Cloud Security Architect -devsecops Manager

This role is for a Cloud Security Architect - DevSecOps Manager at Deloitte. The primary focus is on leading client engagements to operationalize and scale secure-by-design software delivery in cloud-agnostic environments. Responsibilities include designing and implementing secure workflows, building controls frameworks, conducting assessments, defining operating models, embedding security into CI/CD, advancing software supply chain security, and managing client relationships. The role requires experience in technical consulting, DevSecOps program leadership, translating policies into controls, and familiarity with application security and modern engineering ecosystems.

What you'd actually do

  1. Lead delivery of DevSecOps / Secure SDLC programs as a project manager and/or architect, overseeing onsite/offshore teams across governance, identity, application security, platform/infrastructure security, monitoring, resilience, and data protection.
  2. Design and implement Secure by Design / security engagement intake workflows that streamline how engineering teams initiate governance/security processes (e.g., rationalizing questionnaires, automating routing/approvals, reducing cycle time).
  3. Build or tailor controls frameworks and control mappings (e.g., aligned to NIST 800-53 and enterprise policies/standards) and translate them into actionable engineering requirements and measurable outcomes.
  4. Conduct DevSecOps current-state assessments (people/process/technology), facilitate leading-practices workshops, and produce multi-year roadmaps with sequenced initiatives, resourcing, and cost estimates.
  5. Define DevSecOps operating model options (team structure, service catalog, intake, RACI, governance forums) and drive executive decision-making on the target approach.

Skills

Required

  • 6+ years of experience in technical consulting, client problem solving, and delivery leadership.
  • 2+ years designing or leading DevSecOps / Secure SDLC programs (assessment, roadmap, operating model, and implementation oversight).
  • Experience translating policy/standards into engineering-ready controls and workflows; familiarity with security control frameworks (e.g., NIST CSF and/or NIST 800-53).
  • Experience with automation/workflow platforms (e.g., ServiceNow or similar) to support security intake, governance, and evidence collection.
  • Experience with application security and modern engineering ecosystems (CI/CD concepts, containers, SDLC tooling).
  • BA/BS degree preferably in a technical field.

Nice to have

  • Previous consulting or Big 4 experience.
  • Certifications (e.g., CCSP or comparable); familiarity with industry maturity models (e.g., OWASP SAMM, BSIMM) and/or supply chain frameworks (e.g., SLSA).
  • Experience with code signing/PKI concepts and security tooling ecosystems; experience with dashboarding/analytics (e.g., Power BI) a plus.
  • Understanding of regulatory/compliance requirements (e.g., ISO 27001/27017, SOC 2, PCI, HIPAA, SOX, GLBA, NIST 800-53).

What the JD emphasized

  • DevSecOps / Secure SDLC
  • Secure by Design
  • controls frameworks
  • software supply chain security