JOBSEARCHER

DevSecOps Engineer (Secret Clearance)

Join Deloitte's Government & Public Services practice as a DevSecOps-focused Senior Consultant, Enterprise Security. In this role, you will help clients build, secure, and modernize software delivery environments by embedding security across the software development lifecycle. You will work across cloud, application, infrastructure, and platform teams to automate security controls, improve compliance, and strengthen resiliency in mission-driven environments.Work You'll DoAs a Senior Consultant, Enterprise Security on the GPS Cyber team, you will be responsible for...Designing and implementing DevSecOps processes that integrate security controls into software development, build, release, and deployment workflowsBuilding and maintaining continuous integration and continuous delivery pipelines with automated security testing, code scanning, dependency scanning, and secrets detectionSupporting cloud and platform engineering teams with secure configuration, infrastructure as code, container security, and identity and access management practicesCollaborating with application developers, architects, and cyber teams to remediate vulnerabilities, improve secure coding practices, and strengthen release governanceProducing technical documentation, implementation artifacts, and status reporting to support delivery, audit readiness, and client stakeholder decision-makingA successful candidate would possess these skills:Ability to work independently and collaborate as part of a teamEffective written and verbal communication skillsMeticulous attention to detail and quality of work productAbility to build and sustain professional relationshipsAbility to lead projects or workstreamsAbility to manage and prioritize multiple tasks in a fast-paced and dynamic environmentStrong interpersonal skills and professional demeanorAbility to meet deadlinesAbility to provide clear guidance to othersThe TeamDeloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.QualificationsBachelor's degree in computer science, cybersecurity, information technology, engineering, or mathematicsLocal to the DMV area and have the ability to work onsite up to 5 days a weekAbility to travel 20%, on average, based on the work you do and the clients and industries/sectors you serve.4+ years of experience implementing DevSecOps practices across cloud or hybrid environments4+ years of experience building or administering continuous integration and continuous delivery (CI/CD) pipelines using Jenkins, GitLab CI, GitHub Actions, or Azure DevOps2+ years of experience integrating application security testing, dependency scanning, secrets scanning, or container security controls into CI/CD pipelines3+ years of experience with Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP), and infrastructure as code using Terraform, AWS CloudFormation, or AnsibleMust be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.Preferred:Experience supporting federal, state, local, or higher education environmentsExperience with National Institute of Standards and Technology (NIST) 800-53, NIST Secure Software Development Framework, FedRAMP, or Zero Trust security requirementsExperience with Docker, Kubernetes, OpenShift, or container orchestration security practicesExperience using SonarQube, Snyk, Prisma Cloud, Aqua, or comparable security toolingExperience developing automation using Python, PowerShell, Bash, or GoOne or more certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer Associate, or Certified Kubernetes Security Specialist (CKS)The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $107,925 to $188,000.You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.