Project Lead Cybersecurity Engineer
About the role
Join our Deloitte Cyber team to deliver powerful solutions that help clients navigate the ever-changing threat landscape. As a Project - Lead Security Engineer II on the Enterprise Security team, you will support cybersecurity operations by administering and sustaining tools used for continuous monitoring, vulnerability management, log analysis, and security operations support.
Responsibilities
- Administer Tripwire to support file integrity monitoring, configuration assessment, and cybersecurity control execution.
- Support administration of Splunk, SecurityBridge, and ESS, including configuration, monitoring, reporting, and operational support.
- Perform and coordinate ACAS scans, analyze findings, prioritize vulnerabilities, and track remediation with system owners and technical teams.
- Support system hardening, patch coordination, access reviews, and incident analysis across Windows and Linux environments.
- Maintain documentation, standard operating procedures, Plan of Action and Milestones (POA&M) inputs, and audit evidence in alignment with Department of Defense (DoD), Risk Management Framework (RMF), and program requirements.
Skills
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
About the team
Deloitte's Government & Public Services (GPS) practice is designed for impact, serving federal, state, and local government clients as well as public higher education institutions. Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. This includes security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a competitive benefits package.
Qualifications
- Bachelor's degree
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
- Active Secret security clearance required with the ability to obtain a Top Secret clearance
- Ability to travel 25%, on average, based on the work you do and the clients and industries/sectors you serve
- 4+ years of cybersecurity experience, including 2+ years in cloud security
- 4+ years of experience with IAM, encryption, boundary security, logging, and cloud monitoring
- 3+ years of experience with AWS
- 2+ years of the following experience:
- Experience with RMF, NIST 800-53, STIGs, and federal authorization practices
- Experience with ACAS/Nessus
- Experience with Splunk
- Experience with securing AWS environments, preferably in regulated or government settings
- CompTIA Security+ CE DoD 8570/8140-compliant baseline cybersecurity certification
Preferred Qualifications
- OS / Computing Environment Certifications or Training Certificate of Completion (40+ hours):
- Tripwire: Windows Server Administration certification/training covering Windows Server 2022, or similar
- Splunk: CompTIA Linux+ or Red Hat Certified System Administrator (RHCSA), or similar
- CISSP, CASP/SecurityX, CySA, or similar
- Splunk Core Certified User / Power User / Admin
- Experience with AWS GovCloud in a DoD or IC environment
- Experience with SAP cybersecurity tooling, including SecurityBridge
- Experience with RMF, STIGs, POA&M management, and DoD vulnerability management processes