Company

Deloitte UsSee more

addressAddressSacramento, CA
type Form of workOther
CategoryInformation Technology

Job description

Are you looking to elevate your cyber career? Your technical skills? Your opportunity for growth? Deloitte's Government and Public Services Cyber Practice (GPS Cyber Practice) is the place for you! Our GPS Cyber Practice helps organizations create a cyber minded culture and become stronger, faster, and more innovative. You will become part of a team that advises, implements, and manages solutions across five verticals: Strategy, Defense and Response; Identity; Infrastructure; Data; and Application Security. Our dynamic team offers opportunities to work with cutting-edge cyber security tools and grow both vertically and horizontally at an accelerated rate. Join our cyber team and elevate your career.

Work You'll Do:

As the Security Compliance & Vulnerability Manager you will play a critical role in leading end-end compliance security activities for the infrastructure supporting a state-wide integrated system. You are responsible for managing and maturing the Security Compliance program on the project and will lead a team of security engineers to periodically assess security controls for potential risks and secure end-end operations of the solution.

Responsibilities:

  • Drive enhancements to mature the Security Compliance program
  • Primary person responsible for driving Security Compliance efforts across the project. Responsible for providing security control and mitigation subject matter expertise for reduction of risks identified and mapped in risks assessments in coordination with other teams
  • Lead internal Security Compliance activities and support external audits/assessments
  • Lead the development and management of Security Compliance deliverables such as System Security Plan and Plan of Action & Milestone (POA&M), security risk assessment reports
  • Facilitate technical deep-dives and security threat model assessments to evaluate emerging threats
  • Conduct security reviews and coordinate penetration testing exercises on an as-needed basis

The team

Deloitte's Government and Public Services (GPS) practice - our people, ideas, technology and outcomes-is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of more than 15,000 professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise. 

At Deloitte, we believe cyber is about starting things-not stopping them-and enabling the freedom to create a more secure future. Cyber Strategy, Defense and Response (SDR) focuses on helping federal clients design and implement transformational enterprise security programs with an emphasis on defending against, recovering from, and mitigating major cyberattacks. If you're seeking a career that increases cyber awareness, utilizes risk management programs, and develops strategies for cyber defense and response, then the Cyber SDR offering at Deloitte is for you.

Qualifications 

Required:

  • Bachelor's degree required.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • Must be able to obtain and maintain the required clearance for this role.
  • 5+ years experience with designing and implementing security controls for large and complex IT systems hosted on-premise and/or in cloud environment based on security standards such as NIST 800-53, FedRAMP or CMS MARS-E.
  • 5+ years experience with developing system security plan (SSP) for large and complex IT systems hosted on-premise and/or in cloud environment.
  • 5+ years experience with performing security architecture reviews, periodically assessing and monitoring security controls for compliance with security standards, managing Plan of Actions & Milestones (POA&Ms), risk assessment, planning for remediation of identified risks.
  • 3+ years experience with assessing system data sensitivity using security categorizations (e.g., FIPS Publication 199) to identify appropriate security controls to protect Personally Identifiable Information (PII), Protected Health Information (PHI) and/or Federal Tax Information (FTI) data.
  • 3+ years experience with overseeing a team managing security vulnerability management program
  • 3+ years of experience with security concepts and practical usage (Network Engineering, Network Security, Threat and Vulnerability Management, Database, SDLC, and Release Management)
  • 3+ years of experience with Common Vulnerability Scoring System (CVSS) and other vulnerability risk scoring systems used in the industry
  • Role sits in Sacramento, CA.

Preferred:

  • Prior professional services or federal consulting experience
  • Certified Information Systems Security Professional (CISSP) certification or Certified Information Security Manager (CISM).

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $131,175 to $218,625.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

Qualifications:

Are you looking to elevate your cyber career? Your technical skills? Your opportunity for growth? Deloitte's Government and Public Services Cyber Practice (GPS Cyber Practice) is the place for you! Our GPS Cyber Practice helps organizations create a cyber minded culture and become stronger, faster, and more innovative. You will become part of a team that advises, implements, and manages solutions across five verticals: Strategy, Defense and Response; Identity; Infrastructure; Data; and Application Security. Our dynamic team offers opportunities to work with cutting-edge cyber security tools and grow both vertically and horizontally at an accelerated rate. Join our cyber team and elevate your career.

Work You'll Do:

As the Security Compliance & Vulnerability Manager you will play a critical role in leading end-end compliance security activities for the infrastructure supporting a state-wide integrated system. You are responsible for managing and maturing the Security Compliance program on the project and will lead a team of security engineers to periodically assess security controls for potential risks and secure end-end operations of the solution.

Responsibilities:

  • Drive enhancements to mature the Security Compliance program
  • Primary person responsible for driving Security Compliance efforts across the project. Responsible for providing security control and mitigation subject matter expertise for reduction of risks identified and mapped in risks assessments in coordination with other teams
  • Lead internal Security Compliance activities and support external audits/assessments
  • Lead the development and management of Security Compliance deliverables such as System Security Plan and Plan of Action & Milestone (POA&M), security risk assessment reports
  • Facilitate technical deep-dives and security threat model assessments to evaluate emerging threats
  • Conduct security reviews and coordinate penetration testing exercises on an as-needed basis

The team

Deloitte's Government and Public Services (GPS) practice - our people, ideas, technology and outcomes-is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of more than 15,000 professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise. 

