Home
/
Comprehensive
/
Security Compliance Engineer
Security Compliance Engineer-September 2024
Sacramento
Sep 22, 2024
ABOUT DELOITTE
With more than 100,000 Deloitte professionals across the United States, our range of services and depth of resources create the potential to make an impact through most any career. Right now, our prof
10,000+ employees
Consulting, Financial Services
VIEW COMPANY PROFILE >>
About Security Compliance Engineer

  Do you enjoy problem solving? Are you able to see the big picture and think critically to assess a situation? Are you passionate about aiding Government and Public Services (GPS) organizations in preparing for and overcoming the challenges they face? If so, Deloitte could be the place for you! Join our Strategic Risk team and help our clients identify, understand, and prepare for their largest mission risks. If you seek a role that offers you the opportunity to advise government organizations on complex issues, challenges you to think both analytically and strategically, and can develop personally and professionally, consider a career in Deloitte Risk & Financial Advisory's Strategic Risk practice.

  Work you'll do

  As the Security Compliance Lead you will play a critical role in leading end-end compliance security activities for the infrastructure supporting a state-wide integrated system. You are responsible for managing and maturing the security compliance program on the project and will be part of a team responsible for periodically assessing security controls for potential risks and securing end-end operations of the solution.

  Responsibilities:

  Drive enhancements to mature the security compliance program

  Support for driving security compliance efforts across the project. Responsible for providing security control and mitigation subject matter expertise for reduction of risks identified and mapped in risks assessments in coordination with other teams

  Support internal security compliance activities and support external audits/assessments

  Support the development and management of security compliance deliverables such as System Security Plan and Plan of Action & Milestone (POA&M), security risk assessment reports

  Facilitate technical deep-dives and security threat model assessments to evaluate emerging threats

  Conduct security reviews and coordinate penetration testing exercises on an as-needed basis

  The team

  Deloitte's Government and Public Services (GPS) practice - our people, ideas, technology and outcomes-is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of over 15,000+ professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

  Our Strategic Risk practice is comprised of sharp analytical thinkers who are adept at complex problem solving and risk management. Our practitioners are committed to our clients' missions and bring diverse life experiences, skillsets, and creative approaches to work every day to help our clients achieve mission success. Our practitioners are also experienced in collaborating with teams from across our organization in order to bring the full breadth of Deloitte, its commercial and public sector experience, to best support our clients.

  This role is located in Sacramento, CA.

  Qualifications

  Required:

  3+ years designing and implementing security controls for large and complex IT systems hosted on-premise and/or in cloud environment based on security standards such as NIST 800-53, FedRAMP or CMS MARS-E

  3+ years' experience developing system security plan (SSP) for large and complex IT systems hosted on-premise and/or in cloud environment

  3+ years' experience performing security architecture reviews, periodically assessing and monitoring security controls for compliance with security standards, managing Plan of Actions & Milestones (POA&Ms), risk assessment, planning for remediation of identified risks

  3+ years of experience assessing system data sensitivity using security categorizations (e.g., FIPS Publication 199) to identify appropriate security controls to protect Personally Identifiable Information (PII), Protected Health Information (PHI) and/or Federal Tax Information (FTI) data

  Bachelor's degree

  Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future

  Preferred:

  Hold and maintain for the duration of the contract an (ISC)2© Certified Information Systems Security Professional (CISSP) certification, or ISACA Certified Information Security Manager (CISM).

  In-Depth technical background with a good understanding of security concepts and practical usage (Network Engineering, Network Security, Threat and Vulnerability Management, Database, SDLC, and Release Management)

  The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $78,000 to $118,000.

  You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Territory Manager, TASKI - Michigan/Ohio
POSITION SUMMARY:The Territory Manager, TASKI (TASKI Machine Specialist) is responsible for demonstrating, promoting, and selling TASKI & NSS floor machines. This exciting role requires entrepren
Events Coordinator
Job Number 24013806 Job Category Food and Beverage & Culinary Location The St. Regis Singapore, 29 Tanglin Road, Singapore, Singapore, Singapore Schedule Full-Time Located Remotely? N Relocation?
Registered Nurse
Registered Nurse ID2023-21141CategoryRegistered Nurse specialties - AmbulatoryFacilityU.S. Immigration & Customs Enforcement - New Jersey - Elizabeth Contract Detention Facility - Elizabeth, NJ 0
Mining Engineer
Senior Mining Engineer Req ID 17691 Senior Mining Engineer Who We Are At WSP, we are driven by inspiring future-ready pioneers to innovate. We’re looking to grow our teams with people who are ready t
Senior IT Systems Engineer (Phoenix, AZ)
**We are only able to hire candidates that are currently located in WA, OR, ID, FL, NC, TX, and AZ.  The Opportunity As a modern technology consulting firm, ISO is at the forefront of change.  We str
Pharmacy Technician
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced
Sr. Assistant Project Manager
Job Title Sr. Assistant Project Manager Job Description Summary The Sr. Assistant Project Manager is responsible for assisting the Project Manager in overseeing and delivering Project & Development S
Semi Skilled Laborer (Fort Washington State Park Complex)
Reference #: 4339624THE POSITIONAre you someone who loves being outside and getting your hands dirty? If so, then the Semi-Skilled Laborer position at Fort Washington State Park Complex could be the
Product Demonstrator Part Time
Job Posting Overview Weekly Pay Flexible Schedule Fun Work Environment Career Advancement Opportunities Online and/or on-the-job training This part time associate samples products for suppliers withi
Accounts Receivable Clerk
1+ years AR experience - NOT data entry. This person will need to be able to understand the invoicing process and navigate that depending on the invoicing situation (ex., invoice is overpaid/short, h
Copyright 2023-2024 - www.zdrecruit.com All Rights Reserved