into CI/CD and developer workflows, including SAST, DAST, SCA, secrets, infrastructure-as-code, container, API, and vulnerability management, as well as AI-assisted triage, remediation, validation, and secure AI guardrails.
- Perform cloud-native and software supply chain security assessments, including cloud, container, Kubernetes, runtime, dependency, SBOM, artifact integrity, secure build, code-signing, secrets management, and software provenance activities; help define and prioritize remediation actions.
- Contribute to client delivery and team development by facilitating workshops, preparing technical and executive deliverables, tracking work plans, risks, issues, and dependencies, supporting metrics and dashboards, mentoring junior practitioners, reviewing work for quality, and contributing to proposals and reusable practice assets.
The successful candidate would possess these skills
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The Team
Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a clients technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related technical discipline
- 4+ years of professional experience in at least one of the following domains: DevSecOps, Application Security, Secure SDLC, Cloud Security, cybersecurity engineering, software security, or cybersecurity consulting.
- 2+ years of hands-on experience with DevSecOps, Application Security, Secure SDLC, or Secure-by-Design activities, including assessment, design, implementation, or security engineering.
- 1+ year of experience leading or independently owning a cybersecurity, DevSecOps, Application Security, or Secure SDLC project workstream.
- 2+ years of experience with CI/CD or modern software engineering environments, including experience with at least 3 of the following security capabilities: SAST, DAST, SCA, secrets scanning, IaC scanning, container security, API security, threat modeling, or vulnerability management.
- 1+ year of experience translating cybersecurity policies, standards, or control requirements into technical controls, engineering requirements, security procedures, or SDLC workflows.
- Experience applying at least 1 cybersecurity framework or standard, such as NIST CSF, NIST SP 800-53, NIST SSDF, OWASP SAMM, ISO 27001, or comparable framework, on at least 1 project.
- 1+ year of experience with at least 1 cloud or cloud-native environment, including Microsoft Azure, AWS, Google Cloud Platform, Kubernetes, or container-based application environments.
- 1+ year of experience using at least 1 engineering, security workflow, or automation platform, such as ServiceNow, Jira, Azure DevOps, GitHub, GitLab, Jenkins, or comparable technology.
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred Qualifications
- Experience producing at least 2 types of client or enterprise security deliverables, such as assessment reports, technical recommendations, process flows, control mappings, roadmaps, architecture documentation, dashboards, or executive presentations.
- Experience facilitating or supporting at least 2 client or stakeholder workshops, requirements sessions, technical working sessions, or security assessments.
- Experience coordinating activities with at least 1 cross-functional or geographically distributed delivery team.
- 6+ months of experience or project exposure to AI-enabled cybersecurity, Generative AI security, AI-assisted vulnerability management/remediation, or Agentic AI security automation.
- Experience implementing or supporting at least 1 AI-assisted security use case, such as vulnerability triage, remediation recommendations, code remediation, security analysis, control validation, or security workflow automation.
- Experience with at least 1 software supply chain security capability, such as SBOM, SLSA, dependency governance, code signing, artifact integrity, PKI/HSM, or software provenance.
- Experience with OWASP SAMM, BSIMM, NIST SSDF, SLSA, or comparable software security maturity frameworks.
- At least 1 relevant cybersecurity or cloud certification, such as CCSP, CISSP, CISA, CSSLP, Security+, AWS security certification, Microsoft Azure security certification, Google Cloud security certification, or comparable credential.
- 1+ year of consulting or professional services experience preferred.
- Experience using at least 1 reporting or analytics platform, such as Microsoft Power BI, Tableau, or comparable technology.
- Experience supporting security requirements associated with at least 1 regulatory or compliance framework, such as ISO 27001/27017, SOC 2, PCI DSS, HIPAA, SOX, GLBA, or NIST SP 800-53.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
From entry-level employees to senior leaders, we believe theres always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Similar jobs
- Front Office Communications & Strategy SupportMonterey, California, United States Strategy & Transactions
- Project - Manager, Cognos Training - TS/SCI w/ Poly - Chantilly, VARosslyn, Virginia, United States Human Capital
- Project - Manager, Workforce Shaping and Development - TS/SCI w/ Poly - Chantilly, VARosslyn, Virginia, United States Human Capital
- Cyber Manager - Cloud DevSecOpsMultiple Locations Cyber
SCAM ALERT
Caution against fraudulent job offers!
We have been informed of instances where jobseekers are led to believe of fictitious job opportunities with Deloitte US (Deloitte). In one or more such cases, false promises of actual or potential selection, or initiation or completion of the recruitment formalities appear to have been or are being made. Some jobseekers appear to have been asked to pay money to specified bank accounts of individuals or entities as a condition of their selection for a job with Deloitte. These individuals or entities are in no way connected with Deloitte and do not represent or otherwise act on behalf of Deloitte.
We would like to clarify that:
- At Deloitte, ethics and integrity are fundamental and not negotiable.
- We are against corruption and neither offer bribes nor accept them, nor induce or permit any other party to make or receive bribes on our behalf.
- We have not authorized any party or person to collect any money from jobseekers in any form whatsoever for promises of getting jobs in Deloitte.
- We consider candidates on merit and that we provide an equal opportunity to eligible applicants.
- No one other than designated Deloitte personnel (e.g., a Deloitte recruiter or Deloitte hiring partner) is permitted to extend any job offer from Deloitte.
Anyone who at any time has made or makes any payment to any party in exchange for promises of job or selection for a job with Deloitte or any matter related to this (including those for registration, verification or security deposit) or otherwise engages with any such person who has made or makes fraudulent promises or offers, does so (or has done so) entirely at their own risk. Deloitte takes no responsibility or liability for any such unauthorized or fraudulent actions or engagements. We encourage jobseekers to exercise caution.
- About Deloitte
- Terms of use
- Privacy
- Data Privacy Framework
- Do Not Sell or Share My Personal Information
- Cookies
- Legal information for job seekers and ADA
- Labor condition applications
- Assistance for people with disabilities
2026. See Terms of Use for more information.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee ("DTTL"), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as "Deloitte Global") does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the "Deloitte" name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.
SIMILAR OPPORTUNITIES

Cyber Full Stack Senior Consultant
Deloitte
Added 3 days ago

Senior Cybersecurity Consultant
Capgemini
Added 11 days ago

Identity, Defense & Resilience - Cloud Security Senior Associate
PwC
Added 11 days ago

Senior Consultant - Digital Trust (Cyber Defense)
KPMG
Added 11 days ago

Cybersecurity - Cyber Managed Services (Security Operations Analyst) - Consultant
Ernst & Young
Added 9 days ago