At Deloitte, we believe cyber is about starting things-not stopping them-and enabling the freedom to create a more secure future. Cyber Strategy, Defense and Response (SDR) focuses on helping federal clients design and implement transformational enterprise security programs with an emphasis on defending against, recovering from, and mitigating major cyberattacks. If you're seeking a career that increases cyber awareness, utilizes risk management programs, and develops strategies for cyber defense and response, then the Cyber SDR offering at Deloitte is for you.

Qualifications 

Required:

  • Bachelor's degree required.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • Must be able to obtain and maintain the required clearance for this role.
  • 5+ years experience with designing and implementing security controls for large and complex IT systems hosted on-premise and/or in cloud environment based on security standards such as NIST 800-53, FedRAMP or CMS MARS-E.
  • 5+ years experience with developing system security plan (SSP) for large and complex IT systems hosted on-premise and/or in cloud environment.
  • 5+ years experience with performing security architecture reviews, periodically assessing and monitoring security controls for compliance with security standards, managing Plan of Actions & Milestones (POA&Ms), risk assessment, planning for remediation of identified risks.
  • 3+ years experience with assessing system data sensitivity using security categorizations (e.g., FIPS Publication 199) to identify appropriate security controls to protect Personally Identifiable Information (PII), Protected Health Information (PHI) and/or Federal Tax Information (FTI) data.
  • 3+ years experience with overseeing a team managing security vulnerability management program
  • 3+ years of experience with security concepts and practical usage (Network Engineering, Network Security, Threat and Vulnerability Management, Database, SDLC, and Release Management)
  • 3+ years of experience with Common Vulnerability Scoring System (CVSS) and other vulnerability risk scoring systems used in the industry
  • Role sits in Sacramento, CA.

Preferred:

  • Prior professional services or federal consulting experience
  • Certified Information Systems Security Professional (CISSP) certification or Certified Information Security Manager (CISM).

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $131,175 to $218,625.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Information for applicants with a need for accommodation: https://www2.deloitte.com/us/en/pages/careers/articles/join-deloitte-assistance-for-disabled-applicants.html

Education:Bachelor's DegreeEmployment Type:
Refer code: 8646246. Deloitte Us - The previous day - 2024-03-20 09:10

Deloitte Us

Sacramento, CA
Jobs feed

Sr.Manager - Guidewire (Claim Center)

Cognizant North America

Cleveland, OH

life insurance, parental leave, paid time off, paid holidays, 401(k)

Yard Worker Yard

Builders Firstsource

Helena, MT

United States, Montana, Helena

Class A CDL Driver

Builders Firstsource

Perry, GA

United States, Georgia, Perry

Scheduler II Delivery

Builders Firstsource

Shafter, CA

United States, California, Shafter

IT Training Designer

Amentum

Albuquerque, NM

Teamcenter

Cognizant North America

Austin, TX

United States, Texas, Austin

Senior Java Full Stack Developer (On-Site)

Cognizant North America

New York, NY

life insurance, parental leave, paid time off, paid holidays, 401(k)

Delivery Driver-Class A CDL

Builders Firstsource

Coos Bay, OR

United States, Oregon, Coos Bay

Maintenance Technician III

Builders Firstsource

Villa Rica, GA

United States, Georgia, Villa Rica

Embedded Test Engineer

Cognizant North America

Redmond, WA

United States, Washington, Redmond

Share jobs with friends

Related jobs

Security Compliance & Vulnerability Project Manager

SECURITY COMPLIANCE ANALYST

Triune Infomatics

Pleasanton, CA

20 hours ago - seen

Security Compliance Analyst

Top Client Company

Vacaville, CA

20 hours ago - seen

Information Systems Security Compliance Engineer

Canonical - Jobs

Fresno, CA

a week ago - seen

Engineering Program Manager, Security Compliance, Apple Services Engineering

Software And Services

Cupertino, CA

2 weeks ago - seen

Sr. Security & Compliance Analyst

Instride

Los Angeles, CA

4 weeks ago - seen

Information Security Analyst - Risk & Compliance

California State University

$4,912 - $12,124 a month

Long Beach, CA

4 weeks ago - seen

Senior Information Security Compliance Analyst

Ucla

$144,009 - $165,000 a year

Los Angeles, CA

4 weeks ago - seen

ISV Partner Engineer, Security and Compliance, Google Cloud

Google

San Francisco, CA

a month ago - seen

Operations Manager - Compliance - Sacramento

Palamerican Security

Sacramento, CA

a month ago - seen

Security & Compliance Officer

Rhombus

Sacramento, CA

2 months ago - seen

Information Systems Security Compliance Engineer

Canonical - Jobs

Sacramento, CA

2 months ago - seen

Senior Cyber Security- Governance Risk, and Compliance Analyst

Collective Health

$140,000 - $175,000 a year

San Francisco, CA

2 months ago - seen

Cloud Security Operations and Compliance Engineer (SecOps)

Cisco Systems Inc

San Jose, CA

2 months ago - seen

Security Compliance Manager

Docusign

San Francisco, CA

2 months ago - seen

Senior Security Analyst, Risk & Compliance

Turo

San Francisco, CA

2 months ago - seen

IT Security Risk, Governance and Compliance Analyst

Intuitive

Sunnyvale, CA

3 months ago - seen

Security Compliance Specialist

Global It Resources

$100,000 - $135,000 a year

Los Angeles, CA

3 months ago - seen