Deloitte

Cloud Security Architect -DevSecOps Manager

Deloitte$144K — $265K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in technical consulting and client delivery leadership.
  • 2+ years leading DevSecOps / Secure SDLC programs.
  • Proficient in translating policy/standards into engineering-ready controls.
  • Familiarity with automation platforms for security governance.
  • Experience in application security and modern engineering ecosystems.
  • BA/BS degree in a technical field preferred.

Responsibilities

  • Lead DevSecOps/Secure SDLC program delivery as a project manager/architect.
  • Design workflows to streamline security governance for engineering teams.
  • Build controls frameworks aligned to NIST and translate into actionable requirements.
  • Conduct current-state assessments and create multi-year roadmaps.
  • Define options for DevSecOps operating models and drive decision-making.
  • Integrate security into CI/CD and SDLC workflows including governance.
  • Advance software supply chain security by guiding implementation patterns.
  • Define metrics and dashboards to improve project transparency and accountability.
  • Act as the primary client interface, collaborating across teams.
  • Support business development efforts and contribute to thought leadership.

Benefits

  • Access to a broad range of benefits that promote employee well-being.
  • Inclusive culture that values diverse perspectives and fosters innovation.
  • Opportunities for continuous professional development and mentorship.
  • Participation in professional development programs to enhance skills.
  • Commitment to making a meaningful impact on communities and organizations.
Full Job Description
Cloud Security Architect - DevSecOps Manager

Position Summary

Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cloud Cyber Services team and become a member of the largest group of cybersecurity professionals worldwide.

Work you'll do

As a DevSecOps Security Architect (Manager), you will lead client engagements that define, operationalize, and scale secure-by-design software delivery in cloud-agnostic environments. Responsibilities include:
  • Lead delivery of DevSecOps / Secure SDLC programs as a project manager and/or architect, overseeing onsite/offshore teams across governance, identity, application security, platform/infrastructure security, monitoring, resilience, and data protection.
  • Design and implement Secure by Design / security engagement intake workflows that streamline how engineering teams initiate governance/security processes (e.g., rationalizing questionnaires, automating routing/approvals, reducing cycle time).
  • Build or tailor controls frameworks and control mappings (e.g., aligned to NIST 800-53 and enterprise policies/standards) and translate them into actionable engineering requirements and measurable outcomes.
  • Conduct DevSecOps current-state assessments (people/process/technology), facilitate leading-practices workshops, and produce multi-year roadmaps with sequenced initiatives, resourcing, and cost estimates.
  • Define DevSecOps operating model options (team structure, service catalog, intake, RACI, governance forums) and drive executive decision-making on the target approach.
  • Embed security into CI/CD and SDLC workflows (requirements, design, build, test, deploy, operate) including security controls, evidence capture, and release/go-live governance.
  • Advance software supply chain security (e.g., dependency risk, artifact integrity, code signing, PKI/HSM considerations) and guide implementation patterns appropriate to client context.
  • Support container and runtime security assessments and backlog acceleration; help teams prioritize security work without stalling delivery.
  • Define metrics, reporting, and dashboards (e.g., delivery throughput, control compliance, intake cycle time, risk burndown, vulnerability trends) to improve transparency and accountability.
  • Function as the primary day-to-day client interface, building rapport and driving outcomes across Engineering, Security, Risk/Compliance, and Operations.
  • Assist in business development (scope, estimates, pricing, proposals) and contribute to eminence (POVs/whitepapers) and internal enablement
The team

Deloitte's Cyber Cloud team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive Secure.Vigilant.Resilient. TM cyber risk programs. Join the team developing the future state of cyber risk solutions.

Required:
  • 6+ years of experience in technical consulting, client problem solving, and delivery leadership.
  • 2+ years designing or leading DevSecOps / Secure SDLC programs (assessment, roadmap, operating model, and implementation oversight).
  • Experience translating policy/standards into engineering-ready controls and workflows; familiarity with security control frameworks (e.g., NIST CSF and/or NIST 800-53).
  • Experience with automation/workflow platforms (e.g., ServiceNow or similar) to support security intake, governance, and evidence collection.
  • Experience with application security and modern engineering ecosystems (CI/CD concepts, containers, SDLC tooling).
  • BA/BS degree preferably in a technical field.
Additional Requirements:
  • Ability to travel up to 80%, on average, based on the work you do and the clients and industries/sectors you serve
  • Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
  • Previous consulting or Big 4 experience.
  • Certifications (e.g., CCSP or comparable); familiarity with industry maturity models (e.g., OWASP SAMM, BSIMM) and/or supply chain frameworks (e.g., SLSA).
  • Experience with code signing/PKI concepts and security tooling ecosystems; experience with dashboarding/analytics (e.g., Power BI) a plus.
  • Understanding of regulatory/compliance requirements (e.g., ISO 27001/27017, SOC 2, PCI, HIPAA, SOX, GLBA, NIST 800-53).
'Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $144,200 to $265,600

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Recruiting tips

From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.

Benefits

At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.

Our people and culture

Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.

Our purpose

Deloitte's purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.

Professional development

From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.

As used in this posting, "Deloitte" means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.

Requisition code: 327442

Job ID 327442

About Deloitte

Deloitte is a multinational professional services network that provides audit, tax, consulting, enterprise risk and financial advisory services. The company was founded in London in 1845 and has since grown to become one of the largest professional services firms in the world. Deloitte has over 330,000 employees in more than 150 countries and territories. The company's mission is to help clients achieve their goals and make an impact that matters in their businesses and communities.
Learn more about Deloitte
Size
330,000 employees
Industry
Founded
1999

Similar Jobs

More Jobs at Deloitte

More Information Technology Jobs

Find similar Cloud Security Architect -DevSecOps Manager jobs: